Principal Appsec Engineer
Core
Own the team's deep offensive capability, running adversary emulation and bypass testing against production systems, and providing technical depth for architecture reviews.
Role type
Principal AppSec Engineer (Offensive Security)
Builds
Production security testing capabilities and detection rules
Domain
Cybersecurity / Application Security
Required skills
Offensive security (pentesting, red teaming, adversary emulation), Architecture review and threat modeling, Modern AppSec tooling (SAST/DAST, AI-assisted tools), Technical escalation
Preferred skills
Bug bounty triage, Vulnerability disclosure programs
Technologies
NEO, regression code scanning, SAST, DAST
Responsibilities
Run adversary emulation and bypass testing against production systems; Own standardized pentest playbooks for urgent requests; Lead in-depth architecture and design reviews with threat modeling; Mature and scale AI-assisted pentest tooling; Mentor less experienced AppSec engineers; Feed confirmed findings to Detection Engineering & Threat Hunting
Seniority
Principal, hands-on IC with mentorship