Principal Security Engineer
Jobgether United States · $133K–$173K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
Build and maintain offensive security agents that automate reconnaissance, vulnerability validation, and security testing across web and cloud environments. Integrate security tools with enterprise systems and collaborate with cross-functional teams to improve detection and remediation effectiveness.
What they look for
Requirements
Requires 10+ years of professional experience in software engineering, offensive security, or a related technical discipline. Candidates must have hands-on experience with AI-enabled workflows, LLM-powered automation, and modern application security testing techniques.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer based in United States.
This role combines advanced software engineering and offensive security expertise to build AI-enabled systems that discover, validate, and help remediate vulnerabilities across modern environments. You will design and operate agentic security capabilities that automate reconnaissance, vulnerability validation, attack surface management, and security workflows. The position offers significant technical ownership, with a focus on translating offensive security techniques into reliable, scalable automation. You will integrate security tooling, cloud services, asset inventories, ticketing platforms, CI/CD pipelines, and threat intelligence sources into cohesive security workflows. Working across security and engineering teams, you will help improve the speed, consistency, coverage, and effectiveness of vulnerability discovery and remediation. You will also contribute to penetration testing and purple-team activities while ensuring AI-driven findings are validated and appropriately assessed. This is an opportunity to shape the evolution of AI-powered security engineering within a highly regulated technology environment.
\n
Accountabilities
- Build and maintain offensive security agents that automate reconnaissance, enumeration, vulnerability validation, and other security testing activities across web applications, APIs, and cloud environments.
- Develop agentic workflows that support attack surface management and vulnerability management programs while improving the efficiency and consistency of security operations.
- Design automation that combines deterministic technologies such as APIs, infrastructure-as-code, and data pipelines with non-deterministic Large Language Model (LLM)-driven capabilities where appropriate.
- Integrate security tools with ticketing platforms, asset inventories, Continuous Integration/Continuous Delivery (CI/CD) pipelines, threat intelligence sources, and other enterprise systems.
- Apply established architectural patterns, security standards, governance requirements, and human-in-the-loop controls when developing AI-enabled security capabilities.
- Validate findings generated by automated systems, reproduce vulnerabilities, and contribute to risk assessment, prioritization, and remediation activities.
- Develop monitoring, testing, and evaluation mechanisms that improve the reliability, accuracy, and operational effectiveness of agentic security systems.
- Support penetration testing and purple-team exercises focused on validating vulnerabilities, security controls, detection capabilities, and remediation effectiveness.
- Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to strengthen security detection, response, and remediation capabilities.
- Identify technical risks and opportunities for improvement, raise concerns proactively, and contribute to the evolution of security tools, engineering practices, and automation strategies.
- Document technical processes and develop software or AI-enabled solutions that reduce repetitive work and improve security workflows.
- Provide technical leadership in applying AI, automation, and modern software engineering approaches to offensive security challenges.
Requirements
- 10+ years of professional experience in software engineering, offensive security, penetration testing, application security, or a closely related technical discipline.
- Bachelor’s degree in Computer Science, Cybersecurity, Security, or another technical field is preferred, with a Master’s degree considered an advantage.
- Demonstrated experience building, deploying, and supporting production software, automation platforms, or security tooling.
- Hands-on experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
- Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and approaches for evaluating AI-enabled systems.
- Strong software development and integration skills using APIs, cloud services, automation frameworks, and data pipelines.
- Experience using AI-assisted development tools and LLM technologies to accelerate engineering, automation, and security outcomes.
- Strong understanding of the capabilities, limitations, reliability considerations, and operational requirements of production AI systems.
- Hands-on experience testing modern web applications, APIs, and cloud environments.
- Strong knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, exploit validation, and application security testing techniques.
- Experience assessing cloud environments, including identity and access management, configuration risks, and common cloud attack paths.
- Familiarity with offensive security tools, penetration testing methodologies, vulnerability analysis, and remediation workflows.
- Experience integrating security capabilities into CI/CD pipelines and developer workflows is preferred.
- Experience in healthcare, financial services, or another highly regulated industry is preferred.
- Working knowledge of frameworks and standards such as HIPAA, SOC 2, NIST Cybersecurity Framework, or comparable security and compliance frameworks is preferred.
- Relevant certifications such as Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), cloud security certifications, or comparable offensive security credentials are preferred.
- Ability to communicate complex technical risks and security findings effectively to both technical and non-technical audiences.
- Strong judgment and problem-solving skills, with the ability to balance security requirements, engineering practicality, and business objectives.
- Demonstrated ability to collaborate effectively across cross-functional engineering and security teams.
Benefits
- Annual salary range of $133,000–$173,000, with actual compensation based on factors including location, education, skills, experience, and qualifications.
- Eligibility for performance-based incentives as part of the total compensation package.
- Medical, dental, and vision coverage.
- Health Savings Account (HSA) contribution and matching.
- Dependent Care Flexible Spending Account (FSA) matching.
- Uncapped paid time off.
- Paid parental leave.
- 401(k) retirement plan with company matching.
- Personal and healthcare financial literacy programs.
- Ongoing education and tuition assistance.
- Gym and fitness reimbursement.
- Wellness program incentives.
- Fully remote work opportunity within the United States.
- Remote onboarding with an in-person onboarding training component held onsite periodically; required travel and accommodations are covered.
- Opportunity to work on advanced AI-powered security automation, offensive security, cloud environments, and vulnerability management.
- Exposure to highly regulated technology and security environments and cross-functional security teams.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Managing Director Cybersecurity
Sia Amsterdam, North Holland, Netherlands
-
Manager Cybersecurity
Sia Rotterdam, South Holland, Netherlands
-
Cybersecurity Consultant
Sia Rotterdam, South Holland, Netherlands
-
Senior Cybersecurity Consultant
Sia Rotterdam, South Holland, Netherlands
-
Senior consultant in Cybersecurity
Sia Amsterdam, North Holland, Netherlands
-
Automotive Cybersecurity Specialist
Avaron AB Gothenburg, Västra Götaland County, Sweden