The Application Security Principal Engineer will need expertise in Container Scanning, API Security, Threat Modeling and SAST/DAST. Hands on experience on application security scanning tools like Snyk/Checkmarx or equivalent is required for this role. The Application Security Engineer provides a higher level of security in Comerica's web application environments. Generally working with dynamic and static code analyzers, communicates vulnerabilities to development teams and coaches as necessary to remediate these vulnerabilities. Integrates tool output into development pipelines. Creates and shares proof of concept code to demonstrate application attacks. Onboards applications and vulnerability tracking into management system and reports on progress. Hosts threat modeling exercises based on STRIDE or other industry standard methodology to draw out vulnerabilities during design phase. Guides aspiring application security individuals, leads implementation of new tools and methods. Significant overlap and interplay with Penetration Testing team.