> Markdown version of [/jobs/ext/2708343-first-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/2708343-first-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # first Principal Security Engineer - **Company:** Topaz Labs - **Location:** Dallas, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Amazon Web Services, Software Applications, Software System Penetration Testing, Bash Shell, Cloud Computing Security, Computer Clusters, System Configuration, Data Centers, Linux, Identity and Access Management, Networking Hardware, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Linux Kernel, Reverse Engineering, Web Applications, Scripting, High Performance Computing, Amazon Virtual Private Cloud (VPC), Kubernetes, Casper Suite - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-security-engineer-topaz-labs-7500872 ## About the Role * You are a hands-on generalist. You are just as comfortable configuring an IAM policy in AWS as you are setting up a switch in a colocation rack or writing a script for Jamf. * You have a craftsmanship mentality. You take personal pride in building systems that are robust, elegant, and secure by default. You don't just patch holes; you eliminate entire classes of vulnerabilities. * You are an infrastructure native. You are fluent in Linux internals, networking, and container orchestration. You understand the unique security challenges of cloud, distributed, and HPC environments. * You value truth over comfort. You are willing to have hard conversations about risk and prioritize fixing root causes over applying band-aids. * You think like an attacker. You don't wait for a report to tell you something is wrong. You actively probe our defenses (office, colo, and cloud) to prove they work., * 7+ years of experience in security engineering, with a mix of infrastructure, corporate IT, and offensive security. * Deep hands-on experience with cloud security and compliance (AWS, IAM, VPC, SOC II, Vanta). * Proven experience with Endpoint Management & Identity: Expert-level knowledge of Jamf for macOS management and Active Directory (or modern equivalents) for identity governance. * Physical & Network Security: Experience securing physical office networks and colocation facilities (firewalls, VPNs, switching). * Offensive Security: Demonstrated ability to perform manual penetration testing (network and web app).Proficiency in scripting (Python/Bash) to automate security tasks. * Bonus: Experience securing on-device software or desktop applications (Windows/macOS). Do you meet most but not 100% of the above? We'd still like to hear from you-we are passionate about developing a diverse team and culture, so please apply if you're interested! ## Description * Secure the Hybrid Infrastructure (AWS & Colo): You will be the single owner for security across our cloud environments and our physical colocation data centers. This includes configuring firewalls, managing physical network security, and hardening our Linux GPU clusters. * Corporate & Endpoint Security: You will own the security of our internal tools and devices. You will manage our fleet (primarily macOS) using Jamf and oversee identity management via Active Directory. * You ensure our creative workflows are secure without being obstructive. * Hands-On Penetration Testing: We don't just rely on external audits. You will regularly conduct hands-on penetration tests against our internal networks, office infrastructure, and AI applications to find vulnerabilities before anyone else does. * Secure the AI Supply Chain: Our models are our most valuable IP. You will design systems to protect our model weights during training, storage, and delivery, ensuring they are tamper-proof and secure from theft or reverse engineering. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)