[Remote] Sr. Principal Security Engineer, Application Security Strategy & Architecture
Key details
- Work type
- remote
- Employment
- full time
Job Description
Note: The job is a remote job and is open to candidates in USA. Lilly is a global healthcare company dedicated to making life better for people around the world. As a Sr.
Principal Security Engineer, you will lead strategy and architecture for Lilly's Application Security program, providing architectural direction and driving security transformation initiatives.
Responsibilities Define and maintain the architectural direction for Lilly's Secure SDLC program, including SAST, DAST, SCA, secrets management, and software supply chain capabilitiesPartner with the Director of Application Security to identify and communicate program-level execution risks and dependenciesTranslate regulatory, compliance, and audit requirements into security architecture that engineering teams can implement and sustainLead structured evaluations of security tooling across SAST, DAST, SCA, penetration testing, and AI-augmented security platformsDefine evaluation criteria, design proof-of-concept engagements, assess vendor capabilities against Lilly's environment and scale, and produce recommendation packages for leadership decision-makingMaintain awareness of the AppSec tooling landscape and advise on emerging capabilities-including AI-driven security tools-that warrant evaluation or adoptionPartner with procurement, legal, and engineering collaborators to support vendor selection and contract alignmentServe as the AppSec architecture lead for platform transformations, owning security architecture decisions and ensuring AppSec requirements are representedAssess and document the security impact of the migration on existing AppSec controls-identifying gaps in SAST, secrets scanning, and CI/CD security coverage that the migration creates and defining the remediation pathPartner with engineering and platform teams to ensure security requirements are embedded into migration sequencing and cutover planning-not addressed after the factDefine security readiness criteria for each phase of the transformation and serve as the AppSec authority on go/no-go decisions at key transition pointsProvide senior technical guidance to AppSec engineers on complex implementation challenges, architecture decisions, and remediation approachesConduct security reviews for high-risk applications, platforms, and infrastructure changesSupport threat modeling engagements for major product initiatives and platform changes across Lilly's development ecosystemContribute to Lilly's Secure SDLC standards and vulnerability management policy, ensuring policy is grounded in architectural reality and can be implemented through platform and pipeline controls Skills Bachelor's Degree in Computer Science, Information Security, Software Engineering, or a related fieldAt least 5 years of experience in application security, security architecture, or a closely related disciplineDemonstrated experience leading or architecting a large-scale security, identity, or platform migration in an enterprise environmentHands-on experience with GitHub enterprise environments, including GitHub Actions, CI/CD security controls, and identity and access management patternsExperience evaluating and selecting enterprise security tooling, including SAST, DAST, or SCA platformsFamiliarity with threat modeling methodologies and application security fundamentals (OWASP Top 10, CWE, secure coding practices)Deep familiarity with GitHub's identity and access model, including experience with or strong understanding of GitHub Enterprise Managed Users (EMU), SAML/OIDC federation, PAT governance, and GitHub Actions security controlsExperience assessing the security implications of platform migrations-understanding what breaks, what coverage gaps are created, and how to sequence remediationStrong expertise in application security fundamentals-OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability managementWorking knowledge of AppSec tooling ecosystems: SAST (Checkmarx or equivalent), DAST, SCA, and secrets scanning platformsAbility to communicate optimally to produce architectural documentation and present risk and recommendation to senior leadershipFamiliarity with secrets management platforms and software supply chain security patternsAwareness of AI-augmented security tooling and the ability to evaluate where AI meaningfully improves AppSec workflows versus where it introduces riskWorking knowledge of cloud environments (AWS preferred) and containerized workloads in the context of security architectureAbility to operate as a senior individual contributor-providing architectural leadership and program-level judgment without requiring direct management authority to drive outcomes Benefits Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance).Eligibility to participate in a company-sponsored 401(k)PensionVacation benefitsEligibility for medical, dental, vision and prescription drug benefitsFlexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts)Life insurance and death benefitsCertain time off and leave of absence benefitsWell-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities) Company Overview Dice is the go-to career marketplace for tech professionals.
It was founded in 2010, and is headquartered in Drachten, Friesland, NLD, with a workforce of 201-500 employees. Its website is https://www.or-quest.nl/. Company H1B Sponsorship Dice has a track record of offering H1B sponsorships, with 2 in 2022, 4 in 2021, 5 in 2020.
Please note that this does not guarantee sponsorship for this specific role.
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Software Engineer jobs.
Lead/Senior Scrum Master - Remote
Remote Java Developer
WMS Manhattan QA Lead Remote
Source: Google Jobs • Last updated 1d ago