Principal Security Engineer

Chewy, Inc.
Bellevue, WA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$170,500.0 - $271,500.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Security Cyber Security Computer Networks Data as a Services Distributed Data Store Distributed Systems Amazon DynamoDB Identity and Access Management Information Systems Security Architecture Professional Key Management PostgreSQL
+6 more
Network Segmentation Systems Development Life Cycle Kubernetes Information Technology Production Code Terraform

Job description

As a Principal Cybersecurity Engineer, you will operate at the intersection of architecture, engineering, and execution, owning critical security domains and influencing security outcomes across dozens of teams. You will work deeply within AWS-based platforms, Kubernetes (EKS), and data services, setting technical direction while remaining directly engaged in solving complex security engineering problems. This role requires sustained hands-on technical contribution, deep system-level thinking, and the ability to lead through influence in a fast-moving, high-scale e-commerce environment.

What You’ll Do:

  • Design, review, and contribute to security architectures and implementations across cloud, application, data, and platform layers
  • Own and evolve core security engineering capabilities (e.g., cloud security patterns, workload identity, network segmentation, secrets management, data protection) from design through production
  • Develop and maintain threat models, security requirements, and architectural guardrails for distributed systems running on public clouds.
  • Partner directly with engineering teams to embed security into system design and code, not as an after-the-fact review function
  • Define and implement secure-by-default patterns that teams can adopt without centralized friction
  • Lead technical decision-making for high-risk, high-impact security tradeoffs, including incident learnings and architectural remediation
  • Build and refine security engineering standards, reference architectures, and reusable components, and actively ensure they are implemented correctly
  • Diagnose and resolve the most complex security failures and design flaws in production systems
  • Establish measurable security outcomes (not just controls), and track progress against them
  • Mentor engineers by reviewing designs, code, and implementations, raising the bar through direct technical engagement
  • Influence hiring by setting clear expectations for senior and principal-level engineering excellence, and participating directly in interview loops

Requirements

Do you have experience in System design for system development?, * Bachelor’s degree or equivalent practical experience in computer science or engineering

  • 15+ years of engineering experience, with substantial hands-on work in cybersecurity engineering and architecture
  • Demonstrated experience building and operating security controls in production, not just designing or recommending them
  • Deep, practical expertise in securing AWS environments, including IAM, networking, compute, and managed data services
  • Strong hands-on experience with Kubernetes/EKS security, including pod/workload identity, network policies, and runtime controls
  • Proven experience securing distributed data systems, including DynamoDB and PostgreSQL-based platforms
  • Ability to read, review, and meaningfully influence production code and infrastructure-as-code
  • Track record of owning security outcomes across multiple teams through influence rather than direct authority
  • Experience turning ambiguous risk and business requirements into concrete technical designs and implementations
  • Strong written and verbal communication skills, with the ability to explain complex technical decisions to senior engineers and leadership
  • Comfortable operating in environments with incomplete information, evolving requirements, and real operational risk

Bonus:

  • Prior experience securing high-scale e-commerce or consumer-facing platforms
  • Experience building self-service security platforms or guardrails used by multiple engineering team.
  • Strong infrastructure-as-code background (e.g., Terraform) with security-first design
  • Experience integrating security into CI/CD pipelines and developer workflows
  • History of leading or significantly contributing to post-incident architectural improvements

Benefits & conditions

2.82.8 out of 5 stars Bellevue, WA 98004 $170,500 - $271,500 a year - Full-time, Pulled from the full job description

  • Pet insurance
  • Parental leave
  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Family leave, The base salary range for this role is $170,500 - $271,500.00.
  • The specific salary offered to a candidate may be influenced by a variety of factors including but not limited to the candidate’s relevant experience, education, and work location. In addition, this position is eligible for 401k and a new hire and annual equity grant. C08+ positions may also be eligible for annual bonus.

We offer different types of insurance and benefits, such as medical/Rx, vision, dental, life, disability, hospital indemnity, critical illness, and accident. We offer parental leave, family services benefits, backup dependent care, flexible spending accounts, telemedicine, pet adoption reimbursement, employee assistance program, and many discounts including 10% off pet insurance and 20% off at Chewy.com.

Exempt salary team members have unlimited PTO, subject to manager approval. Team members will receive six paid holidays per year. Team members may be eligible for paid sick and family leave in compliance with applicable state and local regulations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

5:37 min

Extensibility and programmability features of the PostgreSQL database

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

Videos

See all

Related articles

See all