Barracuda Networks

Principal Application Security Engineer

Barracuda Networks$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10+ years of experience in product-focused Application Security (AppSec) and Product Security (ProdSec).
  • Deep practical knowledge of core AppSec and ProdSec concepts, particularly in cloud environments.
  • Proven track record in building or growing AppSec and ProdSec programs in a product-focused setting.
  • Experience managing long-term security initiatives and workstreams over a year or more.
  • Proficient in threat modeling and able to facilitate risk-based discussions.
  • Hands-on experience with application penetration testing and security-focused source code reviews.
  • Programming proficiency in at least two languages such as TypeScript, Python, or Java.

Responsibilities

  • Lead and shape Barracuda's Application Security program to align with organizational goals.
  • Mentor and guide AppSec team members to enhance their capabilities.
  • Drive the integration of security practices into product development workflows.
  • Facilitate threat modeling sessions and manage risk discussions across tech stacks.
  • Oversee and execute security assessments, including penetration tests and code reviews.
  • Collaborate with cross-functional teams to promote security initiatives effectively.
  • Deliver concise, developer-friendly security guidance and training.

Benefits

  • Internal mobility opportunities for career advancement and cross-training.
  • Equity in the form of non-qualifying options.
  • Comprehensive health benefits for employee well-being.
  • Retirement plan with employer matching contributions.
  • Flexible Time Off and Paid Time Off benefits for work-life balance.
  • Opportunities for community involvement through volunteer programs.
Full Job Description
Role Overview:

As a Principal Application Security Engineer, you will be tasked with shaping, growing, and leading Barracuda's Application Security program. Additionally, as the most senior member of the AppSec team, you will have the opportunity to provide mentorship to other team members and have a say in the direction of the overarching security program and initiatives.

Candidates should have deep expertise in modern Application Security and Product Security practices, have experience defining and growing appsec/prodsec programs, be familiar with product development workflows/lifecycles, and have experience owning, planning, and executing initiatives across a complex multi-stakeholder business setting.

Core requirements:
  • 8-10+ years in product-focused AppSec: Able to move orgs from reactive pen-test/documentation-heavy to proactive guardrail-driven programs. Has a track record of embedding security across the development life cycle and reducing late-stage findings via automation and developer enablement.
  • Strong understanding of modern AppSec and ProdSec concepts: Deep practical (hands-on) knowledge of core security concepts across AppSec, ProdSec, and Cloud.
  • Experience building/growing AppSec and ProdSec programs: Hands-on experience building or growing modern AppSec/ProdSec programs in a product environment.
  • Hands-on experience owning long-term initiatives: Experience and a proven track record of owning workstreams, initiatives, or impactful project scope over an extended (year+) period.
  • Proficient in Threat Modeling: Can facilitate lightweight, feature-level threat models, drive risk-based discussions, and flag high-risk changes across a broad spectrum of tech stacks and product designs.
  • Hands-on security assessment experience: Has strong hands-on experience performing application penetration tests, conducting security-focused source code reviews, driving risk rating and vulnerability management processes.
  • Programming proficiency: Proficient in at least two programming languages (TypeScript/JavaScript, Python, Ruby, Java, Go, etc.). Able to review code and provide framework-specific remediation guidance.
  • Strong communication and presentation skills: Able to provide concise and practical developer-friendly guidance. Can partner with product, platform, and engineering leads to drive security initiatives. Comfortable leading short, outcome-focused design review discussions and security trainings.

Ideal candidate also has:
  • A strong sense of ownership and community within the team
  • Ability to build automation and successfully leverage AI to facilitate daily tasks
  • Hands-on experience building production-grade software
  • Experience working cross-functionally with technical and non-technical teams

Nice-to-have:
  • Applicable certifications such as OSCP, OSCE, OSWE, etc.
  • Previous management/leadership experience
  • Excited and passionate about application security and software development.

What you'll get from us

A team where you can voice your opinion, make an impact, and where you and your experience are valued. Internal mobility - there are opportunities for cross training and the ability to attain your next career step within Barracuda.
  • Equity, in the form of non-qualifying options
  • High-quality health benefits
  • Retirement Plan with employer match
  • Career-growth opportunities
  • Flexible Time Off and Paid Time Off benefits
  • Volunteer opportunities


#LI-hybrid

About Barracuda Networks

Barracuda Networks is a provider of cloud-enabled security and data protection solutions for businesses. The company was founded in 2003 and is headquartered in Campbell, California. Barracuda Networks offers a range of products, including firewalls, email security, network security, and data protection solutions. The company's solutions are designed to protect against cyber threats, including malware, ransomware, and phishing attacks. Barracuda Networks serves customers in a variety of industries, including healthcare, finance, and education.
Learn more about Barracuda Networks
Size
1,500 employees
Industry
Founded
2003

Similar Jobs

More Jobs at Barracuda Networks

More Information Technology Jobs

Find similar Principal Application Security Engineer jobs: