Principal Security Platform Engineer

Western Alliance Bancorporation
Phoenix, AZ, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Security Configuration Management Databases Cyber Security System Configuration Identity and Access Management Information Security Management Python (Programming Language)
+12 more
Windows PowerShell Salesforce.Com Security Information and Event Management Single Sign-On Software Vulnerability Management Office365 Information Technology SailPoint Webhooks Workday Security Orchestration, Automation & Response Servicenow

Job description

As a Principal Engineer I you’ll provide SME expertise in your respective domain as well as adjacent domains to ensure solutions are safe, secure, compliant, and reliable. You’ll identify development and support needs as well as take on large and complex design responsibilities supporting project tasks. You’ll also engage with project and business sponsors refining requirements and objectives of targeted solutions. As Principal Engineer I, you also facilitate dialogue and activities, and work to ensure team collaboration, including teams outside of your domain., This role is being established as part of the Anthropic/Mythos response to stand up and operate the new SaaS-based defensive tooling the bank is adding to offset Mythos-era risk (e.g., SaaS Security Posture Management, Attack Surface Management, and adjacent cloud/SaaS security platforms). The Security Platform Engineer will own end to end onboarding, configuration, integration, and ongoing operations of 2-3 new SaaS platforms supporting the CISO Office and will flex into adjacent Mythos workstreams (cloud security hygiene, vulnerability remediation, segmentation tooling) as gaps emerge.

  • Build solution designs for SSPM, ASM, and adjacent SaaS security efforts that can be handed off to engineers and analysts for execution while promoting reuse of approved platforms, integration patterns, and enterprise standards where possible
  • Lead vendor onboarding, environment setup, SSO/Entra integration, role design, and production cutover for new SaaS security platforms (SSPM, ASM, and followon tools)
  • Design and implement baseline policies, detection rules, posture benchmarks, and attacksurface reduction configurations across all connected SaaS apps (M365, Workday, ServiceNow, Salesforce, etc.)
  • Build and maintain API/event-driven integrations between SSPM/ASM and SIEM, SOAR, ServiceNow, CMDB, and IAM (SailPoint, Entra) to operationalize findings endtoend
  • Review technical plans developed by engineers and analysts to ensure designs are secure, scalable, operationally supportable, and aligned to the performance, volumetric, and risk objectives of business partners
  • Monitor platform health, manage upgrades/patches, tune alerting, triage incidents, and own vendor escalations to keep tooling stable and effective
  • Track, prioritize, and drive remediation of SaaS misconfigurations, and exposed assets identified in partnership with app owners
  • Flex into adjacent Mythos workstreams (cloud security hygiene, accelerated vulnerability remediation, EOS remediation, segmentation tooling support) as priorities shift across the 90day plan and beyond
  • Build comprehensive dashboards that provide visibility into SaaS platform performance, security posture, remediation progress, control effectiveness, and operational outcomes for security leadership and business partners

  • Maintain runbooks/SOPs, contribute to KB articles, document physical and logical solution layouts with cross-reference to use cases, enforce architecture and operational standards, produce executive-level posture metrics, and support audit/regulatory evidence requests in partnership with the BISO and 2LOD
  • Collaborate with Infrastructure & Operations, IAM, Endpoint Engineering, SOC, GRC, and the BISO team to ensure SaaS security controls align with enterprise standards

Requirements

  • Bachelor’s degree in computer science, Information security, IT, or related field (or equivalent experience).
  • 8+ years of progressive experience in Information security engineering with a focus on cloud/SaaS security, posture management, or attack surface management.
  • Strong working knowledge of AWS, Azure, and Entra security models; Microsoft 365, Workday, Salesforce, and ServiceNow security configurations a plus.
  • Proficiency with APIs, Python (or PowerShell) scripting, and integration patterns (REST, webhooks, eventdriven).
  • Experience integrating security tooling with SIEM/SOAR, ServiceNow, and IAM platforms (SailPoint/Entra preferred).
  • Advanced to expert knowledge of applicable regulatory and legal compliance obligations, rules and regulations, industry standards, and practices.
  • Advanced to expert experience in leading cross-functional teams and managing multiple projects simultaneously with an established expertise with the ability to walk-through top-level process design. Capable of working with regulatory partners like the CFPB, OCC and FRB through audits and collaboration efforts as situations arise.
  • Familiarity with regulatory and risk frameworks relevant to banking (FFIEC, SOX, GLBA, NIST CSF).
  • Excellent written communication; able to translate technical posture findings into executivelevel risk narratives.

Benefits & conditions

We offer all the important things you’d want - like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you’ll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!

About the company

Western Alliance Bank, Member FDIC, is a wholly owned subsidiary of Western Alliance Bancorporation. Serving clients nationwide, Western Alliance Bank includes six legacy bank brands - Alliance Association Bank, Alliance Bank of Arizona, Bank of Nevada, Bridge Bank, First Independent Bank and Torrey Pines Bank - that remain part of the company’s heritage, as well as AmeriHome Mortgage, a Western Alliance Bank Company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

1:28 min

Synchronizing database webhook triggers with pipeline webhooks

Bobur Umurzokov · LIVE

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:30 min

Consumer challenges in ingesting and verifying webhooks

Phil Leggetter Phil Leggetter · WWC Europe 2026

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all