Principal Security Engineer
$205k - $257.5kSmartsheet
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.AI is reshaping what product security can accomplish, both as a target and as a tool. We're looking for a Principal Security Engineer to own the highest-leverage application security work at Smartsheet: leading threat modeling and product security reviews across a modern SaaS platform used by millions of customers, serving as the team's technical authority on AI security risk, and setting the technical standard for application security practice across the engineering organization.This is the most senior individual contributor role on the Application Security team. The expectation is not just depth: it is reach. You will engage product and engineering leadership directly, drive security requirements rather than advisory recommendations, and build team capability over time. If you are a security engineer who thinks upstream, builds threat models that generate concrete test scenarios and can translate technical findings into architecture decisions and business outcomes, this role is built for you.This role reports to the Manager, Application Security and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.You Will: Lead Threat Modeling and Product Security Reviews: Own threat modeling and product security review as the team's primary upstream capability: build models from architecture and data-flow artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. Define and lead the product security review service (set the service model, triage criteria, and enforcement posture) and personally execute reviews for high-risk features with documented findings and remediation timelines. Engage product and engineering directly to establish security requirements at the design phase, with the technical credibility to influence architecture decisions.Define AI Security Methodology and Drive It Across the Practice: Define how AI security risk is assessed, monitored, and mitigated across product, engineering, and third-party AI integrations, with recognized depth on the current threat landscape: LLM workflows, agentic pipelines, MCP-based integrations, and attack classes including prompt injection, indirect injection, and tool-calling authorization gaps. Own and evolve the AI-assisted security review capability: evaluate detection value, assess build-vs-buy tradeoffs, and shape toolchain coverage as Smartsheet's AI-integrated product surface scales.Shape AppSec Technical Direction and SDLC Controls: Serve as the technical authority for the AppSec program's SDLC control surface (secure coding guidelines, CI/CD pipeline security strategy, and toolchain direction across SAST, SCA, secrets, and IaC scanning) with the depth to influence tool decisions and resolve standards decisions that span teams without primary operational ownership. Build runbooks, standards, and documentation that create consistency and reduce single-point-of-failure risk as the team scales.Elevate Team Capability and Engineering Organization Influence: Mentor AppSec team members on threat modeling tradecraft and security review design, and serve as the trusted technical voice with product and engineering leadership, framing risk in terms that move architecture decisions. Your judgment shapes how the team prioritizes and how the broader organization understands and invests in application security.You Have:10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering, including direct ownership of threat modeling programs and security review services at scale.Ability to own threat modeling as a systematic practice (STRIDE, data-flow and architecture diagram driven), producing concrete, actionable test scenarios and abuse cases, embedded into agile design cycles as a repeatable, lightweight practice.Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in the OWASP LLM Top 10 and current AI attack classes, plus experience using AI tooling to scale security review coverage.Experience doing architecture review and targeted manual code review for complex SaaS features, with a track record of driving remediation requirements through to implementation with enough technical credibility to influence design decisions at the engineering leadership level.Experience mentoring engineers into threat modeling ownership and attacker-mindset review design; demonstrated track record of establishing security requirements as design-phase gates and sustaining engagement with engineering teams to drive implementation.Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to credibly influence toolchain direction, resolve standards decisions that span teams, and shape secure coding standards without primary operational ownership; cloud security fundamentals sufficient to tie application controls to the infrastructure they run on.Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent); comfortable reading production codebases to surface issues tooling misses and writing or extending automation others can maintain.Expertise communicating risk and security requirements (written and verbal) clearly across audiences from engineering ICs through executive leadership; recognized as a trusted technical voice by partner teams.Ability to build trusted relationships across engineering, product, and security organizations; earns influence through technical credibility and sustained engagement.Legally eligible to work in the U.S. on an ongoing basis.Nice to Have:GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration.Experience building AI-assisted security tooling or LLM-integrated review workflows that scale security review coverage.Penetration testing depth including exploit writing or vulnerability chaining to validate exploitability and prove real-world impact.Public-facing security contributions: conference speaking, CVE credits, published research, or industry community recognition that reflects the technical authority expected at principal level.Current US Perks & Benefits:Employer subsidized medical/vision and dental coverage for full-time employees401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)Monthly stipend to support your work and productivityFlexible Time Away Program, plus Sick Time OffUS employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plansUS employees receive 12 paid holidays per yearUp to 24 weeks of Parental LeavePersonal paid Volunteer Day to support our communityOpportunities for professional growth and development including access to Udemy online coursesCompany Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet accountTeleworking options from any registered location in the U.S. (role specific)Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.US Base Salary Pay Range$205,000—$257,500 USDGet to Know Us:At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.Equal Opportunity Employer:Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.#LI-Remote
$119.8k - $234.7k
...type: Individual ContributorTravel: Less than 25%Profession: Security EngineeringDiscipline: Penetration TestingCompany: MicrosoftOverviewThe... ...Windows Security team is looking for learn-it-all security engineers that will help secure Microsoft Windows products and devices,...SuggestedOngoing contractLocal areaWorldwide3 days per week- ...Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our... ...prioritize a diverse F5 community where each individual can thrive.Principal Security Engineer - Incident Response & Crisis ManagementOrganization: F5...SuggestedFull timeWork at officeLocal area
$209k
...capabilities that support one of the largest and most complex technology environments in the region. We are looking for an experienced Security Engineer to help modernize our enterprise directory services and identity infrastructure while improving reliability, scalability, and...SuggestedTemporary workFlexible hours$191k - $297k
...Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM)....SuggestedFull timeWork at office$165.6k - $296.4k
...365, OneDrive, Skype, Teams and Xbox Live. Azure Hardware Security Architecture team is responsible for designing and developing... ...cloud scale services and platforms. We are looking for a Principal Security Engineer to join our teamResponsibilitiesLead security initiatives...SuggestedOngoing contractWork at officeLocal areaWorldwide3 days per week$256k - $320k
...on our promise to customers sending money globally, providing secure, simple, and reliable ways to manage their money, ensuring true... ...of what makes this role exciting. Deep expertise in security engineering, application security, and AI development, combined with strength...Full timeWork at officeWorldwide- As a Principal Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls organization, you lead at least one technical area with a security engineering focus, and drive impact within teams, technologies, and projects across departments. Utilize...
$142.8k - $274.8k
...type: Individual ContributorTravel: 25-50%Profession: Security EngineeringDiscipline: Security Operations EngineeringCompany... ...research community and its intellectual property. As a Principal Security Operations Engineer in QSIT, you will own the response to cybersecurity,...Ongoing contractPermanent employmentLocal area3 days per week$168.75k - $270k
...that matters at a company where you matter.Job Description - Principal Security Operations EngineerOur mission is to protect lifeWe’re out... ...every single day.Your ImpactAs a PrincipalSecurity Operations Engineer, you will play a key role in building secure, reliable, and...Work experience placementWork at office$142.8k - $274.8k
...ManagerTravel: Less than 25%Profession: Security EngineeringDiscipline: Penetration... ...WARP) team is looking for a learn-it-all engineering leader that will help secure Microsoft... ...highest possible security standards.In this Principal Security Engineer Manager role, you...Ongoing contractLocal area3 days per week$159.3k - $202.4k
The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate security... ...are inherently secure. We are seeking a talented Security Engineer to join our team, where you will have the opportunity to contribute...Flexible hours$157k - $185k
...Security Engineer, Application Security Bellevue, WA; Menlo Park, CA Join Us In Building The Future Of Finance Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades....Work at officeFlexible hoursShift work3 days per week$165k - $242k
...March 2025. Learn more at What You'll Do: The Enterprise Security team at CoreWeave is responsible for securing how our people... ...team to join. About the Role: As a Senior Security Engineer, Enterprise Security , you'll design and ship the security controls...Permanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$142.8k - $274.8k
...ManagerTravel: Less than 25%Profession: Security EngineeringDiscipline: Security... ...platforms. We bring together security engineering, incident response, data analytics, automation... ...difference on our team.We are looking for a Principal Security Operations Engineering Manager...Ongoing contractLocal area3 days per week$175.1k - $236.9k
At Amazon Healthcare Security (HealthSec), we are on a mission to make healthcare secure and easy. We are developing a patient-centric... .... We are looking for a Senior Manager to lead a security engineering team. As a Security Engineering Manager, your responsibility is...Temporary workFlexible hours$175.1k - $236.9k
AWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the... ...own operational excellence for a regional team of security engineers, engage directly with customer security executives during high...Flexible hoursShift work$175.1k - $236.9k
...we’re looking for talented people who want to help.You’ll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll collaborate with people across AWS to help us...Remote workFlexible hours$175.1k - $236.9k
Amazon Web Services is looking for an experienced Security Engineering Manager to join the Security Analytics and AI Research group within AWS Security Services. This group is entrusted with researching and developing core detection and machine learning algorithms for...Flexible hours$114.33k - $170.98k
...designed for autonomous vehicles, uncrewed aircraft & drones, and security of borders, critical infrastructure, and smart cities. The... ...including Urban Air Mobility (UTM).Echodyne is seeking a Security Engineer II to join our fast-growing team. RESPONSIBILITIESPerform...Full timeTemporary work$176k - $253k
...Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated...$175.1k - $236.9k
We're looking for an experienced Security Engineering Manager to join our Secure Third Party Tools team. Our team builds the standards, controls, and expert review processes that ensure external vendors, software providers, and services meet Amazon's security bar before...Flexible hours$137.88k - $240.4k
...solvers and collaborative mindsets. Does that sound like you? The Opportunity with McKinstryWe are seeking a Senior Manager, Security Engineering to serve as McKinstry’s senior owner of security engineering — a role that sits at the intersection of hands-on technical...Remote workVisa sponsorshipShift work$175.1k - $236.9k
We are looking for an experienced security leader to join the Cloud Security team. As a security leader, you will own building and managing... ...team culture. You and your team will be expected to drive engineering teams to take the right actions in the right time frames to...Remote workFlexible hoursShift workNight shift$208.3k - $281.8k
Do you want to secure Amazon's most customer-centric experiences? As a Security Engineering Manager on the Endpoint Security Team, you'll lead a team that designs, implements, and operates security solutions integral to how Amazon's Customer Service Associates worldwide...WorldwideFlexible hours$250k - $380k
...app development platform, enabling data engineers, analysts, and developers to build and deploy... ...directly within Snowflake. As Principal Engineer for the Streamlit in Snowflake... ...with infrastructure, Snowsight, Cortex/AI, security, and the open-source Streamlit project.Be...$179.8k - $236k
...creating an equitable, inclusive and growth-focused environment for our people.about this teamAs the Senior Technology Manager, Security Engineering & Architecture, you will be a key leader within the Technology organization, responsible for shaping and executing the...Permanent employmentFull timePart timeWork visa$264.3k - $322.3k
...InfrastructureThe Compute Infra Team is the engine behind all of Databricks' products and... ...Isolation: Architect and enforce strong security and performance isolation across a... ...this Challenge?We are seeking a seasoned Principal Engineer who has not only built but successfully...Local areaWorldwide- ...about UiPath, and about our larger purpose.Could that be you?Principal Software Engineer - Intelligent Document Processing & Context GroundingBuild... ...of enterprise documents while maintaining accuracy, security, governance, and performance.This is a hands-on engineering...Temporary workWork at officeImmediate startRemote work
$266k - $365.75k
...enabling data teams to solve the world's toughest problems, from security threat detection to cancer drug development. We do this by... ...high-value challenges that are central to their missions.Our engineering teams build highly technical products that fulfill real, important...Local areaRemote workWorldwide- ...technology at a world-renowned company. Join JPMorganChase and unleash your potential in shaping the industry.As a Director of Security Engineering at JPMorganChase within the Cybersecurity and Technology Controls organization, you lead at least one technical area with a...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security Engineer. Be the first to apply!
- engineering director Bellevue, WA
- principal engineer Bellevue, WA
- general engineer Bellevue, WA
- data center chief engineer Bellevue, WA
- hotel chief engineer Bellevue, WA
- principal developer Bellevue, WA
- senior principal engineer Bellevue, WA
- principal infrastructure engineer Bellevue, WA
- senior director engineering Bellevue, WA
- senior chief engineer Bellevue, WA

