Diligent Technologies, an IBM company Logo

Principal Application Security Engineer

Job Description

Role Overview

You’ll be the senior technical voice for application security across Diligent, shaping how secure software is designed, built, and run for cloud-based web and mobile products. In this Principal Application Security role, you’ll partner closely with Product, Engineering, and Operations to embed security into the software development lifecycle and protect high-impact platforms like Diligent Entities and Diligent Analytics.

You’ll combine deep hands-on security expertise with broad architectural vision: defining security strategy, guiding technology choices, and mentoring engineering teams. You’ll be the go-to expert for complex security decisions, helping the business move fast while staying ahead of evolving threats, industry standards, and best practices.

Here’s a breakdown of what you’ll do (not all of it, just the important stuff)

  • Lead the application security strategy for key SaaS platforms, influencing architecture, design, and implementation across multiple products.

  • Partner with product and engineering leaders to integrate security into the SDLC, from threat modeling and secure design to code review and pre‑production testing.

  • Identify, prioritize, and drive remediation of application vulnerabilities (including OWASP Top 10 and CWE/SANS Top 25) using code analysis, penetration testing, and automation.

  • Define and champion secure coding standards, patterns, and best practices for .NET, JavaScript/AngularJS, C#, and mobile frameworks.

  • Act as a senior technical advisor to leadership, clearly communicating risk, trade-offs, and recommended solutions for complex security issues.

  • Mentor and influence engineers and fellow principals, building a strong security culture and upskilling teams globally.

These are the essentials you’ll need to get an interview

  • Substantial experience (typically 12+ years) in application design and development for web and/or mobile applications, with increasing security responsibilities.

  • Strong understanding of application security concepts, Internet technologies, architectures, and protocols.

  • Hands-on experience identifying and mitigating common web and API vulnerabilities, including OWASP Top 10 and CWE/SANS Top 25.

  • Proficiency with at least some of the core technologies in our stack, such as .NET, C#, AngularJS, or modern mobile frameworks.

  • Experience using application security tools, such as static/dynamic code analysis and penetration testing tools.

  • Familiarity with security standards and frameworks relevant to SaaS (for example ISO, NIST, CSA).

  • Excellent communication and leadership skills, with the ability to influence senior stakeholders and guide engineers.

It would be great if you had these too, but we’ll support you if you don’t

  • Experience with CI/CD and DevSecOps practices (for example Jenkins pipelines, integrating security checks into builds).

  • Exposure to container and secrets ecosystems such as Docker, Kubernetes, Rancher, and tools like Vault.

  • One or more relevant security certifications (for example CISSP, CSSLP, CEH, GPEN, GWAPT, GMOB, Security+), or equivalent practical experience.

About Us

Diligent is the AI leader in governance, risk and compliance (GRC) SaaS solutions, helping more than 1 million users and 700,000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners, the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk, build greater resilience and make better decisions, faster.

At Diligent, we’re building the future with people who think boldly and move fast.  Whether you’re designing systems that leverage large language models or part of a team reimaging workflows with AI, you’ll help us unlock entirely new ways of working and thinking.  Curiosity is in our DNA, we look for individuals willing to ask the big questions and experiment fearlessly - those who embrace change not as a challenge, but as an opportunity.  The future belongs to those who keep learning, and we are building it together.  At Diligent, you’re not just building the future - you’re an agent of positive change, joining a global community on a mission to make an impact.

Learn more at diligent.com or follow us on LinkedIn and Facebook

What Diligent Offers You

  • Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
  • We care about our people. Diligent offers a flexible work environment, global days of service, comprehensive health benefits, meeting free days, generous time off policy and wellness programs to name a few
  • We have teams all over the world. We may be headquartered in New York City, but we have office hubs in Washington D.C., Vancouver, London, Galway, Budapest, Munich, Bengaluru, Singapore, and Sydney.
  • Diversity is important to us. Growing, maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team, facilitate dialogue, and foster understanding.

Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology, insights and connections they need to drive greater impact and accountability – to lead with purpose. Our employees are passionate, smart, and creative people who not only want to help build the software company of the future, but who want to make the world a more sustainable, equitable and better place.

Headquartered in New York, Diligent has offices in Washington D.C.,  London, Galway, Budapest, Vancouver, Bengaluru, Munich, Singapore and Sydney.   To foster strong collaboration and connection, this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations, you will be expected to work onsite at least 50% of the time. We believe that in-person engagement helps drive innovation, teamwork, and a strong sense of community.

We are a drug free workplace. Diligent is proud to be an equal opportunity employer. We do not discriminate based on race, color, religious creed, sex, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental disability, age, military status, protected veteran status, marital status, registered domestic partner or civil union status, gender (including sex stereotyping and gender identity or expression), medical condition (including, but not limited to, cancer related or HIV/AIDS related), genetic information, or sexual orientation in accordance with applicable federal, state and local laws. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Diligent’s EEO Policy and Know Your Rights. We are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at [email protected].

To all recruitment agencies: Diligent does not accept unsolicited agency resumes. Please do not forward resumes to our jobs alias, Diligent employees or any other organization location. Diligent is not responsible for any fees related to unsolicited resumes.

Share this job:
Please let Diligent Technologies, an IBM company know you found this job on Remote First Jobs 🙏

770 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like Diligent Technologies, an IBM company

Find your next opportunity with companies that specialize in Data Protection Solutions. Explore remote-first companies like Diligent Technologies, an IBM company that prioritize flexible work and home-office freedom.

DataGrail Logo

DataGrail

An AI-powered platform for data privacy management, compliance automation, and risk reduction.

View company profile →
ZAVIANT Logo

ZAVIANT

Provides data security, data privacy, and GRC consulting services to organizations.

View company profile →
BigID Logo

BigID

Enterprise software and a platform for data security, privacy, and AI data management solutions.

View company profile →
VComply Logo

VComply

Agile GRC SaaS platform

View company profile →
LogicManager Logo

LogicManager

Provides enterprise risk management (ERM) software to help organizations manage risks and improve business performance.

View company profile →
EasyLlama Logo

EasyLlama

An AI-powered compliance and security training platform for businesses.

View company profile →

Project: Career Search

Rev. 2026.5

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply