Lilly is a global biotechnology and pharmaceuticals healthcare company. Founded by Colonel Eli Lilly in 1876, the company is based in Indianapolis, Indiana, and maintains a strong
Senior Principal Security Engineer, Application Security and Automation
Location
Indiana
Posted
36 days ago
Salary
$126K - $224.4K / year
Seniority
Senior
Job Description
Senior Principal Security Engineer, Application Security and Automation
Lilly
Title: Sr. Principal Security Engineer, Application Security & Automation Location: Remote United States Full time Job Description: At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We're looking for people who are determined to make life better for people around the world. As an Application Security Engineer your role is focused on advancing Lilly's Secure SDLC program through engineering, automation, and applied AI. This is a critical, builder role on the Security Architecture & Engineering (SAE) team that will own and evolve core AppSec platforms- SAST, DAST, SCA, secret scanning, secrets management, and software supply chain controls- while building the automation and AI tooling that can scale across thousands of repositories and hundreds of applications. We're targeting candidates at R4-6. Job description is below. What You'll Be Doing: As an Application Security Engineer, you will operate at the intersection of software engineering and security engineering- leading platforms, writing code, building integrations, and designing automation. You will take part in Lilly's Secure SDLC program end-to-end, including SAST, DAST, SCA, and secret scanning tooling; secrets management; and our emerging software supply chain capabilities. You will use technology and apply LLM-based approaches to secure application and architecture design, vulnerability triage and remediation, and the delivery of secure‑by‑default patterns across Lilly's development ecosystem. How You'll Succeed: - Engineering-first mentality: You bring real software development experience and treat security problems as engineering problems, automating what can be automated, integrating deeply with developer workflows, and writing production-quality code. - AI fluency: You are genuinely excited about LLMs and agentic tooling and have built things with them. You understand MCP, agent harnesses, and how to wire LLMs into real workflows - and you can tell where AI meaningfully accelerates security work versus where it shouldn't be trusted. - Platform management: Success requires running AppSec tooling as platforms with clear SLAs, telemetry, and continuous improvement rather than one-off scans and tickets. - Secure coding credibility: You have written code in multiple languages and ecosystems and can speak the developer's language. When you flag a finding or propose a control, engineers trust that you understand the tradeoffs. - Developer partnership: You build leverage through partnership-meeting development teams where they are, shipping secure-by-default patterns, and making the secure path the path of the least resistance. - Build system security: You understand that CI/CD is itself a high-value target. You have opinions on GitHub Actions OIDC, pinning actions to commit SHAs, least-privilege runners, and protecting secrets and artifacts as they move through the pipeline. Key Responsibilities: - Evolve one or more AppSec platforms within the Secure SDLC program. - Design and build automation within Security Architecture and Engineering. - Apply LLMs, agentic frameworks, MCP servers, and tool-calling patterns. - Partner with development teams on secure coding practices, threat modeling, and remediation of findings from SAST, DAST, SCA, and secret scanning tools. - Contribute to Lilly's Secure SDLC standards and vulnerability management policy, translating policy into enforceable pipeline and platform controls. - Support the secrets management rollout and migration of applications off legacy secret stores, including code-level guidance for SDK-based and injected consumption patterns. - Produce developer-facing content, reference architectures, secure patterns, short-form instructional content and reusable code samples. - Harden Lilly's CI/CD environment against software supply chain attacks- pinned actions, OIDC-based cloud auth, runner isolation, workflow permissions, and protection of build-time secrets and artifacts. - Partner with the Cloud Security team on Infrastructure-as-Code (IaC) security - extending secure-by-default patterns and developer guardrails from application code into the infrastructure that runs it. Your Basic Qualifications: - Bachelor's Degree in Computer Science, Information Security, Software Engineering, or related fields. - At least 2 years of dedicated application security experience - At least 2 years of software development experience with individual contributions to production systems, - At least a total of 5 years of combined experience across both rigors. - Demonstrated production coding experience in at least one of: Python, TypeScript/JavaScript, Java, Go, or C# - not solely in an advisory, review, or scripting capacity. - Experience building or integrating security automation within a GitHub environment, including GitHub Actions. - Familiarity with threat modeling in a professional setting - Hands-on experience with large language models (LLMs) in a professional or project context, such as prompt engineering, API integration, or workflow automation. What You Should Bring: - Hands-on software development experience in at least one modern language (Python, TypeScript/JavaScript, Java, Go, or C#) with a track record of shipping working code- not just reviewing others'. - Strong expertise in application security fundamentals-OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability assessment. - Experience operating or deeply integrating with SAST, DAST, SCA, and secret scanning tools. - Genuine enthusiasm for and hands-on experience with LLMs, prompt engineering, agentic workflows, or LLM-powered tooling-bonus points for things you have actually built and shipped. - Familiarity with secrets management platforms and patterns and with software supply chain / artifact management. - Working knowledge of cloud environments (AWS preferred; Azure or GCP welcome) and containerized workloads (ECS, EKS, Docker). - Familiarity with IaC scanning and the IaC ecosystem (Terraform, CloudFormation, Kubernetes manifests) - Strong communication skills; ability to translate security requirements into actionable engineering guidance and to represent AppSec in conversations with engineering partners. - Commitment to staying ahead of with emerging AppSec threats, tooling, and AI/LLM capabilities. Location & Work Flexibility This role is based at our Corporate Center in Indianapolis, IN. We offer a flexible hybrid work model, with three days onsite and two days working remotely each week, supporting both collaboration and work‑life balance. We are also open to considering fully remote candidates based on role requirements and business needs. Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status. Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia Network, Black Employees at Lilly, Chinese Culture Network, Japanese International Leadership Network (JILN), Lilly India Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ+ Allies), Veterans Leadership Network (VLN), Women's Initiative for Leading at Lilly (WILL), enAble (for people with disabilities). Learn more about all of our groups. Actual compensation will depend on a candidate's education, experience, skills, and geographic location. The anticipated wage for this position is $126,000 - $224,400 Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly's compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees. #WeAreLilly
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Biosecurity Research Specialist
Weekday (YC W21)We are a Y-Combinator-backed startup building your AI-powered Recruiter Agent
Role Description We are seeking highly qualified scientists to contribute to a research initiative focused on building a strong scientific knowledge layer for advanced analytical systems. In this role, you will apply your expertise in biological sciences to: - Provide expert insight into biological feasibility, pathogen behavior, and experimental design - Review and interpret scientific literature across relevant biological and biosecurity-related domains - Evaluate laboratory methodologies and protocols for accuracy and relevance - Contribute structured, high-quality feedback to support research and model development - Apply scientific rigor to ensure outputs align with established biological principles Qualifications - PhD in Biology, Microbiology, Virology, Immunology, or a closely related field - Strong foundation in molecular and cellular biology concepts - Ability to critically analyze and synthesize complex scientific information Requirements - Hands-on experience with molecular biology techniques such as cloning, PCR, and cell culture - Demonstrated publication record in relevant scientific domains - Experience interpreting primary research literature, particularly in biosecurity-adjacent areas - Strong written communication skills with high attention to detail Benefits - Independent contractor role - Fully remote with flexible, self-managed schedule - Competitive compensation based on expertise and experience - Weekly payments via supported global payment platforms Additional Information - Work must not involve sharing confidential or proprietary information from any current or previous employer or institution - Projects may be extended, shortened, or concluded based on performance and business needs - This opportunity does not currently support certain work authorization categories Equal Opportunity Statement All qualified applicants will be considered without regard to legally protected characteristics. Reasonable accommodations are available upon request.
• Own pipeline creation strategy and execution for the cybersecurity services segment, from targeting through handoff to sales • Build and optimize multi-channel campaigns (digital, events, email, partner, and outbound support) to create marketing-sourced and influenced pipeline • Measure, forecast, and improve funnel conversion and deal velocity, tying activities directly to segment revenue goals • Define and continuously refine ICP, personas, and segment positioning across the vertical(s) the company serves • Lead competitive intelligence and market messaging frameworks, translating technical capabilities into outcome-oriented narratives aligned to compliance and risk-reduction drivers • Partner closely with product marketing, delivery, and sales leadership to align GTM priorities, support new offering launches, and bring segment-level market intelligence into positioning decisions • Create persona- and stage-specific enablement bundles (decks, one-pagers, talk tracks, short videos, email sequences) that support both technical and non-technical sellers • Develop battlecards, competitive matrices, and objection-handling frameworks for key competitors and alternatives (status quo, in-house, etc.) • Support cross-sell motions across the full portfolio by designing campaigns and enablement that help legacy reps and acquired sellers confidently introduce cybersecurity services into existing accounts • Use buyer insights, campaign performance data, and regular feedback loops with sales leadership to continuously improve enablement effectiveness and shorten time-to-close
Application Security Principal
Quantum HealthQuantum Health offers solutions and expertise to help consumers navigate the healthcare system. The award-winning company has hired in the past for 100% work-from-home opportunitie
Title: Application Security Principal Location: Dublin, Ohio Department: Information Technology Job Description: Description Who we are Founded in 1999 and headquartered in Central Ohio, we’re a privately-owned, independent healthcare navigation organization. We believe that no one should have to navigate the cost and complexity of healthcare alone, and we’re on a mission to make healthcare simpler and more effective for our millions of members. Our big-hearted, tech-savvy team fights to ensure that our members get the care they need, when they need it, at the most affordable cost – that’s why we call ourselves Healthcare Warriors®. We’re committed to building diverse and inclusive teams – more than 2,000 of us and counting – so if you’re excited about this position, we encourage you to apply – even if your experience doesn’t match every requirement. About the role The Application Security Principal is a senior, hands-on security leader who reports directly to the Chief Information Security Officer (CISO) and is responsible for building, operating, and continuously improving the enterprise Application Security (AppSec) program. The role is deeply embedded within software engineering initiatives, working side-by-side with development teams to enable secure-by-design and secure-by-default software delivery. This leader focuses on teaching, mentoring, and influencing engineers to write secure code and to effectively use modern AppSec tools and automation to reduce risk while maintaining delivery velocity. The role operates in a regulated healthcare environment and ensures alignment with HIPAA and HITRUST requirements. Location: This position is located at our Dublin, OH campus or may work remotely anywhere in the United States of America. What you’ll do (Essential Responsibilities) - Create, own, and drive the enterprise Application Security program, including vision, strategy, roadmap, and operating model. - Embed within software engineering projects to provide hands-on guidance for secure design, coding, testing, and deployment practices. - Teach, mentor, and lead software engineers to improve secure coding skills and security decision-making throughout the SDLC. - Define and operationalize a secure SDLC, including threat modeling, secure design reviews, automated security testing, and release controls. - Own and optimize application security tooling and workflows, including Snyk, SonarCloud, GitHub Advanced Security, GitHub Copilot, Palisade, and related CI/CD integrations. - Establish developer-friendly remediation workflows, including prioritized findings, fix guidance, and automation where possible. - Partner with Engineering and Product leadership to align application security priorities with business objectives and delivery timelines. - Lead threat modeling and architectural risk assessments for new applications, APIs, and major enhancements. - Develop and track AppSec metrics and KPIs that demonstrate risk reduction, coverage, and program effectiveness. - Ensure application security controls and practices meet HIPAA Security Rule and HITRUST CSF requirements and support audit readiness. - Collaborate with infrastructure, cloud, and enterprise security teams on identity, secrets management, and secure platform patterns. - Support security incident response activities related to application vulnerabilities and contribute to root-cause analysis and long-term remediation. - Build and lead an application security champions or guild program to scale secure development practices across teams. - All other duties as assigned. What you’ll bring (Qualifications) - Experience: Extensive experience designing and leading application security programs within complex enterprise environments. - Strong background in software engineering with the ability to read, review, and reason about code for security issues. - Hands-on experience integrating and operating modern AppSec tools such as Snyk, SonarCloud, GitHub Advanced Security, and CI/CD pipelines. - Experience guiding developers in the effective and responsible use of AI-assisted development tools such as GitHub Copilot. - Deep understanding of secure SDLC principles, threat modeling methodologies, and common application vulnerability classes. - Experience securing cloud-native, API-driven, and microservices-based architectures. - Strong knowledge of healthcare regulatory requirements, including HIPAA and HITRUST, and their application to software development. - Proven ability to influence without authority and to build strong partnerships with engineering and product teams. - Excellent communication and teaching skills, with the ability to translate security concepts into practical developer guidance. - Demonstrated leadership, program management, and strategic planning capabilities. - A high degree of personal accountability and trustworthiness, a commitment to working within Quantum Health’s policies, values and ethics, and protecting the sensitive data entrusted to us. -- #LI-AK1 #LI-Hybrid #LI-Remote What’s in it for you - Compensation: Competitive base and incentive compensation - Coverage: Health, vision and dental featuring our best-in-class healthcare navigation services, along with life insurance, legal and identity protection, adoption assistance, EAP, Teladoc services and more. - Retirement: 401(k) plan with up to 4% employer match and full vesting on day one. - Balance: Paid Time Off (PTO), 7 paid holidays, parental leave, volunteer days, paid sabbaticals, and more. - Development: Tuition reimbursement up to $5,250 annually, certification/continuing education reimbursement, discounted higher education partnerships, paid trainings and leadership development. - Culture: Recognition as a Best Place to Work for 15+ years, dedication to diversity, philanthropy and sustainability, and people-first values that drive every decision. - Environment: A modern workplace with a casual dress code, open floor plans, full-service dining, free snacks and drinks, complimentary 24/7 fitness center with group classes, outdoor walking paths, game room, notary and dry-cleaning services and more! What you should know - Internal Associates: Already a Healthcare Warrior? Apply internally through Jobvite. - Process: Application > Phone Screen > Online Assessment(s) > Interview(s) > Offer > Background Check. - Diversity, Equity and Inclusion: Quantum Health welcomes everyone. We value our diverse team and suppliers, we’re committed to empowering our ERGs, and we’re proud to be an equal opportunity employer . - Tobacco-Free Campus: To further enable the health and wellbeing of our associates and community, Quantum Health maintains a tobacco-free environment. The use of all types of tobacco products is prohibited in all company facilities and on all company grounds. - Compensation Ranges: Compensation details published by job boards are estimates and not verified by Quantum Health. Details surrounding compensation will be disclosed throughout the interview process. Compensation offered is based on the candidate’s unique combination of experience and qualifications related to the position. - Sponsorship: Applicants must be legally authorized to work in the United States on a permanent and ongoing future basis without requiring sponsorship. - Agencies: Quantum Health does not accept unsolicited resumes or outreach from third-parties. Absent a signed MSA and request/approval from Talent Acquisition to submit candidates for a specific requisition, we will not approve payment to any third party. Recruiting Scams: Unfortunately, scams targeting job seekers are common. To protect our candidates, we want to remind you that authorized representatives of Quantum Health will only contact you from an email address ending in @quantum-health.com. Quantum Health will never ask for personally identifiable information such as Date of Birth (DOB), Social Security Number (SSN), banking/direct/tax details, etc. via email or any other non-secure system, nor will we instruct you to make any purchases related to your employment. If you believe you’ve encountered a recruiting scam, report it to the Federal Trade Commission and your state’s Attorney General.
Account Supervisor - Cyber Security
FleishmanHillardFleishmanHillard is an international, full-service communications firm offering brand marketing, crisis management, digital, social, media relations, public aff
Title: Account Supervisor - Cyber Security Location: New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United States; Washington, District of Columbia, United States Overview FleishmanHillard is the world’s most complete global communications firm, specializing in public relations, public affairs, marketing, paid media, and transmedia and social content. FleishmanHillard delivers on The power of true, reflecting the firm’s high values and unique ability to guide clients through a world demanding unprecedented authenticity and transparency. The San Francisco, DC, NY and Seattle offices have an immediate opening for an Account Supervisor to join us in a hybrid role in our rapidly expanding technology advisory practice. This position is ideal for someone who is energized by helping enterprise technology and cyber security companies differentiate not just through product hype, but through authentic storytelling that builds belief with key stakeholder audiences: investors, employees, policymakers, talent markets, and society. In this position, you'll lead the development and execution of media-first but not media-only communications programs that help reposition clients as strategic leaders rather than product vendors. Working collaboratively with senior team members and mentoring junior team members, you'll execute integrated communications campaigns that drive results. You’ll combine hands-on execution with the opportunity to shape how your clients lead authentically. FleishmanHillard values the importance of impact and inclusion to strengthen the bonds between us, grow our people and create spaces for everyone to thrive. We stay true to our commitment to our people and the communities in which we live and work. As part of our ongoing effort to be the world’s most inclusive agency, we are committed to seeking candidates who possess and demonstrate a profound interest in furthering our impact and inclusion goals. Responsibilities - Partner with senior team members to develop and execute communications strategies for mid-market and enterprise technology and cyber security clients, helping them build stakeholder confidence and differentiate competitively through authentic positioning. - Build and maintain media relationships by identifying appropriate media contacts, conducting regular outreach, scheduling interviews, and fostering strong connections with journalists in technology and business media. - Collaborate with senior team members and peers to develop strategic messaging frameworks and storytelling angles that translate complex technical innovation into clear, differentiated positioning for target audiences. - Manage day-to-day client relationships, synthesizing research and market intelligence to guide clients toward effective communication strategies. Take ownership of account execution while escalating strategic considerations to senior team members. - Develop messaging strategies and pitch angles that help clients understand and communicate the "why" behind their positioning with clarity and authenticity. - Lead the execution of integrated communications campaigns across PR, digital, social media, and employee communications channels, ensuring alignment with core narrative and coordinating across team members. - Research and analyze market trends and competitive dynamics to identify positioning opportunities and help clients understand their market positioning; recommend communications strategies to address competitive challenges. - Support account growth by identifying opportunities where integrated communications can strengthen client relationships and business outcomes—including product launches, hiring initiatives, and stakeholder engagement. Qualifications - 4-6 years of PR or communications agency experience with strong knowledge of technology and business fundamentals and demonstrated analytical and creative thinking capabilities. - Proven passion for media relations with a strong track record of building relationships with journalists in technology, cyber security, and business, in top tier and trade media. Consistent success in securing meaningful media coverage and understanding how to work with reporters to shape narratives. - Great project management and collaborative skills, including the ability to coordinate multiple work streams, mentor junior team members, and maintain quality and composure under tight deadlines in a fast-paced environment. - Solid experience executing integrated communications campaigns across multiple channels including earned media, owned media, social, and digital. Understanding of how to create cohesive campaigns that drive consistent messaging and results. - Ability to use research and data to inform strategic recommendations. Experience working with research and insights to interpret trends and metrics that shape client strategy and positioning decisions. - Strong written and verbal communication skills with ability to craft compelling client communications, strategic plans, talking points, and bylined content. Comfortable presenting ideas and recommendations in client meetings and internal settings. - Self-motivated and resourceful problem solver. Takes ownership of client success while maintaining focus on both day-to-day delivery and strategic opportunity. Our Story FleishmanHillard specializes in public relations, reputation management, public affairs, brand marketing, digital strategy, social engagement and content strategy. FleishmanHillard was named 2020, 2021 and 2022 Campaign Global PR Agency of the Year; 2023 ICCO Large Agency of the Year – The Americas; 2022 and 2023 PRWeek U.S. Agency of the Year; 2022 and 2023 PRWeek U.S. Outstanding Extra-Large Agency of the Year; 2023 Campaign US PR Agency of the Year; 2021 PRovoke APAC Consultancy of the Year; and 2021 PRWeek UK Large Consultancy of the Year. FleishmanHillard is part of Omnicom PR Group and has nearly 80 offices in more than 30 countries, plus affiliates in 45 countries. FleishmanHillard offers a hybrid work model, and seeks employees who are comfortable working in the office for a portion of their workweek. We value the collaboration and camaraderie that in-person interactions provide, but also understand the importance of flexibility and balance in our employees' lives. As such, we are open to discuss various work arrangements that accommodate individual needs and circumstances, including flexible scheduling and alternative work arrangements. Our goal is to foster a productive and inclusive work environment where all employees can thrive, both in and out of the office. FleishmanHillard is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sex stereotyping, pregnancy (which includes pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), gender, gender identity, gender expression, national origin, age, mental or physical disability, ancestry, medical condition, marital status, military or veteran status, alienage, citizenship status, sexual orientation, genetic information, or any other protected class under federal, state or local laws. Please do not contact the office directly to apply – only resumes submitted through this website will be considered. If you need assistance reviewing career opportunities or completing an application, please email our careers team or call 314-982-1700 and ask to be connected to Talent Development. The anticipated salary range for the Account Supervisor level is $61,000- $94,000. Salary is based on a range of factors that include relevant experience, knowledge, skills, other job-related qualifications and geography. A range of medical, dental, vision, 401(k) matching, paid time off and/or other benefits also are available.



