Principal Application Security Engineer

Barracuda Networks
Ann Arbor
Workplace: HybridFull timeFunction: CybersecurityExperience: 8-10 yearsSkills: ["Mentorship","Communication","Presentation","Ownership","Cross-functional collaboration"]

Shape, grow, and lead the Application Security program as the most senior AppSec team member. Embed modern AppSec/ProdSec practices across the development lifecycle, reduce late-stage findings through automation and developer enablement, and lead threat modeling and hands-on security assessments (pen tests and source code reviews). Partner with product, platform, and engineering leaders to drive risk-based security initiatives across complex, multi-stakeholder environments.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Barracuda Networks
Barracuda Networks
3 days ago

Principal Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 18 hours agoStatus: Live

Job Summary

Shape, grow, and lead the Application Security program as the most senior AppSec team member. Embed modern AppSec/ProdSec practices across the development lifecycle, reduce late-stage findings through automation and developer enablement, and lead threat modeling and hands-on security assessments (pen tests and source code reviews). Partner with product, platform, and engineering leaders to drive risk-based security initiatives across complex, multi-stakeholder environments.
Location: Ann Arbor
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Shape, grow, and lead the Application Security program, influencing overarching security direction and initiatives.
  • •Embed security across the development lifecycle and reduce late-stage findings via automation and developer enablement.
  • •Facilitate lightweight, feature-level threat modeling and drive risk-based discussions to flag high-risk changes.
  • •Perform hands-on security assessments including application penetration tests and security-focused source code reviews, supporting vulnerability management processes.
  • •Partner with product, platform, and engineering leads to drive security initiatives and lead short, outcome-focused security trainings/design reviews.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceEquityPaid LeaveRetirement

Key Requirements

  • •8-10+ years in product-focused AppSec, moving teams from reactive pen testing/documentation-heavy to proactive guardrail-driven programs.
  • •Deep, hands-on AppSec and ProdSec expertise, including core security concepts across AppSec, ProdSec, and Cloud.
  • •Experience building or growing modern AppSec/ProdSec programs in a product environment.
  • •Hands-on security assessment experience, including application penetration tests, security-focused source code reviews, and risk rating/vulnerability management.
  • •Proficiency in at least two programming languages (e.g., TypeScript/JavaScript, Python, Ruby, Java, Go) with ability to provide framework-specific remediation guidance.
Experience:8-10 yearsCybersecurityApplication securityProduct securityCloudAutomation
Skills:MentorshipCommunicationPresentationOwnershipCross-functional collaboration
Certifications:OSCPOSCEOSWE
Tech Stack:TypeScriptJavaScriptPythonRubyJavaGoThreat modelingPenetration testingSource code reviewsVulnerability managementRisk rating

Company Brief

Barracuda Networks
Provides cloud-enabled security and data protection solutions including email protection, network and application security, and backup and recovery services for businesses, service providers, and government organizations worldwide.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Campbell, United States
Founded: 2003
WebsiteLinkedIn