We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Principal Application Security Engineer

IDEXX Laboratories, Inc
401(k)
United States, Maine, Westbrook
1 Idexx Drive (Show on map)
Jul 31, 2025

IDEXX seeks a Principal Application Security Engineer to guide and influence secure design practices across IDEXX product portfolio. This consultative role partners with development teams to establish security best practices, provide architectural guidance, and enable teams to build secure products from inception. You'll serve as a trusted advisor rather than a hands-on implementer.

In this role, you will have the opportunity to shape security culture across IDEXX. This is a high-visibility role influencing product security strategy. You will be engaged with diverse teams and technologies and make an impact on products improving animal health globally.

In this role, you will be responsible for...

Strategic Security Consulting:

  • Advising product teams on security architecture decisions and risk trade-offs
  • Facilitating threat modeling workshops and architecture review sessions
  • Providing expert guidance on security patterns and anti-patterns and influence security strategy across multiple product lines and teams

Security Standards & Governance:

  • Working with IDEXX GRC team to promote security policies, standards, and guidelines for development teams.
  • Creating reusable security blueprints and reference architectures.
  • Establishing security decision frameworks for common architectural patterns and guide teams in interpreting and applying compliance requirements

Stakeholder Engagement & Influence:

  • Consulting with product owners, architects, and engineering leads on security risks.
  • Presenting security recommendations to technical and business stakeholders and build consensus around security decisions across diverse teams and act as liaison between Information Security and product development

Security Program Development

  • Influencing the Product & Application Security program strategy and initiatives
  • Designing security awareness programs tailored to different roles
  • Developing self-service security resources and playbooks
  • Establishing metrics to measure security program effectiveness

What you will need to succeed:

  • 7-10+ years in security consulting, architecture, or advisory roles with experience in application security and implementing SAST, DAST, SCA, etc.
  • In depth experience performing application security initiatives, including security assessments, threat modeling, and secure code reviews.
  • Strong understanding of modern software development practices, cloud computing concepts, and delivery methodologies.
  • Proficiency in security testing tools such as Synopsys, CodeQL, CSPM, etc.
  • Experience with security of cloud workloads (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes).
  • Comfortable working with various methodologies & topologies, including DevOps, DevSecOps, SCRUM/Agile, Waterfall, etc.
  • Expertise in threat modeling and risk assessment methodologies
  • Deep knowledge of application security principles and patterns and understanding of enterprise security architecture frameworks
  • Familiarity with regulatory compliance (SOX, GDPR, HIPAA)
  • Exceptional written and verbal communication abilities with the ability to translate technical risks into business impact
  • Proven track record of influencing technical decisions without direct authority with a background in stakeholder management and consensus building
  • Experience presenting to and advising Principal technical leadership
  • Experience facilitating workshops and leading architectural discussions
  • Skills in creating compelling security documentation and presentations

It would be a plus if you had some of these things:

  • Security certifications (CISSP, SABSA, TOGAF)
  • Experience in healthcare or regulated industries
  • Track record of developing security programs or frameworks
  • Public speaking or thought leadership in security

Location: while it is preferred that you live near our corporate HQ in the Portland, Maine, we are also open to individuals in the EST time zones.

What You Can Expect from Us

  • Base annual salary target: $150000 to 170000 (yes, we do have flexibility if needed)
  • Opportunity for annual cash bonus and yearly equity award
  • Health / Dental / Vision Benefits Day-One
  • 5% matching 401k
  • Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!
Applied = 0

(web-6886664d94-nm6rc)