Principal Security Engineer, Applications

2 weeks ago


Boston, United States CarGurus Full time
Principal Security Engineer, Applications

CarGurus

Unbiased car reviews and over a million opinions and photos from real people. Use CarGurus to find the best used car deals.

At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years.

What we do

The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. But they're not the only ones who love CarGurus—our employees do, too. We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride

Role overview

As a Principal Application Security Engineer, you’ll lead the charge in securing our product offerings, applying risk-based methodologies to vulnerabilities, and partnering with application and platform engineering teams for threat modeling, reporting to our Director of Information Security. This is a highly technical individual contributor role, ideal for someone with hands-on expertise who is excited to mentor and eventually grow into a leadership position.

What you'll do

Core Responsibilities:

  • Coordinate business strategy, security design and review activities with various company teams.
  • Define security architecture and security controls.
  • Provide design and oversight into infrastructure security architectures.
  • Provide design and oversight into cloud security architectures.
  • Provide strategic consultation to business units, identifying and addressing potential security gaps, and advising on the necessary involvement of the security organization in various projects.
  • Apply risk-based methodologies to evaluate, prioritize, and address vulnerabilities and security findings.
  • Serve as a bridge between business and security teams, facilitating communication and ensuring security requirements are integrated efficiently into business processes.
  • Research and implement new security tools, frameworks, and processes to enhance our security posture.

Vulnerability and Risk Management:

  • Advise software development and engineering teams to ensure that data collection, storage, transmission, and usage throughout development are transparent, security focused, and mitigate risk.
  • Provide technical leadership and oversight to application security activities and initiatives.
  • Oversee bug bounty and threat researcher programs.
  • Provide technical leadership and oversight to vulnerability threat management activities and initiatives.
  • Provide technical leadership and oversight to penetration testing activities and initiatives.
  • Provide security oversight and design guidance to the DevOps process.
  • Develop metrics to measure the application security program.
  • Establish automated configurations to enhance user access controls.

Mentorship and Collaboration:

  • Educate and guide engineers on secure coding practices.
  • Mentor junior team members and foster a culture of continuous learning.
  • 7–12 years as an application security practitioner, including 3–5 years in security architecture.
  • Strong knowledge of web/application-layer security, attack vectors, and secure coding practices.
  • Experience conducting application threat modeling and performing in-depth security assessments.
  • Familiarity with frameworks like OWASP, CVSS, NIST, and CIS.
  • Proven expertise with SSO, RBAC models, OAuth 2.0, and other identity solutions.

Nice-to-Have Qualifications:

  • GIAC certifications (e.g., GWAPT) or CISSP/CSSP.
  • Hands-on experience integrating security into product and software development initiatives.
  • Track record of developing and scaling application security programs.

Working at CarGurus

We reward our Gurus’ curiosity and passion with best-in-class benefits and compensation, including equity for all employees, both when they start and as they continue to grow with us. Our career development and corporate giving programs, as well as our employee resource groups (ERGs) and communities, help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch, a new car discount, meditation and fitness apps, commuting cost coverage, and more help our people create space for what matters most in their personal and professional lives.

We welcome all

CarGurus strives to be a place to which people can bring the ultimate expression of themselves and their potential—starting with our hiring process. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We foster an inclusive environment that values people for their skills, experiences, and unique perspectives. That’s why we hope you’ll apply even if you don’t check every box listed in the job description. We also encourage you to tell your recruiter if you require accommodations to participate in our hiring process due to a disability so we can provide the appropriate support. We want to know what only you can bring to CarGurus. #LI-Hybrid

#J-18808-Ljbffr

  • Boston, United States CarGurus Full time

    Who we areAt CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we're the largest and fastest-growing...


  • Boston, United States SimpliSafe Wireless Home Security Full time

    Principal Software Engineer - Video Team We’re a high-tech home security company that’s passionate about protecting the life you’ve built and our mission of keeping Every Home Secure. And we’ve created a culture here that cares just as deeply about the career you’re building. Ours is a no ego culture of collaboration and innovation where those...

  • Principal IT Security

    1 month ago


    Boston, United States Hireteq Solutions Inc. Full time

    Role: Principal IT Security (PAM Engineering)Location: Boston, MA, NJ, Tampa, FL, Dallas, TX, Mclean, VASalary - DOEThis is a Full-time/Permanent Position with our Client (Visa sponsorship is not available for this role)QUALIFICATIONS:Minimum of 8 years of experience in Information Security, including at least 3 years specializing in Privileged Access...


  • Boston, United States SimpliSafe Wireless Home Security Full time

    About SimpliSafe We're a high-tech home security company that's passionate about protecting the life you've built and our mission of keeping Every Home Secure. And we've created a culture here that cares just as deeply about the career you're building. Ours is a no ego culture of collaboration and innovation where those seeking their next challenge can find...


  • Boston, United States SimpliSafe Wireless Home Security Full time

    About SimpliSafe We're a high-tech home security company that's passionate about protecting the life you've built and our mission of keeping Every Home Secure. And we've created a culture here that cares just as deeply about the career you're building. Ours is a no ego culture of collaboration and innovation where those seeking their next challenge can find...


  • Boston, United States Aqua Security Full time

    Aqua Security is a global leader in cloud-native security, safeguarding software infrastructure from development to production. As a rapidly growing player in the cloud-native security space, we champion innovation, collaboration, and growth. We're seeking a talented Security Engineer to join our elite Security team and enhance our vulnerability management...


  • Boston, United States Fresenius Kabi USA, LLC Full time

    Job SummaryThe Principal Cybersecurity Engineer, under minimal supervision, provides hands-on product security engineering, encompassing various aspects of medical device cybersecurity for devices with embedded and web applications. Actively engages in all stages of secure product development, with a particular emphasis on threat modeling, vulnerability...


  • Boston, United States Fresenius Kabi USA, LLC Full time

    Job Summary The Principal Cybersecurity Engineer, under minimal supervision, provides hands-on product security engineering, encompassing various aspects of medical device cybersecurity for devices with embedded and web applications. Actively engages in all stages of secure product development, with a particular emphasis on threat modeling, vulnerability...


  • Boston, United States CloudZero Full time

    About the Role: CloudZero is seeking our first Senior Application Security Engineer. In this pivotal role, you will shape the security framework of our market-leading cloud cost intelligence platform, addressing some of the most critical challenges cloud-driven businesses face today. You will establish and champion best-in-class security practices, ensuring...


  • Boston, United States ZipRecruiter Full time

    Job Description Every day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced "sneak") comes in. Snyk is a developer security platform that makes it easy...


  • Boston, United States Snyk Full time

    Every day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced "sneak") comes in. Snyk is a developer security platform that makes it easy for development...


  • Boston, United States ZipRecruiter Full time

    Job DescriptionJob Description Every day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced "sneak") comes in. Snyk is a developer security platform...


  • Boston, United States Compunnel Inc. Full time

    Job Title: Principal SaaS Security Specialist - W2 only - We can provide sponsorship Duration: Long Term Location: Boston, MA/Salt Lake City, UT - Hybrid - 2 weeks in a month onsiteMust Have: SaaS tools (Archer, Reckon, etc)Programming knowledge in Python, or equivalent scriptingExperience with DevOps is a plusExperience with creating and maintaining Data...


  • Boston, United States Compunnel Inc. Full time

    Job Title: Principal SaaS Security Specialist - W2 only - We can provide sponsorship Duration: Long Term Location: Boston, MA/Salt Lake City, UT - Hybrid - 2 weeks in a month onsiteMust Have: SaaS tools (Archer, Reckon, etc)Programming knowledge in Python, or equivalent scriptingExperience with DevOps is a plusExperience with creating and maintaining Data...

  • Principal Engineer

    4 weeks ago


    Boston, United States ZipRecruiter Full time

    Job DescriptionJob title: Principal Engineer – Mechanical EngineeringLocation: Weymouth – We offer a range of hybrid and flexible working arrangements – please speak to your recruiter about the options for this particular roleSalary: Circa £55,000What you’ll be doing:Taking ownership of specific Mechanical design issues and managing Integrated...


  • Boston, United States Snyk Full time

    Job DescriptionJob DescriptionEvery day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced "sneak") comes in. Snyk is a developer security platform that...


  • Boston, United States Experis Full time

    Our client, a leader in the technology sector, is seeking a Principal Software Engineer to join their team. As a Principal Software Engineer, you will be part of the Software Engineering department supporting the OpenShift AI team. The ideal candidate will have strong communication skills, a collaborative mindset, and a passion for innovation which will...


  • Boston, United States Oracle Full time

    Oracle Senior Principal Software Engineer Boston, Massachusetts Apply NowWe are building a new Software Assurance Gateway team at OCI. Our mission is to build and operate a set of gateway services to ensure the security and integrity of the services running within a customer’s tenancy. The team will develop, maintain and operationalize this new class of...


  • Boston, United States Wasabi Full time

    At Wasabi, we’re a proven collection of pioneers, visionaries and disruptive doers. We see things differently than our competitors, and we make our mark in the industry by challenging the norm and delivering the unexpected and improbable. We’re a fast-growing company taking the Cloud Storage industry by storm and recognized as one of the best places to...


  • Boston, United States Analog Devices Full time

    Principal AI Platform Engineer Apply locations US, CA, San Jose, Rio Robles US, MA, Boston Time type: Full time Posted on: Posted 3 Days Ago Job requisition id: R240791 Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital,...