Principal Security Engineer
Core
Principal Security Engineer owning the AppSec program and leading AI/LLM security hardening for a SaaS platform serving critical infrastructure operators.
Role type
Principal Security Engineer (AppSec & AI Security)
Builds
SaaS platform for grid resilience (vegetation, asset, storm, wildfire intelligence) with embedded GenAI/LLM features.
Domain
Energy/Utilities + Cloud Security + Generative AI
Deliverable
production ML models | product features | infrastructure
Required skills
AppSec toolchain (SAST/DAST/SCA), AI/LLM security (guardrails, prompt injection controls), AWS cloud security, IaC policy-as-code, SBOM/AIBOM management, compliance audit leadership
Preferred skills
MCP work, LLM eval-as-gate, prompt-layer DLP, ISO 42001/NIST AI RMF familiarity, regulated sector experience
Technologies
AWS, Kubernetes, OPA/Rego, Checkov, Kyverno, Semgrep, CodeQL, Snyk, Veracode, Promptfoo, Garak, DeepEval, Giskard, Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, NVIDIA NeMo Guardrails, CrowdStrike, SentinelOne, Defender
Responsibilities
Own and mature AppSec toolchain across CI/CD; Harden production GenAI deployments on AWS; Operate CSPM/CNAPP tooling and vulnerability management; Support ISO 27001/ISO 42001 certifications; Translate emerging AI regulation into engineering requirements
Seniority
Principal, hands-on IC with strategic leadership