Dayforce

Application Security Engineer Principal

United States
C# Java Python API OAuth2 OIDC Azure AWS IAM Docker CI/CD SAST DAST Burp sqlmap
Description

Application Security Engineer Prin

Location: United States

Dayforce is a global human capital management (HCM) company headquartered in Toronto, Ontario, and Minneapolis, Minnesota, with operations across North America, Europe, Middle East, Africa (EMEA), and the Asia Pacific Japan (APJ) region. 

 

Our award-winning Cloud HCM platform offers a unified solution database and continuous calculation engine, driving efficiency, productivity and compliance for the global workforce.

 

Our brand promise - Makes Work Life Better - Reflects our commitment to employees, customers, partners and communities globally. 

 

About the opportunity

As an Application Security Engineer, you’ll play a critical role in helping our engineering teams design and build secure, resilient applications. You’ll lead hands-on product security assessments, collaborate on secure architecture and threat modeling, and influence engineering practices to raise the bar for software security across our organization.

What you'll get to do

Lead product security reviews: Drive security assessments across applications and services - including web applications, APIs, and microservices -through code reviews, threat modeling, and dynamic/static analysis. 

Influence architecture and design: Serve as a security thought partner for product architects and engineers. You'll guide threat modeling efforts, assess technical risk, and champion security best practices throughout the SDLC.

Drive strategic initiatives: Own high-impact security projects that shape the future of our product security posture. Past initiatives have included supply chain security automation, advanced SAST/DAST integrations, and secure development training programs.

Identify and support remediation of vulnerabilities: Leverage available tools (e.g., static/dynamic analysis, scanning platforms, and internal reports) to investigate security issues, assess root causes, and design effective remediation strategies. Partner closely with engineering teams to provide guidance and support throughout the implementation of fixes, ensuring they align with security best practices.

Enable engineering teams: Scale security through enablement: Build frameworks, guidance, and tooling that empower engineering teams to independently build secure systems. Act as a mentor and subject matter expert across teams.

Skills and experiences we value 

  • Hands-on experience in application or product security, with a strong foundation in software engineering and secure system design
  • Strong technical depth, with experience in at least one modern programming language (e.g. C#, Java, Python)
  • Strong understanding of API security principles, including authentication and authorization models (OAuth2, OIDC), token-based security, and common API vulnerabilities
  • Familiarity with secure CI/CD practices and software supply chain security
  • Cloud security expertise, particularly in Azure and/or AWS, including familiarity with IAM, containerization, networking, and native security controls
  • Experience defining or scaling application security programs, practices, or tooling in a cloud-native environment
  • Proven ability to analyze complex systems and codebases, especially within distributed, microservices-based environments
  • Excellent communication skills, with the ability to clearly articulate risk and security trade-offs to technical and non-technical stakeholders
  • Experience with static and dynamic analysis tools, Atlassian suite and pentesting tools (Burp, sqlmap)
  • Ability to perform black-box and grey-box testing of web applications and APIs 

What would make you really stand out

  • Prior experience in a SaaS or cloud-native environment
  • Contributions to open-source security tools or research
  • CISSP, CEH/OSCP certifications

What’s in it for you

Dayforce is fueled by the diversity of our talented employees. We are an equal opportunity employer and consider and embrace ALL individuals and what makes them unique. We believe our employees should be happy and healthy, with peace of mind and a sense of fulfillment.

We encourage individuals to apply based on their passions.

Dayforce encourages personal and professional growth. We offer excellent time away from work programs, comprehensive wellness initiatives and recognition through competitive pay and benefits.

With a commitment to community impact, including volunteer days and our charity, Dayforce Cares we provide opportunities for you to thrive both in your career and personal life. Our focus is not just on your job but on supporting you to be the best version of yourself. 

About the Salary Ranges  

Please note that the salary range mentioned in this job description should serve simply as a guide. The final compensation offered may vary based on a variety of factors, including bonuses and/or incentives, or a candidate’s experience, skills, budget and location. Our company is committed to providing a fair, equitable, and competitive package that reflects the value an individual brings to the organization. 

Fraudulent Recruiting

Beware of fraudulent recruiting. Legitimate Dayforce contacts will use an @dayforce.com email address. We do not request money, checks, equipment orders, or sensitive personal data during the recruitment process. If you have been asked for any of the above, or believe you have been contacted by someone posing as a Dayforce employee, please refer to our fraudulent recruiting statement found here: https://www.dayforce.com/be-aware-of-recruiting-fraud

Dayforce actively monitors all job applications to ensure authenticity. Submissions determined to be fraudulent or misleading will be declined from the recruitment process

#LI-Remote

Dayforce
Dayforce

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say