CronJobs

security jobs

Principal Security Engineer

Smartsheet · Bellevue, WA, USA

remoteprincipal$205,000–$205,000Posted Aug 25, 2026PythonJavaTypeScriptJavaScriptGoSASTSCAIaC

Apply on the employer site

About this role

## Principal Security Engineer **About the Role** Smartsheet is seeking a Principal Security Engineer to lead high-leverage application security work across a modern SaaS platform. You'll own threat modeling and product security reviews, establish AI security methodology, shape SDLC controls, and elevate team capability across the engineering organization. **Key Responsibilities** • **Lead Threat Modeling & Product Security Reviews** — Own threat modeling as a systematic practice, build models from architecture artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. • **Define AI Security Methodology** — Establish how AI security risk is assessed and mitigated across product, engineering, and third-party integrations. Demonstrate depth in LLM workflows, agentic pipelines, MCP-based integrations, and current attack classes (prompt injection, indirect injection, tool-calling authorization gaps). • **Shape AppSec Technical Direction** — Serve as technical authority for SDLC controls (secure coding guidelines, CI/CD pipeline security, SAST/SCA/secrets/IaC scanning toolchain) and influence standards decisions across teams. • **Elevate Team Capability** — Mentor AppSec team members on threat modeling tradecraft and serve as trusted technical voice with product and engineering leadership. **Required Experience** • 10+ years in application security with sustained technical leadership in product security or AppSec engineering • Hands-on experience securing AI-integrated applications with fluency in OWASP LLM Top 10 • Track record of architecture review and targeted code review for complex SaaS features • Demonstrated mentoring of engineers into threat modeling ownership • Depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines • Fluency in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent) • Expertise communicating risk clearly across engineering ICs through executive leadership • Legally eligible to work in the U.S. on an ongoing basis **Nice to Have** • GitLab CI/CD experience with security policy pipeline configuration • Experience building AI-assisted security tooling or LLM-integrated review workflows • Penetration testing depth including exploit writing • Public-facing security contributions (conference speaking, CVE credits, published research) **Compensation & Benefits** 💰 **US Base Salary:** $205,000 – $257,500 USD (plus market competitive incentive) ✓ Employer-subsidized medical/vision/dental coverage ✓ 401k match (50% of contribution up to 6% of eligible pay) ✓ Monthly productivity stipend ✓ Flexible Time Away + Sick Time ✓ Life insurance, short/long-term disability ✓ 12 paid holidays + up to 24 weeks parental leave ✓ Professional development (Udemy access) ✓ Remote-friendly (US-based, role specific) **Location** Bellevue, WA office or remote from anywhere in the U.S. where Smartsheet is a registered employer. **About Smartsheet** For over 20 years, Smartsheet has empowered teams to manage work seamlessly. Now uniting human teams with AI agents to automate manual tasks, uncover insights at scale, and create space for judgment, creativity, and big thinking. **Equal Opportunity Employer** Smartsheet is committed to fostering an inclusive environment and provides equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity,

Listing freshness

CronJobs last confirmed this listing 1d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord