Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CDW

Principal Application Security Engineer

CDW

Principal Application Security Engineer securing CDW’s technology solutions, applications, APIs, and software delivery pipelines. Driving enterprise-wide secure engineering practices, controls, and AI security at scale.

Posted 8/21/2026full-timeRemote • 🇺🇸 United StatesLead💰 $172,000 - $240,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in Application Security Engineering, focusing on secure application architecture, secure coding practices, and threat modeling. Proficient in integrating security into CI/CD pipelines and mentoring teams to enhance application security standards.

Highest-signal resume keywords
Application Security EngineeringSecure Application ArchitectureCI/CD Security IntegrationAPI SecurityThreat Modeling

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Secure Coding PracticesCode-Level Vulnerability AnalysisAuthenticationAuthorizationSession ManagementSecrets ManagementDependency Risk ManagementRuntime Application ProtectionIaC Security (Terraform)Cloud Security (Azure, AWS, GCP)
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationOwnershipAccountabilityMentoring
Tools & Technologies
CI/CD PlatformsWAFAkamaiAI Security ToolsSecure Reference Architectures
Industry Keywords
Zero TrustSecure Platform EngineeringPolicy-as-CodeSoftware Supply Chain SecurityApplication Security Metrics

Tech Stack

Tools & technologies
AWSAzureCloudDistributed SystemsGoGoogle Cloud PlatformJavaJavaScriptPythonTerraformTypeScript

About the role

Key responsibilities & impact
  • Lead high-impact secure code reviews, threat models, and secure design assessments for applications, APIs, and shared services
  • Translate technical risk into clear guidance for engineers, technical leaders, and business stakeholders
  • Drive design, integration, and continuous improvement of application security controls across CI/CD platforms, workflows, and environments
  • Identify control gaps, coverage weaknesses, and engineering friction across the software delivery lifecycle
  • Drive remediation through automation, platform improvements, and secure-by-design patterns
  • Define, advocate for, and build secure coding standards, reference architectures, playbooks, tooling, and automations
  • Serve as a senior technical partner to engineering teams by influencing design decisions and guiding remediation strategy
  • Advance CDW’s approach to securing AI-enabled development and applications
  • Evaluate emerging AI security risks and define practical guardrails
  • Provide subject matter expertise in API security, including authentication, authorization, protections, monitoring, and secure integration patterns
  • Partner with web and platform teams to design, deploy, and tune WAF rules and policies
  • Mentor others, raise standards, and drive organization-wide improvements in application security

Requirements

What you’ll need
  • 10+ years of experience in Application Security Engineering
  • Deep, hands-on expertise in secure application architecture and design, secure coding practices, code-level vulnerability analysis, and threat modeling
  • Background in software engineering, application development, or architecture
  • Strong command of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns
  • Hands-on experience with modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar
  • Strong experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms
  • Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation
  • Strong written and verbal communication skills
  • Strong sense of ownership and accountability
  • Experience defining standards, playbooks, secure reference architectures, or scalable practices
  • Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance, a plus
  • Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on secure use of AI or LLM-based capabilities, a plus
  • Familiarity with Zero Trust, secure platform engineering, and policy-as-code approaches, a plus
  • Prior experience serving as an Application Security Champion, Security Champion, embedded security lead, principal engineer, or senior engineer responsible for driving security within product or application teams, a plus
  • Experience with runtime application protection, exploit prevention, threat detection technologies, and abuse case analysis, a plus
  • Experience influencing secure development practices across decentralized or federated engineering organizations, a plus
  • Experience defining and using application security metrics, maturity measures, or risk-based reporting, a plus
  • Experience designing security controls for cloud-native and distributed systems running in Azure, AWS, or GCP, a plus
  • Experience designing, deploying, or tuning Akamai protections, a plus
  • Experience with reviewing and securing IaC (Terraform or similar), a plus

Benefits

Comp & perks
  • Annual bonus target 15% subject to terms and conditions of plan
  • Benefits overview provided at https://cdw.benefit-info.com/
  • Salary ranges may be subject to geographic differentials