> Markdown version of [/jobs/ext/1507579-principal-security-architect-product-application](https://www.wearedevelopers.com/jobs/ext/1507579-principal-security-architect-product-application). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architect, Product & Application - **Company:** Cambridge Mobile Telematics - **Location:** Cambridge, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $130,600.0 - $163,300.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, User Authentication, Cyber Security, Key Management, Machine Learning, Open Web Application Security, Systems Development Life Cycle, Reverse Engineering, Secure Coding, Mobile Security, Software Engineering, Systems Architecture, Web Services, Large Language Models, Software Security, Backend, Data Pipelines - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d296ec23990eecbe ## About the Role * Bachelor's degree or equivalent years of experience and/or certification in a related field * 7+ years of experience in security with deep expertise in application and product security architecture * Proven ability to set technical direction and drive security initiatives through influence in a highly autonomous role * Strong software engineering foundation with experience reviewing code and system architecture across web services, APIs, and mobile platforms * Deep knowledge of secure SDLC, threat modeling, OWASP, authentication, cryptography, API security, and mobile security * Experience securing products that process sensitive personal data while supporting privacy and regulatory requirements * Working knowledge of AI/ML and LLM security, including the secure adoption of AI development tools * Excellent written and verbal communication skills Nice to Haves: * Experience with mobile SDK security, reverse engineering, and anti-tampering * Familiarity with data-intensive architectures and ML-driven products * Experience developing AI governance or secure AI adoption programs * Experience in telematics, IoT, connected vehicles, fintech, or other high-trust industries * Relevant certifications such as CSSLP, OSCP, or GWEB ## Description * Own the end-to-end security architecture for CMT's products, including mobile SDKs, backend services, APIs, data pipelines, and partner integrations * Define security standards, reference architectures, and engineering guardrails, and drive adoption across the organization * Partner with product and engineering leaders to embed security throughout the SDLC * Lead threat modeling and define application security strategy, including testing, secure coding, secrets management, and software supply chain security * Own security architecture for protecting sensitive data and supporting privacy and regulatory requirements * Define security architecture and guardrails for AI-powered products and AI development tools * Own the Product Security roadmap, including technology strategy, prioritization, and risk-based decision making * Serve as the senior security authority for architecture reviews, technical guidance, and customer security engagements * Mentor engineers and champion secure design practices across the organization * Complete any additional tasks as they arise ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)