companyPhysicsX logo

Principal Security Engineer – DevSecOps & Security Architect

PhysicsXNew York City
On-site Full-time $200K/yr - $300K/yr

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Senior

Qualifications

10+ years in security, particularly in DevSecOps and security design reviews. Hands-on experience with secure coding, OWASP Top 10, threat modeling, and SDLC integration. Familiarity with GitHub/GitLab, CI/CD, IaC, and containerized environments. Experience with SAST tooling (e.g., Semgrep, Snyk). Proficient in Python and Go.

About the job

About Us

At PhysicsX, we are revolutionizing the landscape of hardware innovation by leveraging our expertise in numerical physics and our experience in Formula One. Our mission is to expedite the pace of hardware advancements akin to the rapid developments seen in software.
We are developing an AI-enhanced simulation software suite aimed at transforming engineering and manufacturing across cutting-edge industries. By facilitating high-fidelity, multi-physics simulations through AI inference throughout the engineering lifecycle, PhysicsX empowers engineers to achieve unprecedented levels of optimization and automation in design, manufacturing, and operational processes. Our clientele includes top-tier innovators in Aerospace & Defense, Materials, Energy, Semiconductors, and Automotive sectors.

The Role

As our Principal Security Engineer, you will collaborate closely with engineering teams to design and implement robust secure development practices, embed security measures within our CI/CD pipeline, and guide security and design reviews.

You will leverage your extensive expertise in DevSecOps, application security, and practical experience in securing web applications and APIs, all while possessing a deep understanding of contemporary development workflows. This role presents an exceptional opportunity to influence the direction of our security initiatives within a high-ownership, impactful environment.

Your Responsibilities

  • Design and integrate security tools directly into CI/CD pipelines to automate vulnerability detection and prevention, ensuring scalable 'shift-left' security.
  • Lead threat modeling and secure design reviews for web applications, APIs, and cloud services.
  • Manage the entire product vulnerability lifecycle, from issue triage and prioritization to remediation support, ensuring clear risk communication.
  • Establish secure coding standards, create comprehensive playbooks, and deliver hands-on training and mentorship to foster a security-first culture across the organization.
  • Collaborate cross-functionally with engineering teams to design and scale secure development practices throughout the software lifecycle.
  • Engage with customers during security assessments.

Your Qualifications

  • Over 10 years of experience in security, focusing on DevSecOps and security design reviews.
  • Hands-on expertise in secure coding, comprehensive understanding of OWASP Top 10, threat modeling, and SDLC integration.
  • Proficiency with GitHub/GitLab, CI/CD, Infrastructure as Code (IaC), and containerized environments.
  • Experience with deploying and utilizing SAST tools (e.g., Semgrep, Snyk).
  • Strong development skills in Python and Go.
  • A proven track record of balancing pragmatic security solutions with business needs.

About PhysicsX

PhysicsX is at the forefront of hardware innovation, merging deep-tech expertise in numerical physics with the fast-paced world of Formula One. We are committed to accelerating engineering and manufacturing through our AI-driven simulation software that transforms industries.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.