Principal Cloud Application Security Engineer
Genesys Blackrock, Dublin, Ireland
Software Development · 5,001-10,000 employees
About the role
Lead the technical direction of an application security team while owning the end-to-end security operating model for a multi-tenant SaaS platform. Develop AI-driven automation to improve vulnerability triage, detection coverage, and risk assessment across cloud and software supply chain environments.
What they look for
Requirements
Requires 10+ years of experience in application and cloud security with deep expertise in AWS and web/API security. Candidates must demonstrate strong technical leadership, proficiency in security automation, and the ability to communicate complex security risks to diverse stakeholders.
Benefits
Full description
Be the one building AI-powered experiences where they matter most.
At Genesys, we help organizations create better customer experiences through AI-powered experience orchestration. Our platform connects people, systems, data and AI to help organizations deliver more personalized service, improve operational efficiency and build stronger customer relationships.
Help build, support and operate technology used by more than 8,000 organizations in over 100 countries – moving AI from possibility to production in real-world enterprise environments every day.
Role Overview: Protecting a continuously evolving, multi-tenant SaaS platform requires security decisions that distinguish genuine customer risk from an increasing volume of automated findings. As a Principal Cloud Application Security Engineer in Genesys Cloud Product Security, you will shape how application security scales across cloud accounts, regions, APIs, applications, distributed services, software supply chains, and AI-powered product capabilities.
You will own the technical direction of a small Application Security team while remaining hands-on with complex security analysis, detection engineering, vulnerability triage, and cloud security. Your work will determine where security coverage needs to deepen, which findings represent meaningful exploitability, and how specialist engineering capacity is focused on risks that could affect customer data, tenant isolation, platform integrity, or service security.
AI-assisted development and security analysis are changing both the speed of software delivery and the volume of potential vulnerabilities that security teams must evaluate. You will define how Genesys uses AI and automation to improve vulnerability triage, identify gaps across source code and security tooling, reduce false positives, and establish appropriate human validation for security decisions where context and judgment remain essential.
Genesys Cloud primarily runs on AWS, and you will apply deep cloud security expertise to reason across identity, attack paths, infrastructure exposure, application behavior, and distributed architectures at enterprise scale. This Principal-level individual contributor role provides visibility across enterprise security initiatives, close partnership with engineering and senior leaders, and the opportunity to influence how application and cloud security capabilities evolve as the Genesys Cloud platform and its AI capabilities expand.
Key Responsibilities:
- Lead the technical direction of a small Application Security team, strengthening engineering judgment, security standards, and team capability through hands-on leadership and mentoring
- Own the end-to-end application security operating model, directing how detection coverage evolves, how increasing finding volume is absorbed, and where engineering investment delivers the greatest reduction in exploitable risk
- Drive scalable detection coverage across SAST, SCA, DAST, secrets scanning, mobile application security testing, cloud security posture management, and emerging security capabilities, partnering with security teams to shape tool selection, configuration, tuning, and rule sets
- Expand security visibility across web applications, APIs, mobile applications, cloud environments, AI-powered product capabilities, and software supply chains to identify systemic risks and coverage gaps that individual tools cannot reveal
- Establish meaningful security coverage metrics that demonstrate both what testing discovers and how effectively the relevant application and platform attack surface is assessed
- Own exploitability assessment across automated findings, bug bounty submissions, customer penetration tests, internal assessments, and AI-generated analysis, evaluating reachability, tenant isolation, customer data exposure, affected assets, and blast radius
- Drive consistent and defensible vulnerability decisions through evidence, reproduction, severity rationale, triage runbooks, validation checklists, and known-issue patterns that separate exploitable vulnerabilities from false positives, duplicates, theoretical findings, and accepted risk
- Lead investigation and escalation of high-risk application and cloud security issues, including cross-tenant access, authentication and authorization bypass, sensitive data exposure, production secrets, and externally reachable cloud resources
- Develop AI and automation capabilities that increase security team capacity by improving vulnerability triage, analyzing penetration-test-style reports, identifying false positives, drafting responses, prioritizing findings requiring specialist judgment, and exposing detection gaps across tools and source code
- Define appropriate trust boundaries for AI-assisted security decisions, establishing human validation points and evolving those controls as models, security tooling, attack techniques, and engineering practices change
- Strengthen vulnerability intake and tracking across security tools, bug bounty submissions, customer penetration tests, internal assessments, and other detection sources to improve consistency, traceability, and scalability
- Coordinate the bug bounty program and customer penetration testing workflows, partnering with Sales, Technical Account Managers, Customer Success Managers, penetration testers, and product teams to validate, communicate, and route security findings effectively
- Produce clear, evidence-based security findings, severity decisions, and reusable customer responses that engineering teams, account teams, and customer security stakeholders can act on without additional interpretation
- Partner across Product Security, Security Architecture, Security Development, Security Operations, Penetration Testing, DevOps, engineering, and product teams to convert recurring vulnerabilities and security anti-patterns into scalable preventive controls
- Influence application security strategy across Genesys Cloud by connecting individual findings, systemic weaknesses, detection gaps, and emerging attack techniques to longer-term platform security priorities
Required Qualifications:
- 10+ years of relevant experience across application security, product security, penetration testing, vulnerability management, cloud security, or closely related security engineering disciplines, including significant recent depth in web and API security
- Demonstrated expertise assessing real-world exploitability across authorization flaws, authentication weaknesses, injection vulnerabilities, SSRF, business logic abuse, sensitive data exposure, and multi-tenant isolation risks
- Strong experience implementing, configuring, or tuning application security capabilities such as SAST, SCA, DAST, secrets scanning, mobile application security testing, or cloud security posture management
- Proven experience building or materially expanding security detection capabilities, with sound judgment across coverage depth, false positives, operational cost, engineering effort, and security trade-offs
- Demonstrated success building automation that improved security team capacity, consistency, coverage, or triage efficiency, combined with the judgment to identify where automated decisions require human oversight
- Strong understanding of cloud-hosted, multi-tenant architectures and the ability to reason about attack paths, trust boundaries, identity, authorization, data isolation, and externally exposed services
- Strong cloud security experience, preferably with AWS, including security controls, identity, attack paths, infrastructure exposure, and security posture across large-scale cloud environments
- Demonstrated technical leadership through formal or informal leadership of a small team, mentoring security engineers, leading complex initiatives, or setting technical direction across multiple contributors
- Strong written and verbal communication skills, with the ability to explain exploitability, severity, security findings, and remediation considerations to engineering, product, senior leadership, customer-facing teams, and non-specialist audiences
- Proven ability to collaborate across shared areas of ownership with security, engineering, DevOps, and product teams while maintaining clear accountability and productive working relationships
- Demonstrated discretion when handling sensitive vulnerability information, customer security findings, researcher communications, and confidential security data
Preferred Qualifications:
- Deep cloud security experience with AWS, or transferable cloud security expertise gained in Microsoft Azure or Google Cloud Platform (GCP)
- Familiarity with OWASP API Security Top 10, OWASP Web Security Testing Guide, or established mobile application security testing practices
- Experience with secure SDLC practices, CI/CD security integration, threat modeling, secure design review, or security architecture
- Experience designing, building, or operating AI or LLM-assisted security and engineering workflows
- Hands-on depth in Android or iOS application security or cloud security posture management across large-scale distributed environments
- Experience with software supply chain security, including dependency risk, malicious package detection, software bills of materials (SBOM), build integrity, or provenance
- Familiarity with security and compliance frameworks such as SOC 2, PCI DSS, FedRAMP, or HIPAA and their implications for security evidence and engineering controls
- Proficiency with Python, TypeScript, Bash, Go, or another language suitable for developing security tooling, integrations, and automation
- Experience securing REST APIs, OAuth-based architectures, service-to-service integrations, event-driven systems, microservices, or other distributed SaaS architectures
- Experience working with bug bounty programs, customer penetration testing, vulnerability disclosure, or remediation workflows
We know strong candidates may not meet every item listed above. We will consider candidates with strong application and API security judgment, a record of building capability rather than operating it, and the appetite to scale a security function with automation rather than headcount.
Working at Genesys
- AI at enterprise scale – Build, support and operate AI-powered technology used by more than 8,000 organizations worldwide. 150+ new AI features were released in the last fiscal year.
- A flexible-first culture – Join a global team of nearly 7,000 employees with flexible ways of working designed to help people do their best work.
- Growth in the AI era – Build future-ready skills through mentorship, learning programs, leadership development and education support.
- Time to recharge and give back – Benefits include paid volunteer time, August Free Fridays, well-being resources and regionally tailored programs for employees and their families.
- Recognized globally – Genesys is Great Place to Work® certified in 17 countries and 94% of employees are proud to tell others they work at Genesys.
Learn more about our culture, AI innovation and sustainability commitments through our Careers site and Sustainability Report.
What Happens After You Apply
After you apply, here's what you can typically expect:
- Our Talent Acquisition team reviews your application with the hiring team.
- A Talent Acquisition Partner will review your application and, if your background is aligned, schedule a Zoom interview.
- Next, you'll meet the hiring manager and other members of the interview team.
- We aim to keep the process focused and respectful of your time, with no more than five interviews in most cases.
- After interviews are complete, our team will follow up with the final steps.
Every application is reviewed by a person. Response times may vary by role and location, but our team will keep you informed throughout the process.
Stay Connected
Stay connected to learn more about how we're applying AI to customer and employee experience challenges and get notified when relevant opportunities become available.
Get notified about relevant opportunities.
Be the one building what's next - where AI, experience and impact come together.
Employee Referral
If a Genesys employee referred you, please apply using the link they shared so we can connect your application to their referral.
About Genesys:
Genesys® empowers more than 8,000 organizations worldwide to create the best customer and employee experiences. Genesys Cloud™ is the Agentic Orchestration Platform that securely connects people, systems, data and AI across the enterprise with built-in governance and control. As a result, organizations can drive customer loyalty, growth and retention while increasing operational efficiency and teamwork across human and AI workforces. To learn more, visit www.genesys.ai.
Reasonable Accommodations:
If you require a reasonable accommodation to complete any part of the application process, or are limited in your ability to access or use this online application and need an alternative method for applying, you or someone you know may contact us at reasonable.accommodations@genesys.com.
You can expect a response within 24–48 hours. To help us provide the best support, click the email link above to open a pre-filled message and complete the requested information before sending. If you have any questions, please include them in your email.
This email is intended to support job seekers requesting accommodations. Messages unrelated to accommodation—such as application follow-ups or resume submissions—may not receive a response.
Genesys is an equal opportunity employer committed to fairness in the workplace. We evaluate qualified applicants without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, marital status, domestic partner status, national origin, genetics, disability, military and veteran status, and other protected characteristics.
Please note that recruiters will never ask for sensitive personal or financial information during the application phase.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr