MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Application Security Lead

iHerb

Full-time
USA
$177k-$265k per year
security
devops
docker
aws
architecture
Apply for this position

Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the globe? We are looking for a hands-on Principal Application Security Engineer to lead our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role can be fully remote and must reside in US.

In this role, you will function as the ultimate subject matter expert, responsible for establishing enterprise-wide security architecture, driving deep-level technical mitigations, and ensuring compliance excellence in a complex, fast-paced environment. This role requires unparalleled technical depth and strategic foresight.

Responsibilities Include:

● Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge security development lifecycle (SDL) practices ● Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services across the entire platform ● Establish secure architecture standards, frameworks, and resilient security patterns spanning application, cloud-native, and infrastructure layers ● Evaluate, prototype, implement, operate, and provide governance over core security tools and services (DAST, SAST, SCA, WAF, Secrets Management, etc.) ● Discover and analyze emerging security threats, determining applicability to iHerb, and proactively implement centralized mitigations ● Maintain a strong knowledge of current security threats and operational best practices ● Drive our security assessment, penetration testing, and bug bounty programs translating findings into comprehensive, systemic risk reduction strategies. ● Ensure all application security practices adhere to the Payment Card Industry Data Security Standard (PCI DSS) requirements ● Participate in security incident response activities as a technical leader

In order to be successful in this role you must have:

● Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with an innate ability to translate technical vulnerabilities into organizational risks ● 8+ years of technical security experience at a top-tier software company, including hands-on experience with threat modeling, security design, security architecture, cryptography, mobile security, cloud computing technologies, and security products ● Expert understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…) ● Deep, demonstrable knowledge of the e-commerce transaction lifecycle and expert command of PCI DSS compliance standards within a high-transaction environment. ● Proven track record of driving the implementation of SDL processes, technology, and automation in sophisticated DevOps/DevSecOps environments. ● Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption ● Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

● Exceptional problem solving, critical thinking, collaboration and communication skills with the ability to influence technical and executive leadership

Bonus Qualifications:

● Experience in an e-commerce or high-transaction environment, specifically with knowledge of PCI DSS compliance requirements ● Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker/containers ● Experience driving application security training, security champions and awareness campaigns ● Active contributor to the security community (research, open source, publications…) with the ability to attract and hire great talent ● Relevant security certifications (e.g., OSCP, CISSP, CSSLP)

#LI-JC1

The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work.  The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc.  iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations. Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year.  Eligibility requirements for these benefits will be controlled by applicable plan documents. Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies. For more information on iHerb benefits, visit us at iHerbBenefits.com.

Anticipated Pay Scale:

$176,534—$264,801 USD

Apply for this position
Bookmark Report

About the job

Full-time
USA
Senior Level
$177k-$265k per year
Posted 3 hours ago
security
devops
docker
aws
architecture

Apply for this position

Bookmark
Report
Enhancv advertisement
+ 1,284 new jobs added today
30,000+
Remote Jobs

Don't miss out — new listings every hour

Join Premium

Application Security Lead

iHerb

Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the globe? We are looking for a hands-on Principal Application Security Engineer to lead our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role can be fully remote and must reside in US.

In this role, you will function as the ultimate subject matter expert, responsible for establishing enterprise-wide security architecture, driving deep-level technical mitigations, and ensuring compliance excellence in a complex, fast-paced environment. This role requires unparalleled technical depth and strategic foresight.

Responsibilities Include:

● Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge security development lifecycle (SDL) practices ● Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services across the entire platform ● Establish secure architecture standards, frameworks, and resilient security patterns spanning application, cloud-native, and infrastructure layers ● Evaluate, prototype, implement, operate, and provide governance over core security tools and services (DAST, SAST, SCA, WAF, Secrets Management, etc.) ● Discover and analyze emerging security threats, determining applicability to iHerb, and proactively implement centralized mitigations ● Maintain a strong knowledge of current security threats and operational best practices ● Drive our security assessment, penetration testing, and bug bounty programs translating findings into comprehensive, systemic risk reduction strategies. ● Ensure all application security practices adhere to the Payment Card Industry Data Security Standard (PCI DSS) requirements ● Participate in security incident response activities as a technical leader

In order to be successful in this role you must have:

● Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with an innate ability to translate technical vulnerabilities into organizational risks ● 8+ years of technical security experience at a top-tier software company, including hands-on experience with threat modeling, security design, security architecture, cryptography, mobile security, cloud computing technologies, and security products ● Expert understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…) ● Deep, demonstrable knowledge of the e-commerce transaction lifecycle and expert command of PCI DSS compliance standards within a high-transaction environment. ● Proven track record of driving the implementation of SDL processes, technology, and automation in sophisticated DevOps/DevSecOps environments. ● Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption ● Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

● Exceptional problem solving, critical thinking, collaboration and communication skills with the ability to influence technical and executive leadership

Bonus Qualifications:

● Experience in an e-commerce or high-transaction environment, specifically with knowledge of PCI DSS compliance requirements ● Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker/containers ● Experience driving application security training, security champions and awareness campaigns ● Active contributor to the security community (research, open source, publications…) with the ability to attract and hire great talent ● Relevant security certifications (e.g., OSCP, CISSP, CSSLP)

#LI-JC1

The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work.  The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc.  iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations. Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year.  Eligibility requirements for these benefits will be controlled by applicable plan documents. Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies. For more information on iHerb benefits, visit us at iHerbBenefits.com.

Anticipated Pay Scale:

$176,534—$264,801 USD

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Reviews
Job Alerts

Job Skills
Jobs by Location
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.