Talent.com
Philip Morris International U.S.
Principal InfoSec Engineer Application SecurityPhilip Morris International U.S. • Tampa, Florida, United States
Principal InfoSec Engineer Application Security

Principal InfoSec Engineer Application Security

Philip Morris International U.S. • Tampa, Florida, United States
26 days ago
Salary
$160,000.00 yearly
Job type
  • Full-time
Job description

Principal InfoSec Engineer Application Security – Tampa, FL

At PMI U.S., we are building a modern nicotine business—focused on helping make a future without cigarettes a reality in America. As the U.S. businesses of Philip Morris International, we are investing in new products, science, and capabilities to provide the approximately 25 million legal age adults who still smoke with better alternatives.

Our approach is rooted in innovation, responsible marketing, and a growing U.S. footprint that spans manufacturing, technology, and commercial operations across the country.

That creates real opportunity. You’ll have the space to take ownership, develop new ideas, and contribute to work that is shaping our business and the category. We’re looking for people who are curious, collaborative, and motivated by progress—because the scale of what we’re building creates room to grow in different directions.

Your ‘day to day’:

  • Identify cybersecurity gaps in new and existing applications and systems used by the PMI U.S. business unit via a wide variety of methods (e.g., threat modeling, architecture reviews, access model reviews, configuration reviews, static and dynamic application security testing).

  • Take ownership for execution of security assurance for the most critical or complex projects in the PMI U.S. business unit (e.g., a major system implementation or a multi-state rollout). Plan and deliver the security engagement – from initial risk scoping, ongoing design checkpoints, to final pre-go-live assessments. Ensure all security requirements are addressed throughout the project lifecycle, not just at the end.

  • Develop tailored assurance plans for projects in the PMI U.S. business unit that deviate from the standards. For example, if a project is adopting a new technology, determine what additional assessment steps are needed (specialized testing, extra reviews) and deliver them in coordination with other specialized InfoSec teams or external experts.

  • Describe and demonstrate identified issues in various forms (e.g., reports, technical debt definitions) and ensure that relevant stakeholders understand the risk that those vulnerabilities pose to the Company. Advise technology teams on how to replicate identified cybersecurity issues and remediate them in the most effective and cost-efficient way.

  • Coordinate with other Application Security teams to get specialized input as needed. For instance, bring in Offensive Security specialists for targeted ethical hacking activities and integrate their findings into the overall advisory for projects in the PMI U.S. business unit. Also, feedback common project pain points into the AppSec baseline evolution (e.g., if many projects struggle with a certain policy requirement, flag this to potentially clarify or enhance that standard in future).

  • Support creation of global application security strategies and implementation of strategic application security plans and initiatives for PMI U.S

  • Partner with Information Security leaders to ensure that the PMI U.S. business unit follows best practices in the application security domain by continuously optimizing tools, techniques and methodologies.

  • Keep up to date with the constantly evolving cyber threat landscape and the latest developments in technology and cyber risk management.

Key Skills:

  • 10+ years of experience in Information Security, preferably in the IT risk or assurance function (e.g., IT Security, IT Audit, Application Security, Offensive Security) of a large organization or consulting company.

  • Proven track record in autonomously executing complex IT security assessments or IT audits for large scale technology solutions, including technical reviews such as architecture reviews, configuration reviews, automated testing (SAST, DAST).

  • Broad familiarity with various IT domains such as application development, cloud and infrastructure.

  • Understanding of technical depth to challenge design decisions when needed (e.g., questioning why a certain legacy protocol is used, or whether a proposed architecture meets segmentation requirements).

  • Risk evaluation and articulation skills with ability to foresee project constraints and pragmatically suggest risk mitigations that fit within those constraints (balancing ideal security vs. practical delivery).

  • Excellent communication skills (up and down). Ability to lead meetings with project managers and architects to discuss findings and also brief upper management on the residual risks of a project. Strong negotiation skills to ensure necessary security changes are made.

  • Strong report writing skills for executive-level summaries and detailed risk registers. Also adept at improving team processes and refining existing methodologies (e.g., creating a standardized threat model template for all advisors to use).

  • Professional security certifications: CISA (mandatory), CISSP (mandatory), CISM (optional, but preferred)

Annual Base Salary Range: $160,000 - $200,000

What we offer:

  • We offer a competitive base salary, annual bonus (applicable based on level of position), great medical, dental and vision coverage, 401k with a generous company match, incredible wellness benefits, commuter benefits, pet insurance, generous PTO, and much more!
  • We have implemented Smart Work, a hybrid model of working that promotes flexibility in the workplace.
  • Seize the freedom to define your future and ours. We’ll empower you to take risks, experiment and explore.
  • Be part of an inclusive, diverse culture where everyone’s contribution is respected; Collaborate with some of the world’s best people and feel like you belong.
  • Pursue your ambitions and develop your skills with a global business – our staggering size and scale provides endless opportunities to progress.
  • Take pride in delivering our promise to society: To improve the lives of millions of smokers.

PMI is an Equal Opportunity Employer.

PMI is headquartered in Stamford, Conn., and its U.S. affiliates have more than 3,000 employees.

PMI has been an entirely separate company from Altria and Philip Morris USA since 2008. PMI’s affiliates first entered the U.S. market following the company’s acquisition of Swedish Match in late 2022. Philip Morris International and its U.S. affiliates are working to deliver a smoke-free future. Since 2008, PMI has invested $12.5 billion globally to develop, scientifically substantiate and commercialize innovative smoke-free products for adults who would otherwise continue to smoke with the goal of transitioning legal-age consumers who smoke to better alternatives. In 2022, PMI acquired Swedish Match – a leader in oral nicotine delivery – creating a global smoke-free champion led by the IQOS and ZYN brands. The U.S. Food and Drug Administration has authorized versions of PMI’s IQOS electronically heated tobacco devices and Swedish Match’s General snus as Modified Risk Tobacco Products and renewal applications for these products are presently pending before the FDA. For more information, please visit www.pmi.com/us and www.pmiscience.com.

#PMIUS

#LI-AC1

Create a job alert for this search

Principal InfoSec Engineer Application Security • Tampa, Florida, United States

Similar jobs

Oracle Cloud Data & Security - Senior Manager

Protiviti, Inc.Tampa, FL, United States
Full-time

Oracle Cloud Data & Security - Senior Manager.Protiviti is looking for a Technology Consulting Senior Manager to join our growing Oracle team.As a Senior Manager, you'll partner with our clients to... Show more

 • Promoted

Advanced Cyber Threat Response & Forensics Lead/Manager

DeloitteTampa, FL, United States
Full-time

Cyber Defense And Resilience Team Member.Deloitte's Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilitie... Show more

 • Promoted

Project Manager (Information Security Governance )

Syntricate TechnologiesTampa, FL, United States
Full-time

Project Manager (Information Security Governance).Location: Tampa, FL, Coppell, TX.Role Description: Information Security Governance - Project Manager Good Knowledge Application Security Any CRISC,... Show more

 • Promoted

Principal DevSecOps Engineer (Remote)

BioSpaceTampa, FL, United States
Remote
Full-time

Job DetailsCompany DescriptionAbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow.We... Show more

 • Promoted

Google Cloud Security Senior Manager

DeloitteTampa, FL, United States
Full-time

Senior Manager, GCP Cloud Security.Deloitte is seeking a Senior Manager to lead how clients secure their Google Cloud Platform (GCP) cloud and artificial intelligence (AI) estates across large-scal... Show more

 • Promoted

Information Environment Operations Analyst

CACI InternationalTampa, FL, United States
Full-time

Information Environment Operations Analyst.Join a team dedicated to advancing national security through innovative irregular warfare, intelligence, and operations expertise.CACI is seeking an Infor... Show more

 • Promoted

Cyber Security Project Manager

RIT SolutionsTampa, FL, United States
Full-time

Cyber Security Project Manager.Location: Remote Duration: 15-20 hours per week.Lead and manage cybersecurity and data classification projects from inception to completion, ensuring timely delivery ... Show more

 • Promoted

Google Cloud Security - Manager

DeloitteTampa, FL, United States
Full-time

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.Join our team to deliver powerful solutions to help our clients navigate the ever-changi... Show more

 • Promoted

Security Project Manager

RIT SolutionsTampa, FL, United States
Full-time

Location: 14700 Caribbean Way, Miramar, Fl 33027 (4 days per week onsite, remote Fridays) Duration: 1 year.Job Description - Royal Caribbean Group (RCG) is seeking a seasoned Information Security P... Show more

 • Promoted

Application Security SME - Downtown, NY & Tampa, FL

Staffing the UniverseTampa, FL, United States
Full-time

Application Security SmeLocation:Downtown, NY & Tampa, FLPosition Type:12 Months ContractRate:DoeRequirements:Experience with static and dynamic scanningExperience with penetration assessment o... Show more

 • Promoted

Head of Cybersecurity and Security Operations (SecOps)

Next Level ImpactsTampa, FL, United States
Full-time

Position Overview: As the Head of Cybersecurity and SecOps, you will serve as both the executive leader of our Security Operations function and the primary cybersecurity subject matter expert for o... Show more

 • Promoted

STINGRAI COMSEC Specialist (Industrial Security Analyst 2)- 29305

HII Mission Technologies divisionTampa, FL, United States
Full-time

Stingrai Comsec Specialist (Industrial Security Analyst 2) - 29305.HII's Mission Technologies division is seeking a COMSEC Specialist who is responsible for the management, safeguarding, distributi... Show more

 • Promoted

Oracle Application Security & Controls Manager

PwC (US)Tampa, FL, United States
Full-time

Oracle Application Security & Controls Manager.The Opportunity: As an Oracle Application Security & Controls Manager, you will engage with clients to optimize operational efficiency through special... Show more

 • Promoted

Cloud Security Manager Azure Infrastructure & AI

DeloitteTampa, FL, United States
Full-time

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.Join our team to deliver powerful solutions to help our clients navigate the ever-changi... Show more

 • Promoted

ERP Development & Security Lead

Skanska constructionsTampa, FL, United States
Full-time

ERP Development & Security Lead.Skanska USA is seeking an experienced ERP Development & Security Lead to guide the design, development, security, and modernization of our JD Edwards EnterpriseOne e... Show more

 • Promoted

Information Security Governance Project Manager

Syntricate TechnologiesTampa, FL, United States
Full-time

Information Security Governance Project Manager.Location: Tampa, FL/Coppell, TX Duration: Contract.Information Security Governance - Project Manager Good Knowledge Application Security Any CRISC,CI... Show more

 • Promoted

AWS Cloud Security Senior Manager

DeloitteTampa, FL, United States
Full-time

Senior Manager, AWS Cloud Security.Deloitte is seeking a Senior Manager, AWS Cloud Security to lead the design and delivery of cloud security services within our Cyber practice.In this role, you wi... Show more

 • Promoted

Oracle Cloud Data & Security - Senior Manager

ProtivitiTampa, FL, United States
Full-time

Oracle Cloud Data & Security - Senior Manager.Protiviti is looking for a Technology Consulting Senior Manager to join our growing Oracle team.As a Senior Manager, you'll partner with our clients to... Show more

 • Promoted

Manager, Network & Cybersecurity Engineering

System One Holdings, LLCTampa, FL, United States
Permanent

Network & Cybersecurity Engineering.Location: Tampa, Florida (fully onsite) Type: Direct Hire Compensation: $140,000 - 150,000.This position provides leadership for the integrated Network and Cyber... Show more

 • Promoted

Project Manager - Information Security Governance

Syntricate TechnologiesTampa, FL, United States
Full-time

Information Security Governance - Project Manager.Good Knowledge Application Security. Show more