> Markdown version of [/jobs/ext/1426461-principal-security-platform-engineer](https://www.wearedevelopers.com/jobs/ext/1426461-principal-security-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Platform Engineer - **Company:** Western Alliance Bancorporation - **Location:** Phoenix, AZ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Configuration Management Databases, Cyber Security, System Configuration, Identity and Access Management, Information Security Management, Python (Programming Language), Windows PowerShell, Salesforce.Com, Security Information and Event Management, Single Sign-On, Software Vulnerability Management, Office365, Information Technology, SailPoint, Webhooks, Workday, Security Orchestration, Automation & Response, Servicenow - **Published:** July 24, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17690690?backUrl=%2Fcareer%2F17690690%2FPrincipal-Security-Platform-Engineer-Arizona-Phoenix ## About the Role * Bachelor's degree in computer science, Information security, IT, or related field (or equivalent experience). * 8+ years of progressive experience in Information security engineering with a focus on cloud/SaaS security, posture management, or attack surface management. * Strong working knowledge of AWS, Azure, and Entra security models; Microsoft 365, Workday, Salesforce, and ServiceNow security configurations a plus. * Proficiency with APIs, Python (or PowerShell) scripting, and integration patterns (REST, webhooks, eventdriven). * Experience integrating security tooling with SIEM/SOAR, ServiceNow, and IAM platforms (SailPoint/Entra preferred). * Advanced to expert knowledge of applicable regulatory and legal compliance obligations, rules and regulations, industry standards, and practices. * Advanced to expert experience in leading cross-functional teams and managing multiple projects simultaneously with an established expertise with the ability to walk-through top-level process design. Capable of working with regulatory partners like the CFPB, OCC and FRB through audits and collaboration efforts as situations arise. * Familiarity with regulatory and risk frameworks relevant to banking (FFIEC, SOX, GLBA, NIST CSF). * Excellent written communication; able to translate technical posture findings into executivelevel risk narratives. ## Description As a Principal Engineer I you'll provide SME expertise in your respective domain as well as adjacent domains to ensure solutions are safe, secure, compliant, and reliable. You'll identify development and support needs as well as take on large and complex design responsibilities supporting project tasks. You'll also engage with project and business sponsors refining requirements and objectives of targeted solutions. As Principal Engineer I, you also facilitate dialogue and activities, and work to ensure team collaboration, including teams outside of your domain., This role is being established as part of the Anthropic/Mythos response to stand up and operate the new SaaS-based defensive tooling the bank is adding to offset Mythos-era risk (e.g., SaaS Security Posture Management, Attack Surface Management, and adjacent cloud/SaaS security platforms). The Security Platform Engineer will own end to end onboarding, configuration, integration, and ongoing operations of 2-3 new SaaS platforms supporting the CISO Office and will flex into adjacent Mythos workstreams (cloud security hygiene, vulnerability remediation, segmentation tooling) as gaps emerge. * Build solution designs for SSPM, ASM, and adjacent SaaS security efforts that can be handed off to engineers and analysts for execution while promoting reuse of approved platforms, integration patterns, and enterprise standards where possible * Lead vendor onboarding, environment setup, SSO/Entra integration, role design, and production cutover for new SaaS security platforms (SSPM, ASM, and followon tools) * Design and implement baseline policies, detection rules, posture benchmarks, and attacksurface reduction configurations across all connected SaaS apps (M365, Workday, ServiceNow, Salesforce, etc.) * Build and maintain API/event-driven integrations between SSPM/ASM and SIEM, SOAR, ServiceNow, CMDB, and IAM (SailPoint, Entra) to operationalize findings endtoend * Review technical plans developed by engineers and analysts to ensure designs are secure, scalable, operationally supportable, and aligned to the performance, volumetric, and risk objectives of business partners * Monitor platform health, manage upgrades/patches, tune alerting, triage incidents, and own vendor escalations to keep tooling stable and effective * Track, prioritize, and drive remediation of SaaS misconfigurations, and exposed assets identified in partnership with app owners * Flex into adjacent Mythos workstreams (cloud security hygiene, accelerated vulnerability remediation, EOS remediation, segmentation tooling support) as priorities shift across the 90day plan and beyond * Build comprehensive dashboards that provide visibility into SaaS platform performance, security posture, remediation progress, control effectiveness, and operational outcomes for security leadership and business partners * Maintain runbooks/SOPs, contribute to KB articles, document physical and logical solution layouts with cross-reference to use cases, enforce architecture and operational standards, produce executive-level posture metrics, and support audit/regulatory evidence requests in partnership with the BISO and 2LOD * Collaborate with Infrastructure & Operations, IAM, Endpoint Engineering, SOC, GRC, and the BISO team to ensure SaaS security controls align with enterprise standards ## Related Videos - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Beyond Webhooks: The Future of Scalable API Event Delivery](https://www.wearedevelopers.com/videos/100312-beyond-webhooks-the-future-of-scalable-api-event-delivery) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [The Future of Employee Wellbeing: Benefits, Trust & Performance](https://www.wearedevelopers.com/videos/1808-the-future-of-employee-wellbeing-benefits-trust-performance) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)