
Principal Application Security Engineer
Barracuda Networks, Inc.2 hours ago
Ottawa, CanadaStaff+
Responsibilities
- Shape, grow, and lead Barracuda’s Application Security and Product Security programs.
- Embed security across the software development lifecycle and reduce late-stage findings through automation and developer enablement.
- Facilitate feature-level threat models, risk-based discussions, and identification of high-risk changes.
- Perform application penetration tests and security-focused source-code reviews.
- Drive risk rating and vulnerability management processes.
- Own and execute long-term security initiatives and workstreams across a complex multi-stakeholder business.
- Partner with product, platform, and engineering leaders on security initiatives, design reviews, and training.
- Mentor AppSec team members and help guide the broader security program.
- Build automation and leverage AI to support daily security tasks.
Requirements
- 8–10+ years of experience in product-focused Application Security.
- Deep practical knowledge of modern Application Security, Product Security, and Cloud security concepts.
- Hands-on experience building or growing AppSec and ProdSec programs in a product environment.
- Proven experience owning initiatives or impactful project scope over an extended period of at least one year.
- Strong threat-modeling skills, including facilitating lightweight feature-level threat models and driving risk-based discussions.
- Hands-on application penetration testing, source-code review, risk-rating, and vulnerability-management experience.
- Proficiency in at least two programming languages, such as TypeScript/JavaScript, Python, Ruby, Java, or Go.
- Ability to review code and provide framework-specific remediation guidance.
- Strong communication and presentation skills, including concise developer guidance, design reviews, and security training.
- Experience working cross-functionally with technical and non-technical teams.
- Hands-on experience building production-grade software is preferred.
- Applicable certifications such as OSCP, OSCE, or OSWE are preferred.
- Previous management or leadership experience is preferred.
Benefits
- Equity in the form of non-qualifying options.
- High-quality health benefits.
- Retirement plan with employer match.
- Career-growth opportunities, internal mobility, and cross-training.
- Flexible Time Off and Paid Time Off benefits.
- Volunteer opportunities.
- Hybrid work arrangement indicated by the #LI-hybrid tag.