Principal Information Security Engineer
Environmental Systems Research InstitutePrincipal Information Security Engineer
Environmental Systems Research InstituteLocation
remote, Redlands, CA
Type
Full-time
Posted
10/1/2026
Compensation
$116,480 per year
Job description
As an Application Security Engineer at Esri, you will play a vital role in securing the company's intellectual property and sensitive data against complex threats. You will work closely with application development, DevSecOps, and information security teams to integrate security into applications from the outset. The position emphasizes collaboration, pragmatic security, and continuous improvement, allowing you to make a significant impact in a technology-oriented environment. Your expertise will guide developers in vulnerability remediation and enhance application security testing capabilities.
Requirements
- 8+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive analysis of code, pen test, and open-source security findings.
- Demonstrated experience determining risk based on analysis/findings using a consistent risk management framework.
- Proven ability to develop automations/applications using Python, Typescript, Java, or PowerShell.
- Experience creating and maintaining reusable GitHub Actions workflows, with expertise in all aspects of GitHub workflow management.
- Hands-on experience working in a DevSecOps environment built on Kubernetes with a strong knowledge of Kubernetes security best practices.
- Ability to read and analyze code for security and design vulnerabilities.
- Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more).
- Experience working with cloud platforms, specifically AWS and Azure.
- Willingness to learn new skills and enhance workflows using various AI tools.
- US citizenship and willingness and ability to maintain a US Security Clearance.
- Bachelor’s degree in computer science or related field.
Responsibilities
- Design, operate, and continuously improve application security testing capabilities and pipelines.
- Assess application risks and recommend mitigations.
- Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally.
- Assist with application layer penetration testing to identify potential issues.
- Provide application security guidance and mentorship to development teams as needed.
H-1B filing history
Public USCIS petition and DOL LCA counts · latest USCIS FY2026, LCA FY2026
Filing entity: Environmental Systems Research Institute Inc
As of Aug 23, 2026
Initial approvals
44
FY2026
Approval rate
98.9%
FY2026
LCA certified
67
FY2026
Entry-level share
49.3%
FY2026
Initial approvals YoY
+3%
Trend
LCA certified YoY
-31%
Trend
Initial approvals by fiscal year
Approval rate by fiscal year
Continuing vs initial approvals
LCA certified positions by quarter
LCA certified positions by fiscal year
Based on public USCIS and DOL filings; not a sponsorship guarantee.
Is this posting expired or inaccurate?
