> Markdown version of [/jobs/ext/1762074-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/1762074-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** The MathWorks, Inc. - **Location:** Natick, MA, United States - **Salary:** $160,800.0 - $209,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Engineering, Cyber Security, Computer Programming, Continuous Integration, Programming Tools, Github, Python (Programming Language), Package Management Systems, Systems Development Life Cycle, Software Engineering, Delivery Pipeline, Malware, Gitlab, Build Management, Kubernetes, Teamcity, Jenkins, Vulnerability Analysis, Artifactory - **Published:** July 7, 2026 - **Apply:** https://www.juju.com/job/00000000gejcnh ## About the Role + A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required. Additional Qualifications + Proficiency in programming languages such as Python, Rust, or Go + Experience with security threat modeling, penetration testing, and security reviews. + Deep understanding of the software development lifecycle (SDLC), particularly in large, complex enterprise environments, and a passion for improving the developer experience + Deep understanding of modern attack vectors targeting software supply-chain through malicious code, third-party libraries, and CI/CD systems + Advanced knowledge of developer tools, internal build and dependency systems + Experience with trusted software supply chain concepts, including security standards and best practices (e.g., SLSA), dependency/package management, vulnerability scanning, signing, provenance, and tools such as TeamCity, Jenkins, GitHub, GitLab, Artifactory, and Kubernetes + Experience with Cloud Native Computing Foundation (CNCF) projects related to CI/CD, security, and developer workflow + Ability to collaborate with large, distributed engineering teams to contextualize and prioritize supply chain threats ## Description We're looking for a hands-on, highly collaborative Principal Security Engineer to secure our software delivery pipeline. You'll take ownership of protecting our CI/CD processes, Artifactory, and Internal Developer Platform against supply chain risks and malware attacks. This is a technical, impact-driven role where your expertise in threat modeling, security architecture, and systems design will shape our approach to secure software delivery at scale. MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence. Responsibilities + Design, implement, and continuously improve security controls across our CI/CD pipeline, Artifactory, and developer platforms + Collaborate with various teams and key stakeholders within the organization to embed security best practices in software delivery workflows + Lead threat modeling and risk assessments for our build and release pipelines + Build and deploy custom security solutions and integrations as needed + Monitor, detect, and respond to threats targeting our development infrastructure ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)