> Markdown version of [/jobs/ext/2869829-principal-product-security](https://www.wearedevelopers.com/jobs/ext/2869829-principal-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Product Security - **Company:** Itron, Inc. - **Location:** West Union, SC, United States - **Experience:** Expert - **Salary:** $96,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Information Systems, Continuous Integration, DevOps, Github, Revision Control Systems, Identity and Access Management, Integrated Development Environments, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Open Web Application Security, Windows PowerShell, Release Management, Cloud Services, Secure Coding, Software Engineering, Software Vulnerability Management, Policy as Code, Data Logging, Scripting, Delivery Pipeline, Software Security, Gitlab, Cloudformation, GWAPT, Gitlab-ci, Information Technology, Deployment Automation, Build Tools, Bitbucket, Terraform, Software Version Control, Devsecops, Jenkins - **Published:** September 12, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18284754?backUrl=%2Fcareer%2F18284754%2FPrincipal-Product-Security-South-Carolina-West-Union ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experience. * 7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical discipline. * 5+ years of hands-on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains. * Expert-level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environments. * Strong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices. * Deep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization models. * Experience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processes. * Experience implementing path-to-production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria. * Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholders. * Proven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practices. * Strong written, verbal, and stakeholder-management skills. Preferred Skills & Experience * Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certifications. * Hands-on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanning. * Experience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutions. * Knowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controls. * Familiarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10. * Experience applying application and API security principles across web, cloud, mobile, embedded, and service-based architectures. * Experience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy-as-code approaches to automate security controls. * Understanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulation. * Experience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks., The successful candidate's starting wage will be determined based on permissible, non-discriminatory factors such as skills and experience. ## Description As a member of the Information Security team, you will serve as the senior technical leader responsible for advancing Itron's product security program across software development, cloud, and engineering environments. This role focuses on securing source code, software supply chains, CI/CD pipelines, and product architectures while enabling agile, customer-centric development practices. You will collaborate closely with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to design and implement scalable security solutions that protect Itron products and services throughout the development lifecycle. Duties & Responsibilities * Lead the architecture and engineering of security controls that protect source code repositories, development environments, build systems, software supply chains, and release processes. * Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows that ensure software integrity from code commit through product release. * Partner with security-by-design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls. * Establish and promote secure application and API security standards, including authentication, authorization, secure coding practices, data protection, logging, and abuse prevention. * Collaborate with engineering teams to reduce application, API, and cloud attack surfaces through secure architecture, identity management, and least-privilege access models. * Drive modernization of development and engineering environments to mitigate risks associated with credential compromise, malicious code, dependency attacks, and unauthorized releases. * Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions. * Automate security controls and operational processes using APIs, infrastructure-as-code, and scripting technologies such as Python, PowerShell, Terraform, GitHub Actions, Azure DevOps, Jenkins, and GitLab. * Establish security logging, monitoring, and detection requirements for software development and release environments in partnership with security operations teams. * Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation that support scalable and innovative product delivery. * Ensure auditable evidence exists for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements. * Mentor engineers and influence cross-functional teams to adopt secure, customer-focused, collaborative, and accountable engineering practices across global product environments. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)