Principal Security Engineer

The MathWorks, Inc.
Natick, MA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$160,800.0 - $209,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Engineering Cyber Security Computer Programming Continuous Integration Programming Tools Github Python (Programming Language) Package Management Systems Systems Development Life Cycle Software Engineering Delivery Pipeline
+8 more
Malware Gitlab Build Management Kubernetes Teamcity Jenkins Vulnerability Analysis Artifactory

Job description

We’re looking for a hands-on, highly collaborative Principal Security Engineer to secure our software delivery pipeline. You’ll take ownership of protecting our CI/CD processes, Artifactory, and Internal Developer Platform against supply chain risks and malware attacks. This is a technical, impact-driven role where your expertise in threat modeling, security architecture, and systems design will shape our approach to secure software delivery at scale.

MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.

Responsibilities

  • Design, implement, and continuously improve security controls across our CI/CD pipeline, Artifactory, and developer platforms

  • Collaborate with various teams and key stakeholders within the organization to embed security best practices in software delivery workflows

  • Lead threat modeling and risk assessments for our build and release pipelines

  • Build and deploy custom security solutions and integrations as needed

  • Monitor, detect, and respond to threats targeting our development infrastructure

Requirements

  • A bachelor’s degree and 10 years of professional work experience (or equivalent experience) is required.

Additional Qualifications

  • Proficiency in programming languages such as Python, Rust, or Go

  • Experience with security threat modeling, penetration testing, and security reviews.

  • Deep understanding of the software development lifecycle (SDLC), particularly in large, complex enterprise environments, and a passion for improving the developer experience

  • Deep understanding of modern attack vectors targeting software supply-chain through malicious code, third-party libraries, and CI/CD systems

  • Advanced knowledge of developer tools, internal build and dependency systems

  • Experience with trusted software supply chain concepts, including security standards and best practices (e.g., SLSA), dependency/package management, vulnerability scanning, signing, provenance, and tools such as TeamCity, Jenkins, GitHub, GitLab, Artifactory, and Kubernetes

  • Experience with Cloud Native Computing Foundation (CNCF) projects related to CI/CD, security, and developer workflow

  • Ability to collaborate with large, distributed engineering teams to contextualize and prioritize supply chain threats

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all