> Markdown version of [/jobs/ext/871476-sr-principal-security-engineer-application-security-automation](https://www.wearedevelopers.com/jobs/ext/871476-sr-principal-security-engineer-application-security-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Principal Security Engineer, Application Security & Automation - **Company:** The Lilly Company - **Location:** Indianapolis, IN, United States (Remote available) - **Experience:** Expert - **Salary:** $126,000.0 - $224,400.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), Cloud Computing Security, Cyber Security, Continuous Integration, Github, Python (Programming Language), Key Management, OpenID, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, TypeScript, Software Vulnerability Management, Cloud Platform System, Large Language Models, Prompt Engineering, Software Security, Cloudformation, Build Management, Containerization, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Tenable Nessus, Terraform, Docker, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** June 13, 2026 - **Apply:** https://dejobs.org/x/x/D3A2D391CFCD4CCE8A68005AB9B34933/job/ ## About the Role * Bachelor's Degree in Computer Science, Information Security, Software Engineering, or related fields. * At least 2 years of dedicated application security experience * At least 2 years of software development experience with individual contributions to production systems, * At least a total of 5 years of combined experience across both rigors. * Proven production coding experience in at least one of: Python, TypeScript/JavaScript, Java, Go, or C# - not solely in an advisory, review, or scripting capacity. * Experience building or integrating security automation within a GitHub environment, including GitHub Actions. * Familiarity with threat modeling in a professional setting * Hands-on experience with large language models (LLMs) in a professional or project context, such as prompt engineering, API integration, or workflow automation. What You Should Bring: * Hands-on software development experience in at least one modern language (Python, TypeScript/JavaScript, Java, Go, or C#) with a track record of shipping working code- not just reviewing others'. * Strong expertise in application security fundamentals-OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability assessment. * Experience operating or deeply integrating with SAST, DAST, SCA, and secret scanning tools. * Genuine enthusiasm for and hands-on experience with LLMs, prompt engineering, agentic workflows, or LLM-powered tooling-bonus points for things you have actually built and shipped. * Familiarity with secrets management platforms and patterns and with software supply chain / artifact management. * Working knowledge of cloud environments (AWS preferred; Azure or GCP welcome) and containerized workloads (ECS, EKS, Docker). * Familiarity with IaC scanning and the IaC ecosystem (Terraform, CloudFormation, Kubernetes manifests) * Strong communication skills; ability to translate security requirements into actionable engineering guidance and to represent AppSec in conversations with engineering partners. * Commitment to staying ahead of with emerging AppSec threats, tooling, and AI/LLM capabilities. ## Description * Evolve one or more AppSec platforms within the Secure SDLC program. * Design and build automation within Security Architecture and Engineering. * Apply LLMs, agentic frameworks, MCP servers, and tool-calling patterns. * Partner with development teams on secure coding practices, threat modeling, and remediation of findings from SAST, DAST, SCA, and secret scanning tools. * Contribute to Lilly's Secure SDLC standards and vulnerability management policy, translating policy into enforceable pipeline and platform controls. * Support the secrets management rollout and migration of applications off legacy secret stores, including code-level guidance for SDK-based and injected consumption patterns. * Produce developer-facing content, reference architectures, secure patterns, short-form instructional content and reusable code samples. * Harden Lilly's CI/CD environment against software supply chain attacks- pinned actions, OIDC-based cloud auth, runner isolation, workflow permissions, and protection of build-time secrets and artifacts. * Partner with the Cloud Security team on Infrastructure-as-Code (IaC) security - extending secure-by-default patterns and developer guardrails from application code into the infrastructure that runs it., This role is based at our Corporate Center in Indianapolis, IN . We offer a flexible hybrid work model, with three days onsite and two days working remotely each week , supporting both collaboration and work-life balance. We are also open to considering fully remote candidates based on role requirements and business needs. Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form ( https://careers.lilly.com/us/en/workplace-accommodation ) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)