Principal Security Engineer

Jeppesen Foreflight, Inc.
Englewood, CO, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Software as a Service Cyber Security Data Centers Identity and Access Management Network Segmentation Azure Active Directory Zero Trust Network Access Security Information and Event Management Okta Software Security
+1 more
Amazon Virtual Private Cloud (VPC)

Job description

Jeppesen ForeFlight builds mission-critical navigation and aviation data software used by pilots and operators worldwide. As Principal Security Architect, you’ll own the technical security strategy across our enterprise IT and SaaS environments, partnering closely with engineering, infrastructure, product security, and compliance functions to protect pilot, operator, and avaiation data., Security Architecture

  • Define and continuously evolve the enterprise security architecture across identity, endpoint, network, cloud (AWS/Azure), and SaaS. Produce explicit threat models for each tier; translate them into prioritized engineering roadmaps.

Zero Trust & Identity.

  • Design and oversee implementation of zero-trust access, IAM/PAM, MFA, and privileged credential management - with Okta and Entra ID as the primary platforms.

Detection & Response.

Lead technical response to high-severity incidents. Operate and mature EDR/XDR, SIEM, and DLP programs; drive post-incident hardening with measurable outcomes.

Platform & Vendor Review.

  • Evaluate and approve security designs for new platforms, SaaS integrations, infrastructure initiatives, and M&A activity before they reach production.

Compliance Engineering.

  • Partner with GRC on SOC 2, ISO 27001, and aviation-specific control requirements. Translate auditor findings and regulatory obligations into concrete engineering work - not policy binders.

Technical Leadership.

  • Mentor security and infrastructure engineers, raise the security bar in cross-functional architecture reviews, and serve as a credible peer to product security engineering leaders.

Requirements

Do you have experience in Security compliance frameworks implementation?, * 10+ years in security engineering or architecture, including 3+ years as a principal architect or staff-level IC with demonstrated enterprise ownership.

  • Understanding of security as it flows across environments such as data centers, Azure, AWS. Hands-on familiarity with IAM and VPC security.

  • Proven experience with enterprise identity platforms (Okta, Entra ID/Azure AD) and modern detection tooling (EDR/XDR, SIEM, SOAR).

  • Solid working knowledge of NIST CSF, ISO 27001, and SOC 2; familiarity with FAA/EASA, DoD, or CMMC contexts is a meaningful advantage.

  • Track record of turning risk assessments and audit findings into shipped engineering improvements - not just recommendations.

  • Strong communicator across audiences: equally comfortable whiteboarding with engineers and presenting risk posture to executives.

  • Bachelor’s in CS, engineering, or equivalent experience. CISSP, OSCP, or GIAC certifications are valued, not required.

Preferred Qualifications

  • Experience in aviation, aerospace, defense, or other safety-critical software environments where the cost of a security failure extends beyond data.

  • Hands-on experience integrating acquired companies onto a common enterprise security baseline - identity federation, endpoint standardization, and network segmentation.

  • Familiarity with M&A security due diligence and post-close integration planning.

Benefits & conditions

Pulled from the full job description

  • Paid training
  • Paid parental leave
  • Parental leave
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off, At Jeppesen ForeFlight, we know you want a rewarding career. To do that, you need challenging projects, a good work environment, and awesome coworkers. We believe in our employees, and we empower them to make a direct impact on our products and services. We strive to provide our employees with a world-class benefits experience, focused on supporting their physical, financial, and emotional wellbeing. Our benefits package includes but is not limited to the following:
  • Medical, dental, vision insurance with Employer paid health premiums

  • Open PTO Policy

  • 401(k) with up to 10% company matching and immediate vesting

  • 12 Weeks Paid Maternity Leave

  • 4 Weeks Paid Paternity Leave

  • Flight Training Rewards

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:03 min

Managing massive power consumption scaling in AI data centers

Stephan Gillich Stephan Gillich +3 · World Congress 2024

Videos

See all

Related articles

See all