> Markdown version of [/jobs/ext/215226-business-technology-security-principal](https://www.wearedevelopers.com/jobs/ext/215226-business-technology-security-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Business Technology Security Principal - **Company:** Waters - **Location:** United States - **Contract:** Permanent contract - **Skills:** .NET Framework, C Sharp (Programming Language), Open Web Application Security, Software Engineering, Software Security, AngularJS, Information Technology, Front End Software Development, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 30, 2026 - **Apply:** https://internationalcareers-waters.icims.com/jobs/25515/business-technology-security-principal/job?in_iframe=1 ## About the Role 1. Degree (or equivalent) in a Computer Science or Software Engineering discipline Experience required: 1. Solid experience in an Application Security or DevSecOps role. 2. Strong software engineering background, ideally including .NET and C#. 3. Experience securing applications built with .NET/C# and modern front-end frameworks such as Angular. 4. Strong understanding of secure software development lifecycle principles and major security frameworks (e.g., NIST, OWASP). 5. Ability to identify and remediate application security vulnerabilities beyond common patterns such as the OWASP Top 10. 6. Hands-on experience using common application security tooling (e.g., SAST, DAST, SCA). Aptitude/skills required: 1. Good written and oral communication skills are required, for example, to ensure succinct report generation, effective communication with staff, peer groups, etc., across the organisation. 2. Ability to work autonomously, manage personal workload effectively, and make thoughtful recommendations with limited guidance. 3. Ability to influence and collaborate with cross-functional teams at all levels of the organisation. ## Description To lead application security across a portfolio of on-premises software and applications. This role provides expert guidance, drives secure development practices, and leads key security activities such as threat modelling and backlog management. The Principal Applications Security Engineer works independently and collaborates with engineering teams and product stakeholders to continually strengthen the portfolio's security posture., Role Specific * Provide subject-matter expertise in identifying, assessing, and resolving application security issues across the product portfolio. * Lead threat modelling activities for new features and architectural changes, ensuring risks are well understood and addressed. * Guide development teams in adopting secure coding practices for .NET/C# and Angular applications. * Manage and prioritise the application security backlog, working independently to drive risk-based remediation with product teams. * Support and mature Security Champions, providing coaching, guidance, and security best practices. * Operate and improve existing application security tooling within CI/CD pipelines and influence future enhancements where appropriate. * Develop security guidance and automation that help shift security earlier in the development lifecycle. * Participate in architecture and security reviews, providing constructive and actionable feedback on designs. * Contribute to the ongoing adoption of NIST SSDF-aligned practices across the development lifecycle. Individual 1. Maintain the effectiveness of the Quality and Health, Safety and Environmental (HSE) system at the sites via adherence to applicable policies and procedures 2. Complete Quality and Health, Safety and Environmental (HSE) System related actions in a timely manner according to procedures e.g. CAPA, NCR Adhere to Health, Safety and Environmental (HSE) policies and procedures. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Stop Choosing JavaScript Frameworks and Start Living](https://www.wearedevelopers.com/videos/118-how-to-stop-choosing-javascript-frameworks-and-start-living) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)