FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Principal Application Security Engineer
CDWPrincipal Application Security Engineer securing CDW’s technology solutions, applications, APIs, and software delivery pipelines. Driving enterprise-wide secure engineering practices, controls, and AI security at scale.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Application Security Engineering, focusing on secure application architecture, secure coding practices, and threat modeling. Proficient in integrating security into CI/CD pipelines and mentoring teams to enhance application security standards.
Highest-signal resume keywords
Application Security EngineeringSecure Application ArchitectureCI/CD Security IntegrationAPI SecurityThreat Modeling
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Secure Coding PracticesCode-Level Vulnerability AnalysisAuthenticationAuthorizationSession ManagementSecrets ManagementDependency Risk ManagementRuntime Application ProtectionIaC Security (Terraform)Cloud Security (Azure, AWS, GCP)
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationOwnershipAccountabilityMentoring
Tools & Technologies
CI/CD PlatformsWAFAkamaiAI Security ToolsSecure Reference Architectures
Industry Keywords
Zero TrustSecure Platform EngineeringPolicy-as-CodeSoftware Supply Chain SecurityApplication Security Metrics
Tech Stack
Tools & technologiesAWSAzureCloudDistributed SystemsGoGoogle Cloud PlatformJavaJavaScriptPythonTerraformTypeScript
About the role
Key responsibilities & impact- Lead high-impact secure code reviews, threat models, and secure design assessments for applications, APIs, and shared services
- Translate technical risk into clear guidance for engineers, technical leaders, and business stakeholders
- Drive design, integration, and continuous improvement of application security controls across CI/CD platforms, workflows, and environments
- Identify control gaps, coverage weaknesses, and engineering friction across the software delivery lifecycle
- Drive remediation through automation, platform improvements, and secure-by-design patterns
- Define, advocate for, and build secure coding standards, reference architectures, playbooks, tooling, and automations
- Serve as a senior technical partner to engineering teams by influencing design decisions and guiding remediation strategy
- Advance CDW’s approach to securing AI-enabled development and applications
- Evaluate emerging AI security risks and define practical guardrails
- Provide subject matter expertise in API security, including authentication, authorization, protections, monitoring, and secure integration patterns
- Partner with web and platform teams to design, deploy, and tune WAF rules and policies
- Mentor others, raise standards, and drive organization-wide improvements in application security
Requirements
What you’ll need- 10+ years of experience in Application Security Engineering
- Deep, hands-on expertise in secure application architecture and design, secure coding practices, code-level vulnerability analysis, and threat modeling
- Background in software engineering, application development, or architecture
- Strong command of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns
- Hands-on experience with modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar
- Strong experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms
- Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation
- Strong written and verbal communication skills
- Strong sense of ownership and accountability
- Experience defining standards, playbooks, secure reference architectures, or scalable practices
- Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance, a plus
- Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on secure use of AI or LLM-based capabilities, a plus
- Familiarity with Zero Trust, secure platform engineering, and policy-as-code approaches, a plus
- Prior experience serving as an Application Security Champion, Security Champion, embedded security lead, principal engineer, or senior engineer responsible for driving security within product or application teams, a plus
- Experience with runtime application protection, exploit prevention, threat detection technologies, and abuse case analysis, a plus
- Experience influencing secure development practices across decentralized or federated engineering organizations, a plus
- Experience defining and using application security metrics, maturity measures, or risk-based reporting, a plus
- Experience designing security controls for cloud-native and distributed systems running in Azure, AWS, or GCP, a plus
- Experience designing, deploying, or tuning Akamai protections, a plus
- Experience with reviewing and securing IaC (Terraform or similar), a plus
Benefits
Comp & perks- Annual bonus target 15% subject to terms and conditions of plan
- Benefits overview provided at https://cdw.benefit-info.com/
- Salary ranges may be subject to geographic differentials