Principal Security Software Engineer
Core
Lead improvements to secure software development lifecycle processes, static analysis tool integration, and vulnerability management to meet EU Cyber Resilience Act requirements.
Role type
Principal Security Software Engineer (Process & Tooling)
Builds
Secure software development workflows, static analysis pipelines, and vulnerability remediation frameworks
Domain
Endpoint security, micro-virtualization, software assurance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
C, C++, Rust, Python, PowerShell, static analysis tool integration, threat modelling, secure coding practices, code review, debugging, unit and integration testing, CI/CD workflows
Preferred skills
secure software development lifecycle practices, vulnerability disclosure, severity assessment, remediation planning, technical initiative leadership, influencing without authority
Technologies
static analysis tools, build systems, CI/CD pipelines
Responsibilities
Lead definition and delivery of secure software development lifecycle improvements aligned with CRA expectations; Introduce and tune static analysis tools within development and build workflows; Establish approaches for triaging findings, managing false positives, and tracking remediation; Promote security-by-design through threat modelling and architectural guidance; Improve identification and remediation of vulnerabilities throughout the SDLC; Provide technical leadership on complex security problems and mentor engineers
Seniority
Principal, hands-on IC with strategic influence