Principal of Product Security

Urbint

Austin (TX)

On-site

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid maternity & paternity leave
Paid holidays & sick time
Volunteer time off
Flexible time off
Wellness reimbursement
Mental health benefit
Casual dress

Job summary

Itron is seeking a senior Information Security leader to advance product security across software development, cloud, and engineering environments. You will secure source code, software supply chains, CI/CD pipelines, and architectures while enabling agile development practices.

You will collaborate with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to implement scalable security solutions protecting Itron products and services through the

Qualifications

  • 5+ years of hands-on experience securing software development environments
  • Experience securing source code repositories, CI/CD pipelines, and software supply chains
  • Strong knowledge of OWASP Top 10, API security, and modern authentication/authorization models
  • Ability to influence diverse teams and drive secure practices across large engineering orgs
  • Experience with policy-as-code and release readiness controls

Responsibilities

  • Lead architecture and engineering of security controls across source code, development environments, builds, and release processes
  • Design secure CI/CD patterns, artifact controls, signing services, and deployment workflows
  • Operationalize security requirements, threat modeling outcomes, and vulnerability management with cross-functional teams
  • Promote secure application and API security standards including authentication and data protection
  • Collaborate to reduce attack surfaces via secure architecture and least-privilege models
  • Automate security controls using APIs, IaC, and scripting (Python, PowerShell, Terraform)
  • Establish and enforce auditable evidence for SBOM, release approvals, and governance

Skills

Security architecture
Cloud security
Software supply chain security
CI/CD security
Threat modeling
Leadership
Executive communication

Education

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field

Tools

GitHub
GitLab
Azure DevOps
Jenkins
Terraform

Job description

  • As a member of the Information Security team, you will serve as the senior technical leader responsible for advancing Itron's product security program across software development, cloud, and engineering environments
  • This role focuses on securing source code, software supply chains, CI/CD pipelines, and product architectures while enabling agile, customer-centric development practices
  • You will collaborate closely with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to design and implement scalable security solutions that protect Itron products and services throughout the development lifecycle
  • Lead the architecture and engineering of security controls that protect source code repositories, development environments, build systems, software supply chains, and release processes
  • Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows that ensure software integrity from code commit through product release
  • Partner with security-by-design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls
  • Establish and promote secure application and API security standards, including authentication, authorization, secure coding practices, data protection, logging, and abuse prevention
  • Collaborate with engineering teams to reduce application, API, and cloud attack surfaces through secure architecture, identity management, and least-privilege access models
  • Drive modernization of development and engineering environments to mitigate risks associated with credential compromise, malicious code, dependency attacks, and unauthorized releases
  • Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions
  • Automate security controls and operational processes using APIs, infrastructure-as-code, and scripting technologies such as Python, PowerShell, Terraform, GitHub Actions, Azure DevOps, Jenkins, and GitLab
  • Establish security logging, monitoring, and detection requirements for software development and release environments in partnership with security operations teams
  • Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation that support scalable and innovative product delivery
  • Ensure auditable evidence exists for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements
  • Mentor engineers and influence cross-functional teams to adopt secure, customer-focused, collaborative, and accountable engineering practices across global product environments
Benefits
  • Paid maternity & paternity leave
  • Paid holidays & sick time
  • Volunteer time off
  • Flexible time off
  • Wellness reimbursement
  • Mental health benefit
  • Casual dress

Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholdersExperience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processesStrong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical disciplineProven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practicesExpert-level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environmentsBachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experienceDeep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization modelsExperience implementing path-to-production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria5+ years of hands-on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chainsStrong written, verbal, and stakeholder-management skillsIf you are excited about this role but your past experiences don’t perfectly align with every requirement, we encourage you to apply anyway. In the end, you may be just who we are looking for!Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certificationsHands-on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanningExperience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutionsKnowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controlsFamiliarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10Experience applying application and API security principles across web, cloud, mobile, embedded, and service-based architecturesExperience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy-as-code approaches to automate security controlsUnderstanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulationExperience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal, Product Security
Principal, Product Security

Urbint • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Principal, Product Security
Principal, Product Security

Itron • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Principal, Product Security
Principal, Product Security

Itron, Inc. • North Carolina

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Paid vacation
+1
Principal AI Security
Principal AI Security

Urbint • Austin (TX)

On-site
USD 180,000 - 280,000
Paid maternity & paternity leave
Paid holidays & sick time
Volunteer time off
+4
Principal, Product Security
Principal, Product Security

Itron, Inc. • Liberty Lake (WA)

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Employee stock purchase program
Principal, Product Security
Principal, Product Security

Itron, Inc. • Chicago (IL)

Hybrid
USD 96,000 - 165,000
Competitive benefits
Hybrid work schedule
401k matching
+1
Principal, Product Security
Principal, Product Security

Itron, Inc. • Raleigh (NC)

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Employee stock purchase program
Principal, Product Security
Principal, Product Security

Itron, Inc. • West Union (SC)

On-site
USD 96,000 - 165,000
401k matching
Employee stock purchase program
Hybrid work schedule
+1
Senior Product Security Architect
Senior Product Security Architect

Itron • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000