About Us
Diligent is the AI leader in governance risk and compliance (GRC) SaaS solutions helping more than 1 million users and 700000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk build greater resilience and make better decisions faster.
At Diligent were building the future with people who think boldly and move fast. Whether youre designing systems that leverage large language models or part of a team reimaging workflows with AI youll help us unlock entirely new ways of working and thinking. Curiosity is in our DNA we look for individuals willing to ask the big questions and experiment fearlessly - those who embrace change not as a challenge but as an opportunity. The future belongs to those who keep learning and we are building it together. At Diligent youre not just building the future - youre an agent of positive change joining a global community on a mission to make an impact.
Learn more or follow us onLinkedInandFacebook
Position Overview
The Principal Application Security Engineer will be a key member of the Security group at Diligent working in close partnership with Software Development Site Reliability Engineering and Product Management. This individual will serve as the technical leader and subject matter expert driving the Application Security program with a primary focus on Vulnerability Management for Diligents Board management and GRC platform. The Application Security teams mission is to support secure software development by defining and enforcing best practices maintaining security tools and processes and ensuring vulnerabilities are identified prioritized and remediated according to company standards. The ideal candidate will have a strong background in software development security engineering or DevOps coupled with deep security expertise and a demonstrated ability to influence and lead in dynamic global environments.
Key Responsibilities
- Design implement and lead the Vulnerability Management program ensuring vulnerabilities (across infrastructure and applications) are continuously identified risk assessed and remediated in alignment with Diligents Vulnerability Management Standard and timelines.
- Provide technical leadership and mentorship to application security engineers and other stakeholders involved in secure software development.
- Drive collaboration with Engineering to ensure timely application of security patches and mitigation of vulnerabilities including clear escalation paths exception management and compliance reporting.
- Influence engineering practices and culture by developing and advocating secure coding standards response runbooks and risk-based remediation guidance.
- Serve as a primary escalation point for complex vulnerability management issues and customer or audit inquiries related to application security.
- Participate actively in risk evaluation prioritization remediation planning and exception handling processes for high-risk vulnerabilities.
- Liaising with cross-functional partners to strengthen overall security posture.
Required Experience and Skills
- Bachelors degree in Computer Science or related discipline
- Minimum 10 years of professional experience in application design development and security for web and mobile applications.
- Excellent knowledge of security concepts related to Internet technologies architectures and protocols as well as application software security concepts. This includes extensive experience in mitigating vulnerabilities
- Deep understanding of vulnerability management frameworks and security best practices (e.g. asset inventory vulnerability assessment and scanning patch management risk/timeline evaluation remediation and exception handling).
- Proven experience designing implementing and refining vulnerability lifecycle processes including asset inventory management vulnerability identification risk validation prioritization remediation tracking verification and exception handling.
- Advanced communication skills with demonstrated ability to coordinate across engineering operations risk management audit compliance and executive teams to ensure timely vulnerability remediation and alignment with business objectives.
- Development experience in one or more of: .NET Javascript C# and/or mobile application frameworks.
- Professional certification in Application Security or Penetration Testing (e.g. CISSP CSSLP GSSP-x CEH GPEN GWAPT GMOB Security).
- Familiarity with security standards and frameworks relevant to SaaS and cloud (e.g. ISO NIST CSA).
Preferred Experience and Skills
- Demonstrated leadership in application security including helping set strategic direction influencing day-to-day practices assigning technical priorities and fostering a collaborative high-performing environment.
- Experience developing and presenting program metrics dashboards and risk reports to both technical and non-technical stakeholders utilizing tools such as JIRA ServiceNow or other workflow management solutions.
What Diligent Offers You
- Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
- We care about our people.Diligent offers a flexible work environment global days of service comprehensive health benefits meeting free days generous time off policy and wellness programsto name a few
- We have teams all over the world. We may be headquartered in New York City but we have office hubs in Washington D.C. Vancouver London Galway Budapest Munich Bengaluru Singapore and Sydney.
- Diversity is important to us. Growing maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team facilitate dialogue and foster understanding.
Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology insights and connections they need to drive greater impact and accountability to lead with purpose. Our employees are passionate smart and creative people who not only want to help build the software company of the future but who want to make the world a more sustainable equitable and better place.
Headquartered in New York Diligent has offices in Washington D.C. London Galway Budapest Vancouver Bengaluru Munich Singapore and Sydney. To foster strong collaboration and connection this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations you will be expected towork onsite at least 50% of the time.We believe that in-person engagement helps drive innovation teamwork and a strong sense of community.
We are a drug free workplace. Diligent is proud to be an equal opportunity employer. We do not discriminate based on race color religious creed sex national origin ancestry citizenship status pregnancy childbirth physical disability mental disability age military status protected veteran status marital status registered domestic partner or civil union status gender (including sex stereotyping and gender identity or expression) medical condition (including but not limited to cancer related or HIV/AIDS related) genetic information or sexual orientation in accordance with applicable federal state and local also consider qualified applicants regardless of criminal histories consistent with legal requirements. See alsoDiligents EEO Policy and Know Your are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability you may contact us at .
To all recruitment agencies: Diligent does not accept unsolicited agency resumes. Please do not forward resumes to our jobs alias Diligent employees or any other organization location. Diligent is not responsible for any fees related to unsolicited resumes.
Required Experience:
Staff IC
About UsDiligent is the AI leader in governance risk and compliance (GRC) SaaS solutions helping more than 1 million users and 700000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners the C-Suite and the board a consolidated view of their entire GRC ...
About Us
Diligent is the AI leader in governance risk and compliance (GRC) SaaS solutions helping more than 1 million users and 700000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk build greater resilience and make better decisions faster.
At Diligent were building the future with people who think boldly and move fast. Whether youre designing systems that leverage large language models or part of a team reimaging workflows with AI youll help us unlock entirely new ways of working and thinking. Curiosity is in our DNA we look for individuals willing to ask the big questions and experiment fearlessly - those who embrace change not as a challenge but as an opportunity. The future belongs to those who keep learning and we are building it together. At Diligent youre not just building the future - youre an agent of positive change joining a global community on a mission to make an impact.
Learn more or follow us onLinkedInandFacebook
Position Overview
The Principal Application Security Engineer will be a key member of the Security group at Diligent working in close partnership with Software Development Site Reliability Engineering and Product Management. This individual will serve as the technical leader and subject matter expert driving the Application Security program with a primary focus on Vulnerability Management for Diligents Board management and GRC platform. The Application Security teams mission is to support secure software development by defining and enforcing best practices maintaining security tools and processes and ensuring vulnerabilities are identified prioritized and remediated according to company standards. The ideal candidate will have a strong background in software development security engineering or DevOps coupled with deep security expertise and a demonstrated ability to influence and lead in dynamic global environments.
Key Responsibilities
- Design implement and lead the Vulnerability Management program ensuring vulnerabilities (across infrastructure and applications) are continuously identified risk assessed and remediated in alignment with Diligents Vulnerability Management Standard and timelines.
- Provide technical leadership and mentorship to application security engineers and other stakeholders involved in secure software development.
- Drive collaboration with Engineering to ensure timely application of security patches and mitigation of vulnerabilities including clear escalation paths exception management and compliance reporting.
- Influence engineering practices and culture by developing and advocating secure coding standards response runbooks and risk-based remediation guidance.
- Serve as a primary escalation point for complex vulnerability management issues and customer or audit inquiries related to application security.
- Participate actively in risk evaluation prioritization remediation planning and exception handling processes for high-risk vulnerabilities.
- Liaising with cross-functional partners to strengthen overall security posture.
Required Experience and Skills
- Bachelors degree in Computer Science or related discipline
- Minimum 10 years of professional experience in application design development and security for web and mobile applications.
- Excellent knowledge of security concepts related to Internet technologies architectures and protocols as well as application software security concepts. This includes extensive experience in mitigating vulnerabilities
- Deep understanding of vulnerability management frameworks and security best practices (e.g. asset inventory vulnerability assessment and scanning patch management risk/timeline evaluation remediation and exception handling).
- Proven experience designing implementing and refining vulnerability lifecycle processes including asset inventory management vulnerability identification risk validation prioritization remediation tracking verification and exception handling.
- Advanced communication skills with demonstrated ability to coordinate across engineering operations risk management audit compliance and executive teams to ensure timely vulnerability remediation and alignment with business objectives.
- Development experience in one or more of: .NET Javascript C# and/or mobile application frameworks.
- Professional certification in Application Security or Penetration Testing (e.g. CISSP CSSLP GSSP-x CEH GPEN GWAPT GMOB Security).
- Familiarity with security standards and frameworks relevant to SaaS and cloud (e.g. ISO NIST CSA).
Preferred Experience and Skills
- Demonstrated leadership in application security including helping set strategic direction influencing day-to-day practices assigning technical priorities and fostering a collaborative high-performing environment.
- Experience developing and presenting program metrics dashboards and risk reports to both technical and non-technical stakeholders utilizing tools such as JIRA ServiceNow or other workflow management solutions.
What Diligent Offers You
- Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
- We care about our people.Diligent offers a flexible work environment global days of service comprehensive health benefits meeting free days generous time off policy and wellness programsto name a few
- We have teams all over the world. We may be headquartered in New York City but we have office hubs in Washington D.C. Vancouver London Galway Budapest Munich Bengaluru Singapore and Sydney.
- Diversity is important to us. Growing maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team facilitate dialogue and foster understanding.
Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology insights and connections they need to drive greater impact and accountability to lead with purpose. Our employees are passionate smart and creative people who not only want to help build the software company of the future but who want to make the world a more sustainable equitable and better place.
Headquartered in New York Diligent has offices in Washington D.C. London Galway Budapest Vancouver Bengaluru Munich Singapore and Sydney. To foster strong collaboration and connection this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations you will be expected towork onsite at least 50% of the time.We believe that in-person engagement helps drive innovation teamwork and a strong sense of community.
We are a drug free workplace. Diligent is proud to be an equal opportunity employer. We do not discriminate based on race color religious creed sex national origin ancestry citizenship status pregnancy childbirth physical disability mental disability age military status protected veteran status marital status registered domestic partner or civil union status gender (including sex stereotyping and gender identity or expression) medical condition (including but not limited to cancer related or HIV/AIDS related) genetic information or sexual orientation in accordance with applicable federal state and local also consider qualified applicants regardless of criminal histories consistent with legal requirements. See alsoDiligents EEO Policy and Know Your are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability you may contact us at .
To all recruitment agencies: Diligent does not accept unsolicited agency resumes. Please do not forward resumes to our jobs alias Diligent employees or any other organization location. Diligent is not responsible for any fees related to unsolicited resumes.
Required Experience:
Staff IC
View more
View less