Principal Product Security Engineer

Navy Federal Credit Union

Vienna (VA)

On-site

USD 130,000 - 190,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Navy Federal Credit Union is seeking a Product Security Engineer - Secure Development Lifecycle to define and mature secure practices across its software delivery environment. This senior individual contributor leads integration of secure development patterns with ETS and engineering teams to embed security into workflows and lifecycle activities.

You will translate security standards into practical engineering requirements, map security activities to delivery processes, and drive adoption of

Qualifications

  • Bachelor's degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.
  • Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.
  • Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.
  • Demonstrated experience developing process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.
  • Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.
  • Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.

Responsibilities

  • Define and mature Secure Software Development Lifecycle practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.
  • Define and support a pre-production product security scorecard to support risk-informed release decisions, ensuring product security posture, open risks, exceptions, and required remediation actions are clearly communicated to business and technology stakeholders.
  • Serve as the senior individual contributor integration lead for embedding Secure Development Practice capabilities into Navy Federal engineering workflows, governance forums, and lifecycle activities.
  • Map product security activities to software delivery processes including intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.
  • Establish repeatable process patterns for integrating threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling into engineering workflows.
  • Identify and reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy process steps that are not aligned to Navy Federal software delivery practices.
  • Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.
  • Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.
  • Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development practices with enterprise delivery processes.
  • Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.
  • Recommend process improvements that strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.
  • Establish adoption and effectiveness measures that demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.
  • Lead cross-functional working sessions, develop executive-ready recommendations, and influence process decisions across security and engineering stakeholders without direct authority.

Skills

Secure SDLC
Threat modeling
Secure coding
APIs security
Vulnerability management
Risk-based decisions
Stakeholder influence

Education

Bachelor's degree in IT or related field

Tools

OWASP ASVS
NIST frameworks

Job description

The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices across Navy Federal's software delivery environment. This role serves as the Secure Development Practice integration lead with our Engineering and Technology Services (ETS) organization software delivery teams, ensuring product security expectations are embedded into standard engineering workflows, governance forums, delivery processes, and lifecycle activities.

The role will help evolve product security from standalone reviews and manual touchpoints into a scalable, risk-informed, AI powered, and developer-aligned operating model. The individual will partner with Secure Development Practice leaders, ETS, Product Engineering, Architecture, DevSecOps, platform teams, Information Security, governance, and risk stakeholders to define practical integration patterns for secure-by-design delivery.

This position will establish repeatable process definitions, ownership models, workflow guidance, control integration points, and adoption measures that improve security outcomes while reducing delivery friction.

Responsibilities

Define and mature Secure Software Development Lifecycle practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.

Define and support a pre-production product security scorecard to support risk-informed release decisions, ensuring product security posture, open risks, exceptions, and required remediation actions are clearly communicated to business and technology stakeholders.

Serve as the senior individual contributor integration lead for embedding Secure Development Practice capabilities into Navy Federal engineering workflows, governance forums, and lifecycle activities.

Map product security activities to software delivery processes including intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.

Establish repeatable process patterns for integrating threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling into engineering workflows.

Identify and reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy process steps that are not aligned to Navy Federal software delivery practices.

Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.

Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.

Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development practices with enterprise delivery processes.

Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.

Recommend process improvements that strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.

Establish adoption and effectiveness measures that demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.

Lead cross-functional working sessions, develop executive-ready recommendations, and influence process decisions across security and engineering stakeholders without direct authority.

Qualifications

Bachelor's degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.

Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.

Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.

Demonstrated experience developing process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.

Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.

Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.

Desired Qualifications

Extensive hands-on experience in application security, secure SDLC, software engineering, DevSecOps, enterprise architecture, technology risk, or software delivery governance.

Strong understanding of software delivery practices including Agile, SAFe, DevOps, DevSecOps, CI/CD, product-oriented delivery, architecture governance, and release management.

Advanced degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, Business Administration, or related field.

Experience with industry frameworks or models such as NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework, or similar security and software assurance practices.

CISSP, CISM, CSSLP, CCSP, GIAC, cloud security, architecture, Agile, SAFe, or related professional certifications.

Additional Information
Hours
  • Monday - Friday, 8:00AM - 4:30PM
Location
  • 141 Security Drive, Winchester, VA 22602
About Us
Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks. Our approach to careers is simple yet powerful: Make our mission your passion.* FORTUNE 100 Best Companies to Work For 2026* Yello and WayUp Top 100 Internship Programs 2025* Computerworld Best Places to Work in IT 2026* Most Loved Workplace - America's Top Most Loved Workplaces 2025* 2025 PEOPLE Companies That Care* Newsweek Most Trustworthy Companies in America 2026* Military Times 2025 Best for Vets Employers* Forbes 2026 America's Best Large Employers* Forbes 2025 America's Best Employers for New Grads* Forbes 2025 America's Best Employers for Tech Workers* 2025 RippleMatch Campus Forward Award Winner for Overall Excellence* Military.com Top Military Spouse Employers 2025* 2026 Handshake Early Talent Award* Newsweek America's Greatest Workplaces for Culture, Belonging and Community 2026From Fortune Magazine. 2026 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune 100 Best Companies to Work For are registered trademarks of Fortune Media IP Limited and are used under license. Fortune Magazine, Fortune Media (USA) Corporation, and its affiliates are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.
Overview

The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices across Navy Federal's software delivery environment. This role serves as the Secure Development Practice integration lead with our Engineering and Technology Services (ETS) organization software delivery teams, ensuring product security expectations are embedded into standard engineering workflows, governance forums, delivery processes, and lifecycle activities.

The role will help evolve product security from standalone reviews and manual touchpoints into a scalable, risk-informed, AI powered, and developer-aligned operating model. The individual will partner with Secure Development Practice leaders, ETS, Product Engineering, Architecture, DevSecOps, platform teams, Information Security, governance, and risk stakeholders to define practical integration patterns for secure-by-design delivery.

This position will establish repeatable process definitions, ownership models, workflow guidance, control integration points, and adoption measures that improve security outcomes while reducing delivery friction.

Responsibilities
  • Define and mature Secure Software Development Lifecycle practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.

  • Define and support a pre-production product security scorecard to support risk-informed release decisions, ensuring product security posture, open risks, exceptions, and required remediation actions are clearly communicated to business and technology stakeholders.

  • Serve as the senior individual contributor integration lead for embedding Secure Development Practice capabilities into Navy Federal engineering workflows, governance forums, and lifecycle activities.

  • Map product security activities to software delivery processes including intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.

  • Establish repeatable process patterns for integrating threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling into engineering workflows.

  • Identify and reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy process steps that are not aligned to Navy Federal software delivery practices.

  • Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.

  • Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.

  • Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development practices with enterprise delivery processes.

  • Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.

  • Recommend process improvements that strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.

  • Establish adoption and effectiveness measures that demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.

  • Lead cross-functional working sessions, develop executive-ready recommendations, and influence process decisions across security and engineering stakeholders without direct authority.

Qualifications
  • Bachelor's degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.

  • Experience defining, improving, or integrating secure development lifecycle practices into enterprise software delivery processes.

  • Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.

  • Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.

  • Demonstrated experience developing process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.

  • Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.

  • Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.

Desired Qualifications
  • Extensive hands-on experience in application security, secure SDLC, software engineering, DevSecOps, enterprise architecture, technology risk, or software delivery governance.

  • Strong understanding of software delivery practices including Agile, SAFe, DevOps, DevSecOps, CI/CD, product-oriented delivery, architecture governance, and release management.

  • Advanced degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, Business Administration, or related field.

  • Experience with industry frameworks or models such as NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework, or similar security and software assurance practices.

  • CISSP, CISM, CSSLP, CCSP, GIAC, cloud security, architecture, Agile, SAFe, or related professional certifications.

Additional Information
Hours
  • Monday - Friday, 8:00AM - 4:30PM
Location
  • 820 Follin Lane, Vienna, VA 22180
  • 5510 Heritage Oaks Drive, Pensacola, FL 32526
  • 141 Security Drive, Winchester, VA 22602
About Us
Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks. Our approach to careers is simple yet powerful: Make our mission your passion.* FORTUNE 100 Best Companies to Work For 2026* Yello and WayUp Top 100 Internship Programs 2025* Computerworld Best Places to Work in IT 2026* Most Loved Workplace - America's Top Most Loved Workplaces 2025* 2025 PEOPLE Companies That Care* Newsweek Most Trustworthy Companies in America 2026* Military Times 2025 Best for Vets Employers* Forbes 2026 America's Best Large Employers* Forbes 2025 America's Best Employers for New Grads* Forbes 2025 America's Best Employers for Tech Workers* 2025 RippleMatch Campus Forward Award Winner for Overall Excellence* Military.com Top Military Spouse Employers 2025* 2026 Handshake Early Talent Award* Newsweek America's Greatest Workplaces for Culture, Belonging and Community 2026From Fortune Magazine. 2026 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune 100 Best Companies to Work For are registered trademarks of Fortune Media IP Limited and are used under license. Fortune Magazine, Fortune Media (USA) Corporation, and its affiliates are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.

Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to age, race, sex, color, religion, national origin, disability, veteran status, pregnancy, sexual orientation, genetic information, gender identity or any other basis protected by applicable law. Accommodations: If you need accommodation or assistance for a qualifying condition to complete the online application (or during any stage of the hiring process), you can contact Navy Federal's Medical Accommodations team at medicalaccommodations@navyfederal.org or by calling 1-888-503-6013. This team cannot provide any information on job postings or application status. Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Product Security Engineer
Principal Product Security Engineer

Navy Federal Credit Union • Winchester (VA)

On-site
USD 120,000 - 170,000
Principal Product Security Engineer
Principal Product Security Engineer

Navy Federal Credit Union • Pensacola (FL)

On-site
USD 120,000 - 165,000
Senior Developer
Senior Developer

Navy Federal Credit Union • Winchester (VA)

On-site
USD 110,000 - 170,000
Senior Developer
Senior Developer

Navy Federal Credit Union • Vienna (VA)

On-site
USD 110,000 - 150,000
Senior Developer
Senior Developer

Navy Federal Credit Union • Pensacola (FL)

On-site
USD 90,000 - 130,000
Business Solutions Developer IV (PEGA)
Business Solutions Developer IV (PEGA)

Navy Federal Credit Union • Coppell (TX)

On-site
USD 120,000 - 160,000
Business Solutions Developer IV (PEGA)
Business Solutions Developer IV (PEGA)

Navy Federal Credit Union • San Diego (CA)

On-site
USD 120,000 - 160,000
Assistant Vice President – Core Banking Services
Assistant Vice President – Core Banking Services

Navy Federal Credit Union • Vienna (VA)

On-site
USD 150,000 - 230,000
Business Solutions Developer IV (PEGA)
Business Solutions Developer IV (PEGA)

Navy Federal Credit Union • Jacksonville (FL)

On-site
USD 110,000 - 140,000
Business Solutions Developer IV (PEGA)
Business Solutions Developer IV (PEGA)

Navy Federal Credit Union • Vienna (VA)

On-site
USD 110,000 - 150,000