Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Security Engineer

$205k - $257.5k

Smartsheet

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

AI is reshaping what product security can accomplish, both as a target and as a tool. We're looking for a Principal Security Engineer to own the highest-leverage application security work at Smartsheet: leading threat modeling and product security reviews across a modern SaaS platform used by millions of customers, serving as the team's technical authority on AI security risk, and setting the technical standard for application security practice across the engineering organization.

This is the most senior individual contributor role on the Application Security team. The expectation is not just depth: it is reach. You will engage product and engineering leadership directly, drive security requirements rather than advisory recommendations, and build team capability over time. If you are a security engineer who thinks upstream, builds threat models that generate concrete test scenarios and can translate technical findings into architecture decisions and business outcomes, this role is built for you.

This role reports to the Manager, Application Security and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.

You Will: 

  • Lead Threat Modeling and Product Security Reviews: Own threat modeling and product security review as the team's primary upstream capability: build models from architecture and data-flow artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. Define and lead the product security review service (set the service model, triage criteria, and enforcement posture) and personally execute reviews for high-risk features with documented findings and remediation timelines. Engage product and engineering directly to establish security requirements at the design phase, with the technical credibility to influence architecture decisions.
  • Define AI Security Methodology and Drive It Across the Practice: Define how AI security risk is assessed, monitored, and mitigated across product, engineering, and third-party AI integrations, with recognized depth on the current threat landscape: LLM workflows, agentic pipelines, MCP-based integrations, and attack classes including prompt injection, indirect injection, and tool-calling authorization gaps. Own and evolve the AI-assisted security review capability: evaluate detection value, assess build-vs-buy tradeoffs, and shape toolchain coverage as Smartsheet's AI-integrated product surface scales.
  • Shape AppSec Technical Direction and SDLC Controls: Serve as the technical authority for the AppSec program's SDLC control surface (secure coding guidelines, CI/CD pipeline security strategy, and toolchain direction across SAST, SCA, secrets, and IaC scanning) with the depth to influence tool decisions and resolve standards decisions that span teams without primary operational ownership. Build runbooks, standards, and documentation that create consistency and reduce single-point-of-failure risk as the team scales.
  • Elevate Team Capability and Engineering Organization Influence: Mentor AppSec team members on threat modeling tradecraft and security review design, and serve as the trusted technical voice with product and engineering leadership, framing risk in terms that move architecture decisions. Your judgment shapes how the team prioritizes and how the broader organization understands and invests in application security.

You Have:

  • 10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering, including direct ownership of threat modeling programs and security review services at scale.
  • Ability to own threat modeling as a systematic practice (STRIDE, data-flow and architecture diagram driven), producing concrete, actionable test scenarios and abuse cases, embedded into agile design cycles as a repeatable, lightweight practice.
  • Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in the OWASP LLM Top 10 and current AI attack classes, plus experience using AI tooling to scale security review coverage.
  • Experience doing architecture review and targeted manual code review for complex SaaS features, with a track record of driving remediation requirements through to implementation with enough technical credibility to influence design decisions at the engineering leadership level.
  • Experience mentoring engineers into threat modeling ownership and attacker-mindset review design; demonstrated track record of establishing security requirements as design-phase gates and sustaining engagement with engineering teams to drive implementation.
  • Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to credibly influence toolchain direction, resolve standards decisions that span teams, and shape secure coding standards without primary operational ownership; cloud security fundamentals sufficient to tie application controls to the infrastructure they run on.
  • Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent); comfortable reading production codebases to surface issues tooling misses and writing or extending automation others can maintain.
  • Expertise communicating risk and security requirements (written and verbal) clearly across audiences from engineering ICs through executive leadership; recognized as a trusted technical voice by partner teams.
  • Ability to build trusted relationships across engineering, product, and security organizations; earns influence through technical credibility and sustained engagement.
  • Legally eligible to work in the U.S. on an ongoing basis.

Nice to Have:

  • GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration.
  • Experience building AI-assisted security tooling or LLM-integrated review workflows that scale security review coverage.
  • Penetration testing depth including exploit writing or vulnerability chaining to validate exploitability and prove real-world impact.
  • Public-facing security contributions: conference speaking, CVE credits, published research, or industry community recognition that reflects the technical authority expected at principal level.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range$205,000—$257,500 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. 

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

#LI-Remote

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal Security Engineer in United States vacancy
  • $119.8k - $234.7k

     ...type: Individual ContributorTravel: Less than 25%Profession: Security EngineeringDiscipline: Penetration TestingCompany: MicrosoftOverviewThe...  ...Windows Security team is looking for learn-it-all security engineers that will help secure Microsoft Windows products and devices,... 
    Suggested
    Ongoing contract
    Work at office
    Local area
    Worldwide

    Microsoft

    Redmond, WA
    1 day ago
  •  ...automated threat detection and mitigation systems that process over 1PB of security telemetry daily across host, network, identity, and physical security domains. As a Principal Security Engineer, you will define the technical direction for this work, identifying the... 
    Suggested
    Immediate start
    Worldwide

    Amazon

    Dublin, OH
    4 days ago
  • $221.2k - $387.1k

    Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious...  ....Job DescriptionAbout SSOThe ServiceNow Security Organization (SSO) delivers world-class,...  ...from blocker to enabler.Role As Principal Engineer for AI Security Governance, you... 
    Suggested
    Permanent employment
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    ServiceNow

    Kirkland, WA
    4 days ago
  •  ...What you'll be responsible for:The Circle Security Team works to protect Circle; our...  ...all three; not as a generalist, but as a Principal who can go deep on each.Also note that...  ...experience in detection, response, or security engineering.3+ years of experience commanding... 
    Suggested
    Contract work
    Work experience placement
    Flexible hours
    Shift work
    Night shift

    Circle

    Boston, MA
    4 days ago
  • $102k - $177.1k

     ...Technology Enterprise Strategy & SecurityJob Sub Function: Security & ControlsJob Category:Scientific/TechnologyAll Job...  ...MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be located in Danvers, MA. Remote work options may be... 
    Suggested
    Full time
    Local area
    Immediate start
    Remote work

    Johnson & Johnson

    Indiana
    1 day ago
  • $275k - $300k

     ...and our vision at Postman.About the TeamThe Information Security organization at Postman operates across three pillars:...  ...at Postman's scale.The OpportunityWe are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will... 
    Full time
    Work at office
    Flexible hours
    3 days per week

    Postman

    San Francisco, CA
    1 day ago
  •  ...to grow your career and help people find a place to call home.Job DescriptionFannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture... 
    Full time
    Work at office
    Remote work

    Fannie Mae

    Plano, TX
    2 days ago
  • $104.9k - $174.7k

    Principal Security Engineer, Business EngagementAbout the TeamWe are revamping how the Information Security Business Engagement team works within LexisNexis Legal & Professional. This team sits at the intersection of security, product, and technology, working directly alongside... 
    Full time
    Local area

    RELX Group

    Raleigh, NC
    4 days ago
  • $183k - $265k

    Provide domain expertise in cloud security and compliance, and be a trusted technical advisor to customers.Work with customers...  ...to connect with customers, employees, and partners.As a Principal Security Engineer, you will provide excellent technical guidance to customers... 

    Google

    New York, NY
    2 days ago
  • $160.8k - $241.2k

     ...advanced therapeutic solutions. These teams partner across engineering, security, regulatory, quality, and legal functions to deliver products...  ...while protecting sensitive health and personal data.As the Principal Security & Privacy Engineer, you will serve as the... 
    Full time
    H1b
    Work at office
    Local area
    Immediate start
    Flexible hours

    Medtronic

    Fridley, MN
    1 day ago
  • $147.05k - $198.95k

     ...allow exceptional opportunities for professional achievement and career growth. Essential Duties and Responsibilities:The Principal Security Engineer, under the direction of the Director of Security Engineering and Operations, is responsible for managing the Firm’s... 
    Full time
    Work experience placement
    Remote work
    Worldwide

    Wilson Sonsini Goodrich & Rosati

    Los Angeles, CA
    1 day ago
  • $209k

     ...capabilities that support one of the largest and most complex technology environments in the region. We are looking for an experienced Security Engineer to help modernize our enterprise directory services and identity infrastructure while improving reliability, scalability, and... 
    Temporary work
    Flexible hours

    Coupang

    Mountain View, CA
    1 day ago
  • $111.84k - $139.8k

     ...that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities. ​The Principal OT Security Engineer defines enterprise OT cybersecurity strategy, architecture, and a technical roadmap, leading complex initiatives across... 
    Full time
    Work experience placement
    Work at office
    Remote work

    Donaldson company

    Bloomington, MN
    4 days ago
  • $106.3k - $234.6k

    The Security Engineer will be the technical lead for WIDS deployment and integration across data center sites. The role’s primary focus is ensuring WIDS infrastructure, sensors, rack equipment, network connectivity, software platforms, and operational workflows are designed... 
    Temporary work
    Flexible hours

    Oracle Corporation

    Nashville, TN
    1 day ago
  • $205k - $257.5k

     ...magic at work, and it’s what we show up for every day.AI is reshaping what product security can accomplish, both as a target and as a tool. We're looking for a Principal Security Engineer to own the highest-leverage application security work at Smartsheet: leading... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work

    Smartsheet

    Bellevue, WA
    1 day ago
  •  ...Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our...  ...prioritize a diverse F5 community where each individual can thrive.Principal Security Engineer - Incident Response & Crisis ManagementOrganization: F5... 
    Full time
    Work at office
    Local area

    F5 Networks

    Seattle, WA
    4 days ago
  • $256k - $320k

     ...on our promise to customers sending money globally, providing secure, simple, and reliable ways to manage their money, ensuring true...  ...of what makes this role exciting. Deep expertise in security engineering, application security, and AI development, combined with strength... 
    Full time
    Work at office
    Worldwide

    Remitly

    Seattle, WA
    2 days ago
  • $240k - $310k

    The RoleYou will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance checklist—you will architect, build, and scale the technical systems that protect our customers and their... 

    Candid Health

    San Francisco, CA
    18 hours ago
  • $142.8k - $274.8k

     ...ContributorTravel: Less than 25%Profession: Security EngineeringDiscipline: Security...  ...Engagement space, we partner closely with engineering teams, architects, and product leaders...  ...controls across the browser platform. As a Principal Security Engineer, you will help define... 
    Ongoing contract
    Work at office
    Local area
    Worldwide

    Microsoft

    Redmond, WA
    3 days ago
  • As a Principal Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls organization, you lead at least one technical area with a security engineering focus, and drive impact within teams, technologies, and projects across departments. Utilize... 

    JP Morgan Chase

    Seattle, WA
    18 hours ago
  • $191k - $297k

     ...Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM).... 
    Full time
    Work at office

    Nordstrom

    Seattle, WA
    2 days ago
  •  ...aware that all official communication will only be sent from @Rippling.com addresses.About the roleRippling is looking for a Principal Security Engineer to tackle some of the most complex, cross-cutting security challenges across our technical ecosystem. Reporting directly... 
    Work at office
    3 days per week

    Rippling

    San Francisco, CA
    3 days ago
  • $142k - $186k

    DevSecOps Engineer - IAMAs a DevSecOps Engineer, you will be responsible for the development, administration, maintenance, promotion, and...  ...in cloud development and applications teams to ingest IAM secure code, API, policies, and controls as part of the normal CI/CD pipeline... 
    Local area
    Monday to Friday
    Flexible hours

    Citizens Financial Group

    Johnston, RI
    1 day ago
  • $401k

     ...artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products....  ...robust security culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team.... 
    Work at office
    Local area
    Remote work
    Flexible hours

    OpenAI

    San Francisco, CA
    2 days ago
  • $180k - $220k

     ...aviation data software used by pilots and operators worldwide. As Principal Security Architect, you’ll own the technical security strategy...  ...IT and SaaS environments, partnering closely with engineering, infrastructure, product security, and compliance functions... 
    Immediate start
    Remote work
    Worldwide

    ForeFlight

    Englewood, CO
    1 day ago
  • $104.9k - $174.7k

     ...technical guidance that shapes how we approach security across the organization — with real...  ...detection) into CI/CD pipelines in ways engineers actually embrace rather than route...  ...slowing everything to a crawl At the Principal Level, additionally: Shape multi-year... 
    Local area

    Hackajob

    Raleigh, NC
    2 days ago
  • $142.8k - $274.8k

     ...Principal Security Engineer The Microsoft Offensive Research & Security Engineering (MORSE) team is looking for a Principal Security Engineer to help secure Microsoft's products and devices. MORSE is responsible for securing Microsoft's operating systems and platform... 
    Local area
    Worldwide

    Microsoft Corporation

    Pittsburgh, PA
    1 day ago
  • $106.3k - $234.6k

     ...cloud products that meet the needs of our customers who are tackling some of the world's biggest challenges. As a Principal Hardware Security Engineer you will be involved in ensuring that the compute hardware that is used in the Oracle Cloud Infrastructure meets the... 
    Temporary work
    Flexible hours

    Oracle

    Boston, MA
    3 days ago
  • $96k - $132k

     ...Baxter At Baxter Healthcare Corporation, we invite a driven Principal Engineer, Cybersecurity who is passionate about contributing to healthcare...  ..., assuring that our solutions are consistently highly secure. This is where your expertise helps people Your expertise will... 
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Baxter

    Skaneateles Falls, NY
    2 days ago
  • $203.5k - $275.3k

     ...built the world's most adopted cloud. Join us and help us grow. AWS is building a new security engineering team for the AWS Global Sales (AGS) organization, and we're looking for a Principal Technical Program Manager to help define it from day one. Customers are moving... 
    Local area
    Worldwide
    Flexible hours
    Shift work
    Day shift

    Amazon

    Herndon, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Security Engineer. Be the first to apply!