> Markdown version of [/jobs/ext/2419282-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/2419282-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Smartsheet Inc. - **Location:** Seattle, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $205,000.0 - $257,500.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Software as a Service, Cloud Computing Security, Code Review, Continuous Integration, Data Flow Control, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Secure Coding, TypeScript, Smartsheet, Large Language Models, Multi-Agent Systems, Software Security, Gitlab-ci, Static Application Security Testing - **Published:** August 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=78a116a81522d317 ## About the Role * 10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering, including direct ownership of threat modeling programs and security review services at scale. * Ability to own threat modeling as a systematic practice (STRIDE, data-flow and architecture diagram driven), producing concrete, actionable test scenarios and abuse cases, embedded into agile design cycles as a repeatable, lightweight practice. * Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in the OWASP LLM Top 10 and current AI attack classes, plus experience using AI tooling to scale security review coverage. * Experience doing architecture review and targeted manual code review for complex SaaS features, with a track record of driving remediation requirements through to implementation with enough technical credibility to influence design decisions at the engineering leadership level. * Experience mentoring engineers into threat modeling ownership and attacker-mindset review design; demonstrated track record of establishing security requirements as design-phase gates and sustaining engagement with engineering teams to drive implementation. * Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to credibly influence toolchain direction, resolve standards decisions that span teams, and shape secure coding standards without primary operational ownership; cloud security fundamentals sufficient to tie application controls to the infrastructure they run on. * Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent); comfortable reading production codebases to surface issues tooling misses and writing or extending automation others can maintain. * Expertise communicating risk and security requirements (written and verbal) clearly across audiences from engineering ICs through executive leadership; recognized as a trusted technical voice by partner teams. * Ability to build trusted relationships across engineering, product, and security organizations; earns influence through technical credibility and sustained engagement. * Legally eligible to work in the U.S. on an ongoing basis. Nice to Have: * GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration. * Experience building AI-assisted security tooling or LLM-integrated review workflows that scale security review coverage. * Penetration testing depth including exploit writing or vulnerability chaining to validate exploitability and prove real-world impact. * Public-facing security contributions: conference speaking, CVE credits, published research, or industry community recognition that reflects the technical authority expected at principal level. ## Description * Lead Threat Modeling and Product Security Reviews: Own threat modeling and product security review as the team's primary upstream capability: build models from architecture and data-flow artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. Define and lead the product security review service (set the service model, triage criteria, and enforcement posture) and personally execute reviews for high-risk features with documented findings and remediation timelines. Engage product and engineering directly to establish security requirements at the design phase, with the technical credibility to influence architecture decisions. * Define AI Security Methodology and Drive It Across the Practice: Define how AI security risk is assessed, monitored, and mitigated across product, engineering, and third-party AI integrations, with recognized depth on the current threat landscape: LLM workflows, agentic pipelines, MCP-based integrations, and attack classes including prompt injection, indirect injection, and tool-calling authorization gaps. Own and evolve the AI-assisted security review capability: evaluate detection value, assess build-vs-buy tradeoffs, and shape toolchain coverage as Smartsheet's AI-integrated product surface scales. * Shape AppSec Technical Direction and SDLC Controls: Serve as the technical authority for the AppSec program's SDLC control surface (secure coding guidelines, CI/CD pipeline security strategy, and toolchain direction across SAST, SCA, secrets, and IaC scanning) with the depth to influence tool decisions and resolve standards decisions that span teams without primary operational ownership. Build runbooks, standards, and documentation that create consistency and reduce single-point-of-failure risk as the team scales. * Elevate Team Capability and Engineering Organization Influence: Mentor AppSec team members on threat modeling tradecraft and security review design, and serve as the trusted technical voice with product and engineering leadership, framing risk in terms that move architecture decisions. Your judgment shapes how the team prioritizes and how the broader organization understands and invests in application security. ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [TypeScript Features That Changed the Game](https://www.wearedevelopers.com/videos/100061-typescript-features-that-changed-the-game) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)