> Markdown version of [/jobs/ext/2722732-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/2722732-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Seesaw Learning, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $177,600.0 - $210,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing Security, Code Review, Identity and Access Management, Systems Development Life Cycle, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Logging, Cloud Platform System, Software Security, Infrastructure Automation Frameworks, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/principal-security-engineer-seesaw-2-7920479 ## About the Role Must-Haves * 7+ years of hands-on software engineering experience * Strong experience in application security (threat modeling, code review, SDLC integration) * Experience securing cloud environments (AWS, GCP, or Azure), including IAM and networking * Ability to operate both strategically and tactically-setting direction while staying hands-on * Strong communication skills; able to translate security concepts into clear, actionable guidance Nice-to-Haves * Experience with compliance frameworks (SOC 2, ISO 27001) * Familiarity with security tooling (SAST, DAST, SCA, SIEM, vulnerability management) * Experience building security programs in startup or high-growth environments * Relevant certifications (CISSP, CCSP, CSSLP, OSCP), though not required ## Description You'll be joining our collaborative, mission-driven Engineering organization and reporting directly to our EVP of Engineering. In this role, you'll work closely with Engineering, IT, and Legal teams - acting as a key cross-functional partner bridging technical execution and organizational risk. You won't be siloed in a security corner; you'll be embedded in the heart of our product and infrastructure decisions, partnering across the company to make security a shared responsibility at every level., We're looking for a Principal Senior Security Engineer who is, first and foremost, an exceptional software engineer - one who has developed deep expertise in security along the way. This is not a governance-only or leadership-only role. You'll be expected to write code, review architecture, shape our SDLC, and get your hands dirty alongside our engineering team while also owning the strategic direction of our security program., * Own and drive the company's security strategy, roadmap, and overall posture * Serve as the internal expert on security best practices and risk management * Partner cross-functionally to ensure security is embedded across engineering, product, IT, and legal Application Security & Secure SDLC * Lead threat modeling, secure code reviews, and architecture reviews * Define and enforce secure coding standards and vulnerability management processes * Drive adoption of SAST, DAST, SCA, and other security tooling Hands-On Engineering * Build and maintain security tooling, automation, and infrastructure as code * Implement security controls across application, API, and infrastructure layers * Partner with engineers on authentication, authorization, and data protection Infrastructure & DevSecOps * Own vulnerability scanning, patching, and incident response processes * Strengthen cloud security (IAM, networking, secrets, logging, monitoring) * Integrate security into CI/CD pipelines and automate security gates Compliance & Policy * Partner with Legal to develop and maintain security policies and standards * Lead or support compliance efforts (e.g., SOC 2, ISO 27001) * Stay ahead of evolving regulatory requirements ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)