Principal Application Security Engineer
Application Security
Application Security Strategy
Cybersecurity Tools
Data Security
DevSecOps
Digital Marketing
Dynamic Application Security Testing
Enterprise Risk
InfoSec
Infrastructure As Code
Project Management
Risk Governance
Risk Management
SAS
Security
Security Assessment
Security Automation
Security Testing
Software Composition Analysis
Software Security
Solution Architecture
Static Application Security Testing
Strategic Advisory
Job Description
Motion Recruitment is partnering with a well-known financial services company to hire a Principal Application Security Engineer for a 12-month contract in Charlotte, NC (Hybrid). This role is built for experienced engineering leaders who can shape enterprise application security strategy, modernize AppSec through automation, and expand security capabilities for AI and GenAI applications.
What You’ll Do
- Serve as an expert consultant to develop or influence initiatives and resources for complex business and technical needs across Engineering.
- Consult on strategy and resolution of highly complex, unique challenges using in-depth evaluation across multiple areas, delivering long-term, large-scale solutions.
- Provide technical expertise to client senior leadership and strategically engage with client personnel.
- Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
- Evaluate current AppSec control coverage, establish baseline mappings by application tier, and identify control gaps.
- Drive remediation and onboarding plans with application teams and stakeholders.
- Partner with Application Security Champions and engineering teams to support consistent adoption of required AppSec controls.
- Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
- Identify and deliver AI and GenAI use cases that reduce manual AppSec effort while improving security coverage.
- Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
- Develop adversarial testing for GenAI and LLM-based applications, including prompt injection and abuse scenario coverage.
- Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
- Define protections for AI-specific risks, including insecure prompt construction, tool misuse, and secrets exposure.
- Drive modernization of AppSec controls via automation, rationalization, and platform integration.
- Build proofs-of-concept and pilot new security capabilities, scaling successful approaches into production.
- Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
- Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Research emerging threats and technologies and translate findings into actionable AppSec strategy.
Required Qualifications
- 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of work or consulting experience, training, military experience, or education.
- 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
- Deep expertise in SSDLC controls, including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
- Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
- Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
- Experience designing AI-driven security automation or decisioning capabilities.
- Strong understanding of DevSecOps and CI/CD security integration.
- Experience working in highly regulated environments such as financial services.
- Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
Key Technologies
SSDDC, SDLC, SSAST, SCA, DAST, GenAI, LLM, DevSecOps, CI/CD, infrastructure-as-code