EngineerJobs.io
← Back to all jobs

Job Description

Philip Morris International U.S. is seeking a Principal InfoSec Engineer focused on Application Security to lead security assurance for PMI U.S. applications from Tampa. This role centers on identifying cybersecurity gaps, owning security engagements for critical projects, and guiding global AppSec strategies that align with PMI U.S. objectives.

Responsibilities

  • Identify cybersecurity gaps in new and existing applications and systems used by the PMI U.S. business unit via methods including threat modeling, architecture reviews, access model reviews, configuration reviews, and SAST/DAST.
  • Own the execution of security assurance for the most critical or complex projects in the PMI U.S. business unit, planning and delivering the security engagement from initial risk scoping and design checkpoints to final pre go-live assessments, ensuring security requirements are addressed throughout the project lifecycle.
  • Develop tailored assurance plans for projects that deviate from standards, determining additional assessment steps when new technologies are adopted and coordinating with other specialized InfoSec teams or external experts.
  • Describe and demonstrate identified issues through reports and technical debt definitions, ensuring stakeholders understand the risk and advising technology teams on effective and cost-efficient remediation and replication steps.
  • Coordinate with other AppSec teams to obtain specialized input, bring in Offensive Security specialists for targeted activities, and integrate findings into project advisories while feeding common pain points back into AppSec baselines.
  • Support the creation of global application security strategies and implement strategic AppSec plans and initiatives for PMI U.S.
  • Partner with Information Security leaders to continuously optimize tools, techniques, and methodologies across the PMI U.S. AppSec domain.
  • Stay current with the evolving cyber threat landscape and advances in technology and cyber risk management.

Requirements

  • 10+ years of experience in Information Security, preferably within IT risk or assurance (IT Security, IT Audit, Application Security, or Offensive Security) in a large organization or consulting environment.
  • Proven track record of autonomously executing complex IT security assessments or IT audits for large-scale technology solutions, including architectural reviews, configuration reviews, and automated testing (SAST, DAST).
  • Broad familiarity with multiple IT domains such as application development, cloud, and infrastructure.
  • Technical depth to challenge design decisions when needed and assess whether architectures meet segmentation requirements.
  • Risk evaluation and articulation skills with the ability to foresee project constraints and pragmatically propose mitigations that balance security with practical delivery.
  • Excellent communication skills to lead discussions with project managers and architects and brief senior management on residual risks; strong negotiation skills to drive necessary security changes.
  • Strong report writing abilities for executive summaries and risk registers, plus experience improving team processes and refining methodologies (for example, standardized threat model templates).
  • Professional security certifications: CISA (mandatory), CISSP (mandatory). CISM is optional but preferred.

Technologies

  • SAST
  • DAST

Benefits

  • Annual bonus
  • Medical, dental, and vision coverage
  • 401k with a generous company match
  • Wellness benefits
  • Commuter benefits
  • Pet insurance
  • Generous PTO
  • Hybrid work model (Smart Work) promoting flexibility
  • Inclusive, diverse culture
  • Opportunities to progress and develop skills in a global business
  • Autonomy to take risks, experiment, and explore
  • Mission driven work contributing to society

Salary

USD 160,000 - 200,000 per year

Location

Onsite in Tampa, Florida

Similar Jobs