> Markdown version of [/jobs/ext/3584091-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/3584091-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** Insight Global - **Location:** Saint Paul, MN, United States - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Adobe InDesign, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Business Software, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Open Web Application Security, Scrum Methodology, Cloud Services, Secure Coding, Security Support Provider Interface, Software Engineering, Systems Integration, Software Vulnerability Management, Software Organization, Cloud Platform System, Spring Cloud, Software Security, Generative AI, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** October 4, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3417341510&tx=HT767THZ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role 12+ years of experience in Product Security, Security Architecture, Application Security, Security Engineering, Software Engineering, or related disciplines. Deep expertise in application security, cloud security, and modern software development practices. Strong experience conducting architecture reviews, threat modeling, and security risk assessments. Hands-on experience performing application security testing and vulnerability remediation activities. Experience securing cloud-native applications and enterprise platforms in Azure and/or AWS environments. Knowledge of modern authentication and authorization frameworks, API security concepts, and secure development methodologies. Proven ability to influence engineering teams and drive security outcomes without direct authority. Strong communication skills with the ability to engage stakeholders ranging from developers to executive leadership. The ideal candidate is a highly experienced security professional who combines the strategic mindset of an architect with the practical execution skills of a security engineer. They are comfortable leading architecture discussions with senior stakeholders while also rolling up their sleeves to troubleshoot vulnerabilities, validate findings, and help engineering teams implement solutions. This individual thrives in a collaborative environment, builds trust with development teams, and approaches security as an enabler of product innovation rather than a gatekeeping function. Experience serving as the lead security advisor for digital product or software engineering organizations. Experience supporting enterprise AI, Generative AI, or Responsible AI initiatives. Familiarity with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), OWASP, and modern security architecture principles. Experience securing customer-facing applications, APIs, and cloud-hosted platforms. Security certifications such as CISSP, CSSLP, CCSP, GIAC, or equivalent industry credentials. ## Description Insight Global is seeking a Principal Product Security Engineer to serve as the senior security leader embedded within a product engineering organization. This individual will partner directly with Product Managers, Architects, Technical Leads, and Engineering teams to design, build, secure, and modernize critical business applications. This role will initially focus heavily on security architecture, solution design, and secure development practices. As security capabilities mature within the product portfolio, the role will evolve into a highly hands-on position responsible for validating controls, performing security testing, identifying vulnerabilities, and partnering directly with engineering teams to remediate issues. The ideal candidate is not only capable of defining secure architectures and technical standards, but is also willing and able to work alongside developers to implement solutions, troubleshoot security findings, and drive tangible security outcomes. This role requires a blend of strategic leadership, technical depth, and a consultative mindset. Key Responsibilities Security Architecture & Secure Design Serve as the primary security advisor for product and engineering teams. Lead architecture reviews for applications, platforms, APIs, cloud solutions, integrations, and emerging technologies. Define security requirements and secure-by-design standards throughout the software development lifecycle. Conduct threat modeling exercises and security risk assessments. Partner with engineering teams to evaluate technology decisions and ensure alignment with enterprise security standards. Establish scalable security patterns that enable secure product delivery. Embedded Product Security Leadership Function as an integrated member of agile product teams. Participate in design reviews, sprint planning, backlog refinement, and release readiness activities. Provide real-time guidance to engineers during development efforts. Influence security decisions through collaboration and technical expertise rather than formal authority. Act as the bridge between Product Engineering and Enterprise Security organizations. Application Security Testing & Remediation Perform hands-on application security reviews and testing activities. Assess findings from SAST, DAST, SCA, API security, cloud security, and container security tools. Validate vulnerabilities and identify root causes. Partner directly with developers to remediate security findings. Assist with implementation of security controls, secure coding practices, and architectural improvements. Drive risk reduction through practical, engineering-focused solutions. Identity, Access Management & Platform Security Define authentication, authorization, and identity management strategies. Review access models, service accounts, machine identities, secrets management, and privileged access controls. Ensure applications align with enterprise IAM standards and security requirements. Partner with application teams to implement appropriate access controls and security safeguards. AI & Emerging Technology Security Support architecture reviews and risk assessments for AI-enabled solutions. Evaluate Responsible AI, privacy, governance, and security requirements. Collaborate with engineering teams to implement appropriate controls for AI and machine learning solutions. Provide guidance on emerging technology risks and secure adoption strategies. Security Governance & Compliance Ensure products align with internal security standards and regulatory requirements. Support security assessments, audits, and compliance initiatives as needed. Translate security and compliance requirements into practical engineering controls. Assist teams in balancing business objectives, development velocity, and security risk. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Serverless Architectures with Spring Cloud Functions and Knative](https://www.wearedevelopers.com/videos/814-serverless-architectures-with-spring-cloud-functions-and-knative) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [The transformative impact of GenAI for software development and its implications for cybersecurity](https://www.wearedevelopers.com/videos/952-the-transformative-impact-of-genai-for-software-development-and-its-implications-for-cybersecurity) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)