Principal Security Platform Engineer

Western Alliance Bancorporation

Phoenix (AZ)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salaries
Ownership stake in the company
Medical and dental insurance
Time off
401k matching program
Tuition assistance program
Employee volunteer program
Wellness program

Job summary

Western Alliance Bancorporation is seeking a Principal Security Platform Engineer to own end-to-end onboarding, configuration, and operations of new SaaS security platforms such as SSPM and ASM. You will design baseline policies, integrate with SIEM, SOAR, ServiceNow, and IAM, and collaborate with BISO and 2LOD to meet regulatory and enterprise standards.

The role requires 8+ years in information security, cloud/SaaS expertise, and strong scripting with Python or PowerShell; experience with AWS,

Qualifications

  • Bachelor's degree in computer science, information security, IT, or related field (or equivalent experience).
  • 8+ years of progressive experience in information security engineering with a focus on cloud/SaaS security, posture management, or attack surface management.
  • Strong working knowledge of AWS, Azure, and Entra security models; Microsoft 365, Workday, Salesforce, and ServiceNow security configurations a plus.
  • Proficiency with APIs, Python (or PowerShell) scripting, and integration patterns (REST, webhooks, eventdriven).
  • Experience integrating security tooling with SIEM/SOAR, ServiceNow, and IAM platforms (SailPoint/Entra preferred).
  • Advanced to expert knowledge of applicable regulatory and legal compliance obligations, rules and regulations, industry standards, and practices.
  • Advanced to expert experience in leading cross-functional teams and managing multiple projects simultaneously with ability to walk-through top-level process design.

Responsibilities

  • Provide SME expertise in security engineering and adjacent domains to ensure safe, secure, compliant, and reliable solutions.
  • Own end-to-end onboarding, configuration, integration, and ongoing operations of 2-3 new SaaS platforms supporting the CISO Office.
  • Design baseline policies, detection rules, posture benchmarks, and attacksurface reduction configurations across connected SaaS apps.
  • Build and maintain API/event-driven integrations between SSPM/ASM and SIEM, SOAR, ServiceNow, CMDB, and IAM.
  • Review technical plans to ensure security, scalability, and alignment with business objectives.
  • Monitor platform health, manage upgrades/patches, tune alerting, and own vendor escalations.
  • Track remediation of SaaS misconfigurations and exposed assets in partnership with app owners.
  • Collaborate with Infrastructure, IAM, Endpoint Engineering, SOC, GRC, and BISO to align controls with enterprise standards.

Skills

Cloud security
Posture management
Attack surface
SaaS security
APIs
Python
PowerShell
REST
SIEM/SOAR
ServiceNow
IAM
Leadership
Regulatory knowledge

Education

Bachelor's degree in CS/InfoSec/IT

Tools

SailPoint
Entra
SSPM
ASM
Microsoft 365
Workday
Salesforce
ServiceNow

Job description

Job Title: Principal Security Platform Engineer

Location: Block 23

What you'll do:

As a Principal Engineer I you'll provide SME expertise in your respective domain as well as adjacent domains to ensure solutions are safe, secure, compliant, and reliable. You'll identify development and support needs as well as take on large and complex design responsibilities supporting project tasks. You'll also engage with project and business sponsors refining requirements and objectives of targeted solutions. As Principal Engineer I, you also facilitate dialogue and activities, and work to ensure team collaboration, including teams outside of your domain.

This role is being established as part of the Anthropic/Mythos response to stand up and operate the new SaaS-based defensive tooling the bank is adding to offset Mythos-era risk (e.g., SaaS Security Posture Management, Attack Surface Management, and adjacent cloud/SaaS security platforms). The Security Platform Engineer will own end to end onboarding, configuration, integration, and ongoing operations of 2-3 new SaaS platforms supporting the CISO Office and will flex into adjacent Mythos workstreams (cloud security hygiene, vulnerability remediation, segmentation tooling) as gaps emerge.

  • Build solution designs for SSPM, ASM, and adjacent SaaS security efforts that can be handed off to engineers and analysts for execution while promoting reuse of approved platforms, integration patterns, and enterprise standards where possible
  • Lead vendor onboarding, environment setup, SSO/Entra integration, role design, and production cutover for new SaaS security platforms (SSPM, ASM, and followon tools)
  • Design and implement baseline policies, detection rules, posture benchmarks, and attacksurface reduction configurations across all connected SaaS apps (M365, Workday, ServiceNow, Salesforce, etc.)
  • Build and maintain API/event-driven integrations between SSPM/ASM and SIEM, SOAR, ServiceNow, CMDB, and IAM (SailPoint, Entra) to operationalize findings endtoend
  • Review technical plans developed by engineers and analysts to ensure designs are secure, scalable, operationally supportable, and aligned to the performance, volumetric, and risk objectives of business partners
  • Monitor platform health, manage upgrades/patches, tune alerting, triage incidents, and own vendor escalations to keep tooling stable and effective
  • Track, prioritize, and drive remediation of SaaS misconfigurations, and exposed assets identified in partnership with app owners
  • Flex into adjacent Mythos workstreams (cloud security hygiene, accelerated vulnerability remediation, EOS remediation, segmentation tooling support) as priorities shift across the 90day plan and beyond
  • Build comprehensive dashboards that provide visibility into SaaS platform performance, security posture, remediation progress, control effectiveness, and operational outcomes for security leadership and business partners
  • Maintain runbooks/SOPs, contribute to KB articles, document physical and logical solution layouts with cross-reference to use cases, enforce architecture and operational standards, produce executive-level posture metrics, and support audit/regulatory evidence requests in partnership with the BISO and 2LOD
  • Collaborate with Infrastructure & Operations, IAM, Endpoint Engineering, SOC, GRC, and the BISO team to ensure SaaS security controls align with enterprise standards
What you'll need:
  • Bachelor's degree in computer science, Information security, IT, or related field (or equivalent experience).
  • 8+ years of progressive experience in Information security engineering with a focus on cloud/SaaS security, posture management, or attack surface management.
  • Strong working knowledge of AWS, Azure, and Entra security models; Microsoft 365, Workday, Salesforce, and ServiceNow security configurations a plus.
  • Proficiency with APIs, Python (or PowerShell) scripting, and integration patterns (REST, webhooks, eventdriven).
  • Experience integrating security tooling with SIEM/SOAR, ServiceNow, and IAM platforms (SailPoint/Entra preferred).
  • Advanced to expert knowledge of applicable regulatory and legal compliance obligations, rules and regulations, industry standards, and practices.
  • Advanced to expert experience in leading cross-functional teams and managing multiple projects simultaneously with an established expertise with the ability to walk-through top-level process design. Capable of working with regulatory partners like the CFPB, OCC and FRB through audits and collaboration efforts as situations arise.
  • Familiarity with regulatory and risk frameworks relevant to banking (FFIEC, SOX, GLBA, NIST CSF).
  • Excellent written communication; able to translate technical posture findings into executivelevel risk narratives.
Benefits you'll love:
  • competitive salaries
  • an ownership stake in the company
  • medical and dental insurance
  • time off
  • a great 401k matching program
  • tuition assistance program
  • an employee volunteer program
  • a wellness program

Western Alliance Bank, Member FDIC, is a wholly owned subsidiary of Western Alliance Bancorporation. Serving clients nationwide, Western Alliance Bank includes six legacy bank brands - Alliance Association Bank, Alliance Bank of Arizona, Bank of Nevada, Bridge Bank, First Independent Bank and Torrey Pines Bank - that remain part of the company's heritage, as well as AmeriHome Mortgage, a Western Alliance Bank Company.

Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488. When contacting us, please provide your contact information and state the nature of your accessibility issue. We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.

Western Alliance Bancorporation

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Platform Engineer
Principal Security Platform Engineer

Western Alliance Bank • Phoenix (AZ)

On-site
USD 180,000 - 240,000
Ownership stake
Medical insurance
Dental insurance
+5
Staff Engineer II - Cyber
Staff Engineer II - Cyber

Western Alliance Bancorporation • Phoenix (AZ)

On-site
USD 130,000 - 170,000
Medical insurance
Dental insurance
401k matching
+4
Staff Engineer II - Cyber
Staff Engineer II - Cyber

westernalliancebank • Phoenix (AZ)

On-site
USD 140,000 - 190,000
Medical and dental insurance
401k matching program
Tuition assistance program
+2
Staff Engineer II - Cyber
Staff Engineer II - Cyber

Western Alliance Bank • Phoenix (AZ)

On-site
USD 140,000 - 210,000
Competitive salaries
Equity stake in the company
Medical and dental insurance
+5
Principal Engineer I - Senior DevOps Engineer
Principal Engineer I - Senior DevOps Engineer

Western Alliance Bank • Phoenix (AZ)

On-site
USD 120,000 - 160,000
Competitive salaries
Ownership stake
Medical and dental insurance
+4
Principal Engineer I, Cyber - IT Security Governance
Principal Engineer I, Cyber - IT Security Governance

Western Alliance Bank • United States

On-site
USD 140,000 - 210,000
Health insurance
401k matching
Tuition assistance program
+2
Principal Engineer I - Senior DevOps Engineer
Principal Engineer I - Senior DevOps Engineer

Western Alliance Bancorporation • Phoenix (AZ)

On-site
USD 120,000 - 150,000
Competitive salaries
Ownership stake in the company
401k matching program
+1
Principal Engineer I - Azure Cloud Engineer
Principal Engineer I - Azure Cloud Engineer

Western Alliance Bancorporation • Columbus (OH)

On-site
USD 140,000 - 200,000
Competitive salaries
401k matching program
Tuition assistance
+2
Principal Engineer II - Delivery Lead
Principal Engineer II - Delivery Lead

Relha LLC • Columbus (OH)

On-site
USD 130,000 - 180,000
Competitive salaries
Ownership stake in the company
Medical and dental insurance
+5
Staff Engineer II - M365/Sharepoint Engineer
Staff Engineer II - M365/Sharepoint Engineer

Relha LLC • Phoenix (AZ)

On-site
USD 90,000 - 130,000
Competitive salaries
Ownership stake in the company
Medical and dental insurance
+5