Principal Product Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
Insight Global is seeking a Principal Product Security Engineer to serve as the senior security leader embedded within a product engineering organization. This individual will partner directly with Product Managers, Architects, Technical Leads, and Engineering teams to design, build, secure, and modernize critical business applications.
This role will initially focus heavily on security architecture, solution design, and secure development practices. As security capabilities mature within the product portfolio, the role will evolve into a highly hands-on position responsible for validating controls, performing security testing, identifying vulnerabilities, and partnering directly with engineering teams to remediate issues.
The ideal candidate is not only capable of defining secure architectures and technical standards, but is also willing and able to work alongside developers to implement solutions, troubleshoot security findings, and drive tangible security outcomes. This role requires a blend of strategic leadership, technical depth, and a consultative mindset.
Key Responsibilities Security Architecture & Secure Design Serve as the primary security advisor for product and engineering teams. Lead architecture reviews for applications, platforms, APIs, cloud solutions, integrations, and emerging technologies. Define security requirements and secure-by-design standards throughout the software development lifecycle. Conduct threat modeling exercises and security risk assessments. Partner with engineering teams to evaluate technology decisions and ensure alignment with enterprise security standards. Establish scalable security patterns that enable secure product delivery. Embedded Product Security Leadership Function as an integrated member of agile product teams. Participate in design reviews, sprint planning, backlog refinement, and release readiness activities. Provide real-time guidance to engineers during development efforts. Influence security decisions through collaboration and technical expertise rather than formal authority. Act as the bridge between Product Engineering and Enterprise Security organizations. Application Security Testing & Remediation Perform hands-on application security reviews and testing activities. Assess findings from SAST, DAST, SCA, API security, cloud security, and container security tools. Validate vulnerabilities and identify root causes. Partner directly with developers to remediate security findings. Assist with implementation of security controls, secure coding practices, and architectural improvements. Drive risk reduction through practical, engineering-focused solutions. Identity, Access Management & Platform Security Define authentication, authorization, and identity management strategies. Review access models, service accounts, machine identities, secrets management, and privileged access controls. Ensure applications align with enterprise IAM standards and security requirements. Partner with application teams to implement appropriate access controls and security safeguards. AI & Emerging Technology Security Support architecture reviews and risk assessments for AI-enabled solutions. Evaluate Responsible AI, privacy, governance, and security requirements. Collaborate with engineering teams to implement appropriate controls for AI and machine learning solutions. Provide guidance on emerging technology risks and secure adoption strategies. Security Governance & Compliance Ensure products align with internal security standards and regulatory requirements. Support security assessments, audits, and compliance initiatives as needed. Translate security and compliance requirements into practical engineering controls. Assist teams in balancing business objectives, development velocity, and security risk.
Requirements
12+ years of experience in Product Security, Security Architecture, Application Security, Security Engineering, Software Engineering, or related disciplines. Deep expertise in application security, cloud security, and modern software development practices. Strong experience conducting architecture reviews, threat modeling, and security risk assessments. Hands-on experience performing application security testing and vulnerability remediation activities. Experience securing cloud-native applications and enterprise platforms in Azure and/or AWS environments. Knowledge of modern authentication and authorization frameworks, API security concepts, and secure development methodologies. Proven ability to influence engineering teams and drive security outcomes without direct authority. Strong communication skills with the ability to engage stakeholders ranging from developers to executive leadership.
The ideal candidate is a highly experienced security professional who combines the strategic mindset of an architect with the practical execution skills of a security engineer. They are comfortable leading architecture discussions with senior stakeholders while also rolling up their sleeves to troubleshoot vulnerabilities, validate findings, and help engineering teams implement solutions. This individual thrives in a collaborative environment, builds trust with development teams, and approaches security as an enabler of product innovation rather than a gatekeeping function. Experience serving as the lead security advisor for digital product or software engineering organizations. Experience supporting enterprise AI, Generative AI, or Responsible AI initiatives. Familiarity with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), OWASP, and modern security architecture principles. Experience securing customer-facing applications, APIs, and cloud-hosted platforms. Security certifications such as CISSP, CSSLP, CCSP, GIAC, or equivalent industry credentials.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Now is the time for industrialized software development
The 12 Best Jobs for Software Engineers
Dev Digest 120 - Apple and peers
Why Upskilling And Reskilling is Important For Developers