In this role, you won’t just support change, you’ll help build programs from the ground up, defining new standards and leading initiatives that modernize how we design, develop, and deploy technology across the business. Your technical expertise, paired with industry best practices, will directly influence how technology aligns with and advances our broader business strategy.
If you're driven to lead, innovate, and leave a lasting impact, you’ll find the opportunity to do your most meaningful work here.
The Principal Application Security Engineer is responsible for defining and driving the application security strategy across the organization. This role ensures secure design and development practices are embedded within the software development lifecycle (SDLC) and DevSecOps pipelines. The architect will lead efforts to implement security tooling, establish reporting frameworks, and collaborate with developers, infrastructure teams, vendors, and security stakeholders to maintain a robust application security posture.
To perform this job successfully, an individual must be able to perform each duty satisfactorily. Other ancillary duties may be assigned.
Provides day-to-day management for the Information Protection function, responsible for security technologies utilized to protect WM's data and networks.
Participates in WM's Information Security Office leadership team to drive innovative security solutions, and collaboration with other IT and global functions.
Responsible for managing the work environment, identifying workforce needs and ensuring performance against expectations, values and vision.
Manages security audit and intrusion detection system logs for system and network anomalies and provides highest level analysis.
Responds to unique, highly complicated, suspicious or malicious events detected through collection or reported by Help Desk or users.
Provides technically advanced remediation and application event support to IT operations and engineering teams
Performs initial computer system forensic investigations and supports fraud investigations.
Provides top level analysis, design and support for log collection of firewalls, routers, networks and operating systems.
Communicates technical and event assessment results, evaluates engineering and integration initiatives and provides technical expertise to assess security policies, standards and guidelines.
Develops, collects and analyzes logs from firewalls, intrusion detection systems, enterprise anti-virus systems and software deployment tools.
Reviews and recommends the installation, modification or replacement of hardware or software components
Identifies and addresses any configuration change(s) that impact event collection.
Will coach and mentor less experienced analysts and act as team leader on more complicated systems projects.
A. Education and Experience
Education: Bachelor's Degree (accredited) in Computer Science, MIS, Business Administration or similar area of study or in lieu of degree, High School Diploma or GED (accredited) and four years of relevant work experience.
Experience: Seven years of prior work experience (in addition to education requirement).
B. Certificates, Licenses, Registrations or Other Requirements
One or more of the following is required:
Certified Information Systems Security Professional (CISSP).
Certified Information Systems Auditor (CISA).
Certified Information Security Manager (CISM).
C. Other Knowledge, Skills or Abilities Required
Technically advanced or in-depth knowledge or skills in one or more of the following is required:
Fortune 500 experience.
Listed below are key points regarding environmental demands and work environment of the job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Normal setting for this job is: office setting
This position is required to be onsite Monday through Thursday at our downtown Houston HQ with a flexible work from home day on Fridays.
Benefits
At Waste Management, each eligible employee receives a competitive total compensation package including Medical, Dental, Vision, Life Insurance and Short Term Disability. As well as a Stock Purchase Plan, Company match on 401K, and more! Our employees also receive Paid Vacation, Holidays, and Personal Days. Please note that benefits may vary by site.
If this sounds like the opportunity that you have been looking for, please click "Apply".
Waste Management is the largest environmental solutions provider in North America, serving more than 21 million municipal, commercial and industrial customers in the U.S. and Canada. We have invested in developing waste solutions for a changing world. Today, this includes not just disposal and recycling, but personal counseling to help customers achieve their green goals, including zero waste.
Waste Management is North America’s largest residential recycler and a renewable energy provider. We recover the naturally occurring gas inside landfills to generate electricity, called landfill-gas-to-energy. Waste Management’s fleet of natural gas trucks is the largest heavy-duty truck fleet of its kind in North America. With the largest network of recycling facilities, transfer stations and landfills in the industry, our entire business can adapt to meet the needs of every distinct customer segment.
As North America’s leading provider of comprehensive waste management services, our mission is to maximize resource value while minimizing impact in order to further both economic and environmental sustainability for all of our stakeholders.