Principal Security Engineer

Valmar Holdings LLC.

Village of Williamsville (NY)

Hybrid

USD 140,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Valmar Holdings LLC is seeking a Principal Security Engineer to protect systems, data, and customer trust across Valmar Merchant Services and Totality LMS. You will work with product and platform teams to identify attack surfaces and implement strong controls within a hybrid Buffalo/Williamsville, NY environment.

The role involves hands-on testing of applications, APIs, and cloud infrastructure, leading incident response, and driving SOC 2 and PCI DSS readiness.

Qualifications

  • Hands-on testing of apps and APIs with exploitation validation.

Responsibilities

  • Review designs to map attack vectors and build controls.
  • Perform authorized penetration testing across apps, APIs, and cloud.
  • Test authentication and authorization end to end.
  • Assess third-party integrations and data access.
  • Lead security incident response and remediation.
  • Drive SOC 2 and PCI DSS evidence across audits.
  • Embed security into CI/CD and development workflows.
  • Educate engineers with practical design guidance.

Skills

App & API security
AWS security
CI/CD security
Incident response
SOC 2 / PCI DSS
Security design
Third-party review
Technical leadership
AI-assisted security

Tools

Burp Suite
ZAP
Nmap
Wireshark
Semgrep
Trivy
Prowler
GuardDuty
AI security tools

Job description

Please Read Before Applying - *This role is located in Buffalo/Williamsville, NY in a hybrid capacity therefore applicants should reside in the Western New York area and be able to maintain a hybrid work schedule. Applicants within a reasonable commutable distance will be prioritized*

Valmar Holdings is looking for a Principal Security Engineer to protect the systems, data, and customer trust behind Valmar Merchant Services and Totality LMS. You will work directly alongside our product and platform engineering teams across payments and software, helping us identify how our systems can be attacked before someone else does - and turning what you learn into stronger products, better defenses, and practical controls.

This is a high-ownership individual contributor role for someone who wants to be in the work. You will personally test applications, APIs, cloud infrastructure, authentication and authorization flows, business logic, and third-party integrations. You will investigate real incidents, help defend against active threats, and lead through technical expertise and practical guidance - not through a management title or layers of process.

The right person can move comfortably between offensive security, defensive engineering, and compliance. You can demonstrate an exploitable weakness to an engineer, help design the fix, validate that remediation actually works, and translate the same technical reality into effective SOC 2 and PCI DSS controls and evidence. We want someone who thinks like an attacker, communicates like a partner, and takes ownership through resolution.

What You Will Own
  • Review product and platform designs before implementation. Map attack vectors, trust boundaries, abuse cases, and failure scenarios, then work with engineers to build the right controls in from the start.
  • Perform authorized penetration testing across applications, APIs, and cloud infrastructure using manual investigation, code review, automated tooling, and AI-assisted vulnerability discovery and validation. Go beyond scanner output to determine what is actually exploitable and why it matters.
  • Test authentication and authorization end to end, including login, account recovery, sessions, permissions, tenant isolation, and custom role-based access controls. Establish whether one customer can reach another customer's data or perform actions they should not be able to take.
  • Challenge business workflows across payments and Totality LMS. Look for ways to bypass permissions, manipulate approvals, replay requests, eviate transaction limits, or trigger duplicate processing.
  • Assess partners and integrators before connection and as integrations evolve, including data access, credentials, request validation, security practices, and the risk created by third-party access.
  • Turn findings into fixes. Demonstrate impact safely, create reproducible evidence, prioritize by business risk, work with engineering through remediation, and retest until the issue is actually closed.
  • Lead security incident response and help defend against active attacks. Investigate events, preserve evidence, coordinate containment and recovery, and convert lessons learned into stronger detections, logging, runbooks, and engineering controls.
  • Drive security work for SOC 2 audits and applicable PCI DSS assessments. Establish scope with control owners and auditors, manage evidence and gaps throughout the year, and ensure compliance reflects how the systems actually operate.
  • Build security into the development lifecycle. Help engineering place automated checks and meaningful security gates at the right points in CI/CD and Git workflows without creating security theater or unnecessary friction.
  • Teach continuously. Translate emerging threats, vulnerabilities, attack techniques, and lessons from incidents into practical design guidance, focused training, and changes to how we build.
What Success Looks Like
  • Security is engaged early enough to change designs, not simply document risk after systems are built.
  • Findings are actionable and prioritized by real business impact. Engineers understand the attack path, know what good remediation looks like, and security stays involved through validation.
  • Valmar becomes harder to attack and faster to investigate: better logging, stronger detection, current runbooks, exercised response plans, and fewer preventable repeat issues.
  • SOC 2 and PCI DSS evidence is an output of durable controls and disciplined operations rather than a scramble before an audit.
  • Security tooling, automation, and AI reduce repetitive work without weakening human review, authorization, confidentiality, or accountability.
  • Engineering teams see Security as a technically credible partner that helps them ship safer systems - not a gatekeeper that only identifies problems.
What You Bring
  • Hands-on application and API security testing. You have personally found and validated vulnerabilities, demonstrated impact, and worked with engineers through remediation. You can go well beyond a scanner report.
  • Production cloud security experience, particularly in AWS. You can review permissions, IAM, secrets, exposed services, logging, and WAF controls and trace how a small configuration mistake can become a path to sensitive systems.
  • Experience building security into CI/CD and development workflows, including automated checks and security gates placed where they improve outcomes rather than simply add process.
  • Real incident response experience. You have investigated security events and made containment and recovery decisions with engineering teams under pressure.
  • Hands-on SOC 2 and PCI DSS experience: implementing or evaluating controls, collecting evidence, answering auditor questions, defining scope, and closing gaps.
  • Security design and third-party review experience. You can identify attack paths in proposed systems and evaluate the risks created by partner access and integrations.
  • Principal-level technical leadership without requiring people management. You can read code, write scripts or testing tools, make risk tradeoffs clear, and teach engineers how to prevent the next issue.
  • Practical AI-assisted security and automation experience. You can build effective prompts and reusable agent skills to reduce security toil, use authorized AI security capabilities for white-hat testing, and independently validate findings and proposed fixes.
Bonus points for:

fintech, payments, card processing, ACH or other money-movement systems; AWS security across ECS, Lambda, API Gateway, RDS and IAM; cardholder data environments, tokenization and PCI scope reduction; multi-tenant platforms and custom RBAC; Go, PHP or Terraform; container security; PostgreSQL security; and practical experience evaluating AI-assisted development workflows.

Tools:

You may use Burp Suite or ZAP, Nmap, Wireshark, Semgrep, Trivy, Prowler, Amazon GuardDuty, and AI-assisted security tooling. Equivalent tools are welcome. What matters is knowing which tool fits the problem, validating its output, and acting on the result.

How We Use AI

AI is part of how we accelerate security work, not a substitute for security judgment. You will build and maintain prompts, automations, and reusable agent skills for work such as initial finding triage, audit evidence preparation, recurring security reporting, and authorized testing. You will test their accuracy and keep human review wherever decisions affect access, customer data, credentials, or production systems.

You will also help engineering teams across Valmar Merchant Services and Totality LMS use AI safely: protecting sensitive data and credentials, reviewing generated code, evaluating the access granted to agents, and recognizing when speed creates new attack surface. Human authorization, professional judgment, and an audit trail remain essential.

This Role Is Not a Fit If
  • You want a management role where most of your time is spent directing others rather than personally investigating, testing, and delivering security work.
  • Your security work ends when a scanner produces a report. We need someone who can validate exploitability, demonstrate impact, help drive the fix, and retest remediation.
  • You want to focus exclusively on offensive testing or exclusively on compliance. This role moves between product security, cloud security, incident response, engineering enablement, and audit readiness.
  • You struggle to turn technical findings into clear risk decisions and practical next steps with engineers.
  • You prefer Security to operate as a gatekeeper rather than working alongside engineering to find a responsible path forward.
  • You are uncomfortable making decisions during an active incident, working through ambiguity, or owning an issue until it is resolved.
  • You treat SOC 2 or PCI DSS as a once-a-year evidence exercise rather than an operating discipline supported by real controls.
  • You use AI-generated findings or fixes without independently validating them, or you are resistant to using modern security automation and AI tools thoughtfully.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Principal Security Engineer
Principal Security Engineer

Valley Bank • Morristown (NJ)

On-site
USD 180,000 - 240,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Lead Security Engineer
Lead Security Engineer

LawnStarter • United States

Remote
USD 180,000 - 280,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Security Analyst
Senior Security Analyst

Valon • New York (NY)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 110,000 - 170,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

United States Digital Space LLC • United States

On-site
USD 140,000 - 190,000