> Markdown version of [/jobs/ext/146034-senior-principal-security-engineer-cloud-application-security](https://www.wearedevelopers.com/jobs/ext/146034-senior-principal-security-engineer-cloud-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Principal Security Engineer - Cloud & Application Security - **Company:** Saviynt Inc. - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $260,000.0 - $275,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Audit Trail, Microsoft Azure, Burp Suite, Cloud Computing, Static Program Analysis, Cyber Security, Computer Networks, Database Security, DDoS Mitigation, Disaster Recovery, Elasticsearch, Groovy, Grails (Framework), Java Virtual Machine (JVM), Python (Programming Language), Key Management, Network Security, PostgreSQL, MySQL, Network Architecture, Oracle (Applications), Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Role-Based Access Control, Zero Trust Network Access, Secure Coding, Software Engineering, Data Streaming, SSL Certificate Management, Data Classification, Istio, Spring-boot, Software Security, Amazon Virtual Private Cloud (VPC), Cloudformation, Kubernetes, Hashicorp, Cloudflare, Linkerd (Service Mesh), Azure AKS, Software Coding, Firewall Services Module, Terraform, AWS EKS, Docker, Static Application Security Testing, Vulnerability Analysis - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d4567c3260a7c93e ## About the Role We are looking for a Principal Security Engineer to lead application and infrastructure security efforts across our engineering organization. You will be hands-on identifying vulnerabilities, writing fixes, and working directly with tiger teams to resolve critical and zero-day issues under pressure. This is not a governance-only role; you will code, review, and ship., * 10+ years in software engineering or security engineering, with 5+ years focused on application and infrastructure security * AI first approach to assess, design, triage and fix issues. Produce shareable AI artifacts for others to scale fixing issues * Deep expertise in static analysis (SAST), software composition analysis (SCA), and secret scanning across JVM ecosystems (Java, Spring Boot, Grails) and Python * Strong hands-on coding ability - you can read, write, and fix code in Java, Python, and Groovy * Production experience securing Kubernetes workloads on AWS EKS or Azure AKS * Solid understanding of container security - image scanning, runtime protection, least-privilege configurations * Strong knowledge of end-to-end encryption - TLS/mTLS implementation, certificate management, PKI, key rotation, and secrets management (HashiCorp Vault, AWS KMS,Azure Key Vault) * Proven experience conducting threat modeling on product requirements - ability to partner with product teams early in the SDLC to identify and mitigate risks before implementation * Working knowledge of network security: ingress/egress controls, TLS termination, mTLS, VPC/VNET segmentation * Practical experience with penetration testing tools and methodologies (Burp Suite, OWASP ZAP, etc.) * Strong command of OWASP Top 10 vulnerabilities and their mitigations * Demonstrated experience evangelizing security culture - delivering training, mentoring developers, and driving adoption of secure coding practices using security training platforms * Experience responding to critical security incidents and zero-day disclosures in fast-paced environments ## Description * Lead SAST, SCA, and secret detection initiatives across Java, Spring Boot, Grails, JVM-based, and Python application and IaC stacks * Triage, prioritize, and remediate vulnerabilities - including writing code fixes * Define and enforce container security standards for Docker images, base image hardening, and runtime policies * Secure Kubernetes clusters on AWS EKS and/or Azure AKS - RBAC, network policies, pod security standards, admission controllers * Experience with infrastructure-as-code security scanning - Terraform, CloudFormation, and Helm chart security review and hardening * Conduct threat modeling on new features and requirements provided by product teams - identify attack surfaces, data flow risks, and trust boundaries before code is written (STRIDE, DREAD, or equivalent frameworks) * Conduct targeted penetration testing and vulnerability assessments on applications and infrastructure * Assess application security needs and recommend WAF, DDoS protection, and rate limiting strategies (e.g., Cloudflare, AWS WAF/Shield, Azure Front Door) * Collaborate with tiger teams during incident response to analyze, contain, and remediate critical and zero-day vulnerabilities * Evangelize OWASP Top 10 awareness and secure coding practices across engineering teams through structured training programs, lunch-and-learns, and hands-on workshops * Administer a security training platform - curate learning paths, track completion metrics, and ensure all engineers complete baseline secure coding training * Evaluate, integrate and mature security tooling into CI/CD pipelines * Experience building internal security tooling or custom SAST/SCA rules, * Database security experience - access controls, query injection prevention, audit logging, encryption at the storage layer (PostgreSQL, MySQL, Oracle, Elasticsearch) * Familiarity with service mesh security (Istio, Linkerd) * Design and review network security controls including ingress/egress traffic policies, service mesh configurations, and firewall rules * Implement and enforce end-to-end encryption using TLS and mTLS across services - certificate lifecycle management, trust chain validation, and zero-trust network architecture If required for this role, you will: * Complete security & privacy literacy and awareness training during onboarding and annually thereafter * Review (initially and annually thereafter), understand, and adhere to Information Security/Privacy Policies and Procedures such as (but not limited to): > Data Classification, Retention & Handling Policy > Incident Response Policy/Procedures > Business Continuity/Disaster Recovery Policy/Procedures ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)