Principal Application Security Engineer

Barracuda Networks Inc.Ann Arbor, MI
Hybrid

About The Position

As a Principal Application Security Engineer, you will be tasked with shaping, growing, and leading Barracuda’s Application Security program. Additionally, as the most senior member of the AppSec team, you will have the opportunity to provide mentorship to other team members and have a say in the direction of the overarching security program and initiatives. Candidates should have deep expertise in modern Application Security and Product Security practices, have experience defining and growing appsec/prodsec programs, be familiar with product development workflows/lifecycles, and have experience owning, planning, and executing initiatives across a complex multi-stakeholder business setting.

Requirements

  • 8-10+ years in product-focused AppSec.
  • Able to move orgs from reactive pen-test/documentation-heavy to proactive guardrail-driven programs.
  • Deep practical (hands-on) knowledge of core security concepts across AppSec, ProdSec, and Cloud.
  • Hands-on experience building or growing modern AppSec/ProdSec programs in a product environment.
  • Experience and a proven track record of owning workstreams, initiatives, or impactful project scope over an extended (year+) period.
  • Proficient in Threat Modeling.
  • Strong hands-on experience performing application penetration tests, conducting security-focused source code reviews, driving risk rating and vulnerability management processes.
  • Proficient in at least two programming languages (TypeScript/JavaScript, Python, Ruby, Java, Go, etc.).
  • Strong communication and presentation skills.
  • Able to provide concise and practical developer-friendly guidance.
  • Comfortable leading short, outcome-focused design review discussions and security trainings.

Nice To Haves

  • A strong sense of ownership and community within the team.
  • Hands-on experience building production-grade software.
  • Experience working cross-functionally with technical and non-technical teams.
  • Applicable certifications such as OSCP, OSCE, OSWE, etc.
  • Previous management/leadership experience.
  • Excited and passionate about application security and software development.

Responsibilities

  • Shaping, growing, and leading Barracuda’s Application Security program.
  • Providing mentorship to other team members.
  • Having a say in the direction of the overarching security program and initiatives.
  • Embedding security across the development life cycle.
  • Reducing late-stage findings via automation and developer enablement.
  • Facilitating lightweight, feature-level threat models.
  • Driving risk-based discussions.
  • Flagging high-risk changes across a broad spectrum of tech stacks and product designs.
  • Performing application penetration tests.
  • Conducting security-focused source code reviews.
  • Driving risk rating and vulnerability management processes.
  • Reviewing code and providing framework-specific remediation guidance.
  • Partnering with product, platform, and engineering leads to drive security initiatives.
  • Leading short, outcome-focused design review discussions and security trainings.
  • Building automation and successfully leveraging AI to facilitate daily tasks.

Benefits

  • Opportunities for cross training and the ability to attain your next career step within Barracuda.
  • Equity, in the form of non-qualifying options.
  • High-quality health benefits.
  • Retirement Plan with employer match.
  • Career-growth opportunities.
  • Flexible Time Off and Paid Time Off benefits.
  • Volunteer opportunities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service