Principal, Product Security

Jobtailor

Illinois

On-site

USD 140,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor seeks a Senior Security Architect to lead architecture and engineering of security controls across software development environments, CI/CD pipelines, and cloud services. You will design secure release workflows and artifact management, partnering with security-by-design teams to operationalize requirements.

You will mentor engineers, drive secure engineering practices across global product environments, and ensure auditable evidence, SBOM generation, and release integrity.

Qualifications

  • 7+ years in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or related technical discipline.
  • Hands-on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains.
  • Expert-level ability to design and operate security controls across cloud, SaaS, enterprise, and product engineering environments.
  • Strong knowledge of software supply chain security, secrets management, artifact integrity, and secure release practices.
  • Familiarity with OWASP Top 10, API security, and modern authentication/authorization models.
  • Experience communicating risk and recommendations to engineering leadership and executives.
  • Certifications such as CISSP, CSSLP, CCSP, or equivalent security credentials.

Responsibilities

  • Lead architecture and engineering of security controls protecting source code repositories, development environments, build systems, software supply chains, and release processes.
  • Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows.
  • Partner with security-by-design andAppSec teams to operationalize requirements, vulnerability management, threat modeling outcomes, and release controls.
  • Establish secure application and API security standards and promote secure practices across engineering teams.
  • Collaborate with engineering to reduce attack surfaces across applications, APIs, and cloud services.
  • Drive modernization of development and engineering environments and integrate security across tools and platforms.
  • Automate security controls and processes using APIs, IaC, and scripting; establish logging and detection requirements.

Education

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field

Tools

GitHub
GitLab
Azure DevOps
Bitbucket
Jenkins
GitHub Actions
Terraform
Open Policy Agent

Job description

• Lead the architecture and engineering of security controls protecting source code repositories, development environments, build systems, software supply chains, and release processes
• Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows
• Partner with security-by-design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls
• Establish and promote secure application and API security standards
• Collaborate with engineering teams to reduce application, API, and cloud attack surfaces
• Drive modernization of development and engineering environments
• Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions
• Automate security controls and operational processes using APIs, infrastructure-as-code, and scripting technologies
• Establish security logging, monitoring, and detection requirements for software development and release environments
• Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation
• Ensure auditable evidence for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements
• Mentor engineers and influence cross-functional teams to adopt secure engineering practices across global product environments

Requirements
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experience
  • 7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical discipline
  • 5+ years of hands‑on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains
  • Expert‑level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environments
  • Strong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices
  • Deep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization models
  • Experience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processes
  • Experience implementing path‑to‑production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria
  • Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholders
  • Proven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practices
  • Strong written, verbal, and stakeholder‑management skills
  • Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certifications
  • Hands‑on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanning
  • Experience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutions
  • Knowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controls
  • Familiarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10
  • Experience applying application and API security principles across web, cloud, mobile, embedded, and service‑based architectures
  • Experience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy‑as‑code approaches to automate security controls
  • Understanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulation
  • Experience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks
  • Travel: Less than 25%
Core Competencies

Demonstrates expertise in designing and implementing security controls for software development environments, CI/CD pipelines, and cloud services, while ensuring compliance with industry standards. Proven ability to mentor teams and drive the adoption of secure engineering practices across diverse environments.

Highest-signal resume keywords
  • Cybersecurity Expertise
  • CI/CD Pipeline Security
  • Application Security Principles
  • Security Control Design
  • Regulatory Compliance Experience
ATS Optimization Keywords
Hard Skills
  • Software Supply Chain Security
  • Secure Coding Practices
  • Infrastructure-as-Code
  • API Security
  • Threat Modeling
  • Vulnerability Management
  • Artifact Integrity
  • Secrets Management
  • Policy Enforcement
  • Deployment Automation
Soft Skills
  • Stakeholder Management
  • Technical Communication
  • Influencing Teams
  • Mentoring Engineers
  • Collaboration
Certifications & Qualifications
  • CISSP
  • CSSLP
  • CCSP
  • GIAC GWEB
  • GWAPT
  • GCSA
  • AWS Security Specialty
  • Microsoft Certified: Cybersecurity Architect Expert
Industry Keywords
  • ISO 27001
  • SOC 2
  • NIST
  • CMMC
  • IEC 62443
  • OWASP Top 10
  • SLSA
  • NIST SSDF
  • OWASP SAMM
  • Secure Release Practices
Tools & Technologies
  • GitHub
  • GitLab
  • Azure DevOps
  • Jenkins
  • Terraform
  • AWS CloudFormation
  • Open Policy Agent
  • Python
  • PowerShell
  • Security Monitoring Solutions
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Senior Manager – Product Cybersecurity
Senior Manager – Product Cybersecurity

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 230,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Technical Lead, Security Embedded Engineering
Technical Lead, Security Embedded Engineering

Jobtailor • Plano (TX)

On-site
USD 140,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Cyber Product Owner
Cyber Product Owner

Jobtailor • Town of Texas (WI)

On-site
USD 120,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Senior DevSecOps Engineer II
Senior DevSecOps Engineer II

Jobtailor • Reston (VA)

On-site
USD 150,000 - 210,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000
DevOps Integration Automation Engineer
DevOps Integration Automation Engineer

Jobtailor • Arlington (VA)

On-site
USD 120,000 - 150,000