Principal Security Engineer - AI-Driven Security for Devs

Bonterra

United States

Remote

USD 145,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bonterra is seeking a Principal Security Engineer to embed with engineering teams, driving vulnerability remediation and secure development practices. You will build and operate AI-powered agents and workflows that scale security across the product portfolio, and drive vulnerabilities to closure in collaboration with developers within CI/CD pipelines.

This role supports audits (SOC 2, PCI-DSS, HIPAA) and requires knowledge of OWASP Top 10, NIST, and CVSS scoring, with hands-on software

Qualifications

  • Demonstrated experience building AI agents, LLM-powered workflows, or automated pipelines.
  • Working knowledge of software vulnerability classes, how CVEs are assessed, and what good remediation looks like.
  • Understand how software gets built and where security integrates into the development process.
  • Translate a security finding into language a developer can act on without a security background.

Responsibilities

  • Report directly to the Head of Application Security.
  • Build, extend, and operate AI-powered agents and workflows that automate vulnerability remediation tasks.
  • Drive vulnerabilities to closure by working directly with development teams.
  • Act as a security champion embedded across Bonterra's engineering organizations, building trust and normalizing secure development practices.
  • Triage and prioritize findings from SAST, SCA, IaC scanners, filtering noise and surfacing what needs immediate attention.
  • Integrate security validation into CI/CD pipelines and developer workflows.
  • Support SOC 2, PCI-DSS, HIPAA, and other audits as needed.

Skills

AI agents
LLM workflows
Vulnerability remediation
CI/CD security
SAST/SCA
IaC scanners
Cloud security (AWS)
OWASP Top 10
NIST
CVSS
Software development

Tools

SAST platforms
SCA platforms
AWS security services

Job description

Bonterra is seeking a Principal Security Engineer to embed with engineering teams, driving vulnerability remediation and secure development practices. You will build and operate AI-powered agents and workflows that scale security across the product portfolio, and drive vulnerabilities to closure in collaboration with developers within CI/CD pipelines.

This role supports audits (SOC 2, PCI-DSS, HIPAA) and requires knowledge of OWASP Top 10, NIST, and CVSS scoring, with hands-on software

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer: AI-Driven Remediation
Principal Security Engineer: AI-Driven Remediation

Social Solutions Global • United States

On-site
USD 150,000 - 190,000
Bonuses
Equity
Comprehensive benefits
Security Engineer Leader: AI-Powered Security Workflows
Security Engineer Leader: AI-Powered Security Workflows

Social Solutions Global • United States

On-site
USD 117,000 - 150,000
Comprehensive benefits package
Senior AppSec Engineer: AI-Powered Security Champion
Senior AppSec Engineer: AI-Powered Security Champion

bonterra • United States

On-site
USD 100,000 - 130,000
Principal Security Engineer
Principal Security Engineer

Social Solutions Global • United States

On-site
USD 150,000 - 190,000
Bonuses
Equity
Comprehensive benefits
Lead Security Engineer
Lead Security Engineer

Social Solutions Global • United States

On-site
USD 117,000 - 150,000
Comprehensive benefits package
Senior Application Security Engineer
Senior Application Security Engineer

bonterra • United States

On-site
USD 100,000 - 130,000
Principal Security Engineer: AI & Cloud Security Leader
Principal Security Engineer: AI & Cloud Security Leader

Senovo Capital Management GmbH • Berlin (MD)

On-site
USD 150,000 - 200,000
Principal Security Engineer
Principal Security Engineer

Bonterra • United States

Remote
USD 145,000 - 185,000
Principal Security Engineer: Hybrid Cloud & AI Security
Principal Security Engineer: Hybrid Cloud & AI Security

Topaz Labs • Emeryville (CA)

On-site
USD 130,000 - 160,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
Principal Application Security Engineer: AI & DevSecOps Leader
Principal Application Security Engineer: AI & DevSecOps Leader

Relha LLC • Brooklyn Park (MN)

Hybrid
USD 168,000 - 303,000
Health benefits
401(k) plan
Paid time off