About the job
About Us
The Role
As our Principal Security Engineer, you will collaborate closely with engineering teams to design and implement robust secure development practices, embed security measures within our CI/CD pipeline, and guide security and design reviews.
You will leverage your extensive expertise in DevSecOps, application security, and practical experience in securing web applications and APIs, all while possessing a deep understanding of contemporary development workflows. This role presents an exceptional opportunity to influence the direction of our security initiatives within a high-ownership, impactful environment.
Your Responsibilities
- Design and integrate security tools directly into CI/CD pipelines to automate vulnerability detection and prevention, ensuring scalable 'shift-left' security.
- Lead threat modeling and secure design reviews for web applications, APIs, and cloud services.
- Manage the entire product vulnerability lifecycle, from issue triage and prioritization to remediation support, ensuring clear risk communication.
- Establish secure coding standards, create comprehensive playbooks, and deliver hands-on training and mentorship to foster a security-first culture across the organization.
- Collaborate cross-functionally with engineering teams to design and scale secure development practices throughout the software lifecycle.
- Engage with customers during security assessments.
Your Qualifications
- Over 10 years of experience in security, focusing on DevSecOps and security design reviews.
- Hands-on expertise in secure coding, comprehensive understanding of OWASP Top 10, threat modeling, and SDLC integration.
- Proficiency with GitHub/GitLab, CI/CD, Infrastructure as Code (IaC), and containerized environments.
- Experience with deploying and utilizing SAST tools (e.g., Semgrep, Snyk).
- Strong development skills in Python and Go.
- A proven track record of balancing pragmatic security solutions with business needs.

