Eli Lilly and Company
Sr. Principal Security Engineer, Application Security Strategy & Architecture
About This Role
About Eli Lilly and Company
Eli Lilly and Company is a global research-based pharmaceutical corporation founded in 1876 in Indianapolis, Indiana. Established by Colonel Eli Lilly, the company has grown from a small operation to one of the largest pharmaceutical firms in the world, with products available in approximately 125 countries. Throughout its history, Eli Lilly has developed numerous significant medications, including the first commercially available insulin product, Iletin®, and the Salk Polio Vaccine, which it was the first to manufacture and distribute globally. The company has also introduced various antibiotics and treatments for conditions like pernicious anemia. In addition to pharmaceuticals, Eli Lilly has diversified into agricultural chemicals, veterinary medicine, cosmetics, and medical instruments. The company is known for its commitment to innovation and humanitarian service, reflecting its founder's vision of continuous improvement.
Security at Eli Lilly and Company
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- The team emphasizes building security by design with early involvement of security teams in innovation conversations, implementing 'shift left' practices rather than late-stage gating.
- The CISO views security as a continuous, long-term responsibility, stating "From day one through day 1,000,001, I am responsible for security.".
Security Team
The AppSec function resides within the engineering-focused security arm on the Security Architecture and Engineering team. Key leaders include Andrea Abell (CISO) and Tim Messing (AppSec Contributor). Team size information is not publicly available. As of, there is 1 active AppSec job posting. Common skill patterns include proficiency in DevSecOps and end-to-end security testing.
Key Initiatives
The company operates a security champions program and cyber security apprenticeship program. They implement 'shift left' practices by integrating application security testing tools into the development and deployment pipeline. The vulnerability management process includes acknowledging receipt of cybersecurity reports. Specific remediation SLAs and recent 2026 tool rollouts are not publicly documented.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn