Principal Application Security Engineer

Principal Application Security Engineer


Job ID: mrp-884691

CHARLOTTE, ,

Information Technology

Contract,

$89.37 - $100.69

On-site

Other/Non Classified

CHARLOTTE, ,

$89.37 - $100.69

Contract,

Other/Non Classified

On-site

Information Technology

Job details

Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Principal Application Security Engineer in Charlotte, NC (Hybrid).

Work with the brightest minds at one of the largest financial institutions in the world. This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today’s digital age. If you want to work for a company that is not only a household name, but also truly cares about satisfying customers’ financial needs and helping people succeed financially, apply today.

Contract Duration: 12 Months

Required Skills & Experience

  • 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.
  • 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
  • Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
  • Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
  • Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
  • Experience designing AI-driven security automation or decisioning capabilities.
  • Strong understanding of DevSecOps and CI/CD security integration.
  • Experience working in highly regulated environments such as financial services.
  • Relevant security certifications (CISSP, CSSP, CISM, or equivalent).

What You Will Be Doing

  • Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
  • Consult on the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, and advanced analytical and inductive thinking.
  • Provide expertise to client senior leadership on innovative Engineering business solutions.
  • Strategically engage with client personnel.
  • DCMS Application Security Strategy
  • Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
  • Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
  • Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
  • Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls.
  • Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
  • AI Innovation for Application Security
  • Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
  • Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
  • Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
  • Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
  • Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
  • AppSec Modernization and Automation
  • Drive modernization of AppSec controls through automation, rationalization, and platform integration.
  • Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
  • Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
  • Senior Lead Influence and Leadership
  • Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
  • Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
  • Research emerging threats and technologies and translate insights into actionable AppSec strategy.

Share this job

I want more jobs like this in my inbox.

Share this job

As part of our promise to talent, Kelly supports those who work with us through a variety of benefits, perks, and work-related resources. Please note: The following benefits reflect Kelly's general offerings. Eligibility may vary by assignment, location, and job type. Kelly offers eligible employees voluntary benefit plans including medical, dental, vision, telemedicine, term life, whole life, accident insurance, critical illness, a legal plan, and short-term disability. As a Kelly employee, you will have access to a retirement savings plan, service bonus and holiday pay plans (earn up to eight paid holidays per benefit year), and a transit spending account. In addition, employees are entitled to earn paid sick leave under the applicable state or local plan. Click here for more information on benefits and perks that may be available to you as a member of the Kelly Talent Community.



About Kelly

Work changes everything. And at Kelly, we’re obsessed with where it can take you. To us, it’s about more than simply accepting your next job opportunity. It’s the fuel that powers every next step of your life. It’s the ripple effect that changes and improves everything for your family, your community, and the world. Which is why, here at Kelly, we are dedicated to providing you with limitless opportunities to enrich your life—just ask the 300,000 people we employ each year.

Kelly is committed to providing equal employment opportunities to all qualified employees and applicants regardless of race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, age, marital status, pregnancy, genetic information, or any other legally protected status, and we take affirmative action to recruit, employ, and advance qualified individuals with disabilities and protected veterans in the workforce. Requests for accommodation related to our application process can be directed to the Kelly Human Resource Knowledge Center. Kelly complies with the requirements of California’s state and local Fair Chance laws. A conviction does not automatically bar individuals from employment. Kelly participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.

Kelly may use AI-powered tools during the recruitment and hiring process. For full details, including how Kelly uses AI, your rights, and how to request a reasonable accommodation, visit the Recruitment Artificial Intelligence Notice.