Principal, Product Security

itron

Austin (TX)

On-site

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Itron is seeking a senior security engineering leader to advance product security across software development, cloud, and engineering environments. You will design secure CI/CD patterns, govern software supply chains, and enforce secure release practices while enabling agile, customer‑centric development.

You will mentor engineers, collaborate with Product Development, DevOps, Cloud Engineering, and Cybersecurity teams to implement scalable security solutions protecting Itron products and

Qualifications

  • 7+ years in cybersecurity, product security, or related field.
  • 5+ years securing software development environments, CI/CD, or software supply chains.
  • Expert-level in security controls across cloud, SaaS, and enterprise environments.
  • Strong knowledge of software supply chain security, secrets management, and artifact integrity.
  • Deep understanding of application and API security principles (OWASP Top10).
  • Experience communicating risk to engineering leadership and executives.
  • Proven ability to influence diverse teams toward secure, agile practices.

Responsibilities

  • Lead architecture and engineering of security controls for source code repositories and release processes.
  • Design secure CI/CD patterns, artifact controls, signing services, and deployment workflows.

Skills

Cybersecurity
Product security
DevSecOps
Cloud security
CI/CD pipelines
Threat modeling
OWASP Top10
Access management
Artifact integrity
Evidence collection
Stakeholder communication

Education

Bachelor's degree or equivalent in CS/IS/Cybersecurity

Tools

Python
PowerShell
Terraform
GitHub Actions
Azure DevOps
Jenkins
GitLab

Job description

Itron is innovating new ways for utilities and cities to manage energy and water. We create a more resourceful world to protect essential resources for today and tomorrow. Join us.

Itron, Inc. (NASDAQ: ITRI) is a global technology and services company dedicated to the resourceful use of energy and water. With more than 300 million deployed endpoints worldwide, Itron is a leader in IoT innovation, helping utilities and cities create a more sustainable, connected, and resourceful future.

As a member of the Information Security team, you will serve as the senior technical leader responsible for advancing Itron's product security program across software development, cloud, and engineering environments. This role focuses on securing source code, software supply chains, CI/CD pipelines, and product architectures while enabling agile, customer‑centric development practices. You will collaborate closely with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to design and implement scalable security solutions that protect Itron products and services throughout the development lifecycle.

Duties & Responsibilities
  • Lead the architecture and engineering of security controls that protect source code repositories, development environments, build systems, software supply chains, and release processes.
  • Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows that ensure software integrity from code commit through product release.
  • Partner with security‑by‑design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls.
  • Establish and promote secure application and API security standards, including authentication, authorization, secure coding practices, data protection, logging, and abuse prevention.
  • Collaborate with engineering teams to reduce application, API, and cloud attack surfaces through secure architecture, identity management, and least‑privilege access models.
  • Drive modernization of development and engineering environments to mitigate risks associated with credential compromise, malicious code, dependency attacks, and unauthorized releases.
  • Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions.
  • Automate security controls and operational processes using APIs, infrastructure‑as‑code, and scripting technologies such as Python, PowerShell, Terraform, GitHub Actions, Azure DevOps, Jenkins, and GitLab.
  • Establish security logging, monitoring, and detection requirements for software development and release environments in partnership with security operations teams.
  • Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation that support scalable and innovative product delivery.
  • Ensure auditable evidence exists for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements.
  • Mentor engineers and influence cross‑functional teams to adopt secure, customer‑focused, collaborative, and accountable engineering practices across global product environments.
Required Skills & Experience
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experience.
  • 7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical discipline.
  • 5+ years of hands‑on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains.
  • Expert‑level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environments.
  • Strong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices.
  • Deep understanding of application and API security principles, including OWASP Top10, OWASP API Security Top10, secure coding practices, and modern authentication and authorization models.
  • Experience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processes.
  • Experience implementing path‑to‑production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria.
  • Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholders.
  • Proven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practices.
  • Strong written, verbal, and stakeholder-
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal, Product Security
Principal, Product Security

Itron, Inc. • North Carolina

Hybrid
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Paid vacation
+1
Principal, Product Security
Principal, Product Security

Itron, Inc. • Raleigh (NC)

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Employee stock purchase program
Principal, Product Security
Principal, Product Security

Itron, Inc. • West Union (SC)

On-site
USD 96,000 - 165,000
401k matching
Employee stock purchase program
Hybrid work schedule
+1
Principal, Product Security
Principal, Product Security

Urbint • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Principal, Product Security
Principal, Product Security

Itron • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Principal, Product Security
Principal, Product Security

Itron, Inc. • Liberty Lake (WA)

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Employee stock purchase program
Senior Product Security Architect
Senior Product Security Architect

Itron • United States

Hybrid
USD 96,000 - 165,000
Hybrid work schedule
401k matching
Employee stock purchase program
+1
Principal, AI Security
Principal, AI Security

itron • Austin (TX)

On-site
USD 180,000 - 240,000
Senior Product Security Architect
Senior Product Security Architect

itron • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Product Security Architect — DevSecOps & Cloud
Senior Product Security Architect — DevSecOps & Cloud

Itron, Inc. • Raleigh (NC)

On-site
USD 96,000 - 165,000
401k matching
Hybrid work schedule
Employee stock purchase program