PMI logo
PMIPosted 1 month ago

Principal InfoSec Engineer Application Security

$160,000–$200,000 year

HybridTampa, Florida, United States

Full TimeSenior Level

Job Summary

Identify cybersecurity gaps in new and existing applications via threat modeling, architecture reviews, and static/dynamic testing. Take ownership of security assurance for critical projects by planning engagements from risk scoping through pre-go-live assessments and developing tailored plans for non-standard technologies. Describe identified issues to stakeholders, advise teams on remediation strategies, and coordinate with offensive security specialists for targeted ethical hacking. Support global application security strategies, optimize security tools and methodologies, and evolve AppSec baselines based on project pain points. Maintain awareness of the evolving cyber threat landscape to inform risk management decisions.

Required Qualifications

  • 10+ years of experience in Information Security, preferably in the IT risk or assurance function (e.g., IT Security, IT Audit, Application Security, Offensive Security) of a large organization or consulting company
  • Proven track record in autonomously executing complex IT security assessments or IT audits for large scale technology solutions, including technical reviews such as architecture reviews, configuration reviews, automated testing (SAST, DAST)
  • Broad familiarity with various IT domains such as application development, cloud and infrastructure
  • Understanding of technical depth to challenge design decisions when needed (e.g., questioning why a certain legacy protocol is used, or whether a proposed architecture meets segmentation requirements)
  • Risk evaluation and articulation skills with ability to foresee project constraints and pragmatically suggest risk mitigations that fit within those constraints (balancing ideal security vs. practical delivery)
  • Excellent communication skills (up and down)
  • Ability to lead meetings with project managers and architects to discuss findings
  • Ability to brief upper management on the residual risks of a project
  • Strong negotiation skills to ensure necessary security changes are made
  • Strong report writing skills for executive-level summaries and detailed risk registers
  • Ability to improve team processes and refine existing methodologies (e.g., creating a standardized threat model template for all advisors to use)
  • CISA (mandatory)
  • CISSP (mandatory)

Desired Qualifications

  • CISM (optional, but preferred)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce