Principal Security Engineer
Role details
Job location
Tech stack
Job description
As a Principal Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified and fixed. You will also build and operate AI agents and workflows that make that work scale across the product portfolio.
This is a technical role. The ideal candidate has engineering instincts, can build AI-powered workflows, and knows how to work alongside development teams rather than audit them from the outside.
What you'll do
- Report directly to the Head of Application Security.
- Build, extend, and operate AI-powered agents and workflows that automate vulnerability remediation tasks.
- Drive vulnerabilities to closure by working directly with development teams.
- Act as a security champion embedded across Bonterra's engineering organizations, building trust and normalizing secure development practices.
- Triage and prioritize findings from SAST, SCA, IaC scanners, filtering noise and surfacing what needs immediate attention.
- Integrate security validation into CI/CD pipelines and developer workflows.
- Support SOC 2, PCI-DSS, HIPAA, and other audits as needed.
Requirements
- Demonstrated experience building AI agents, LLM-powered workflows, or automated pipelines.
- Working knowledge of software vulnerability classes, how CVEs are assessed, and what good remediation looks like.
- Understand how software gets built and where security integrates into the development process.
- You can translate a security finding into language a developer can act on without a security background.
What sets you apart
- An extensive track record of building AI agents to solve real operational problems that accelerate outcomes.
- Experience with SAST/SCA platforms at an engineering team level.
- Prior work building or running a security champion program.
- Familiarity with AWS security services or cloud environment security.
- Knowledge of application security frameworks -- OWASP Top 10, NIST, CVSS scoring.
- Previous software development experience.
Benefits & conditions
At Bonterra, we're innovating with a higher purpose: to increase giving to 3% of US GDP by 2033, creating $573 billion more in global impact every year. At Bonterra, we foster an inclusive, equitable culture where every team member belongs and contributes to meaningful impact. Read more about our values and culture here. Compensation & Benefits
We offer a comprehensive benefits package that supports your health, well-being and growth - explore full details here.
Compensation and benefits for this role apply to full-time employees in the United States and may vary based on local standards, laws and norms. Pay is determined by location, skills, experience, and education, and is one part of Bonterra's total rewards package, which may also include bonuses, incentives, equity, and a comprehensive benefits program.