Principal Cybersecurity Engineer
The job description
Tech stack. Enterprise security architecture, threat modeling (STRIDE, PASTA), zero trust design patterns, cloud and identity platforms, risk quantification (FAIR), Python or Go, adversary emulation planning
About the role
You will define the technical direction of security for a global technology company, spanning every product line and business unit with your architecture decisions. Instead of responding to incidents, you eliminate entire classes of vulnerability through design, and your standards become the blueprint every engineering team builds against. You will review the highest-risk initiatives, set multi-year technical strategy, and be the final escalation point for security architecture disputes. This role matters because your choices determine whether security scales gracefully with the business or becomes its permanent bottleneck, and getting architecture right once beats fixing the same flaw a hundred times across a hundred teams.
What you will achieve
- Define company-wide security architecture standards adopted by every engineering organization, cutting systemic design flaws discovered in review by half within two years.
- Lead threat modeling for the three highest-risk product initiatives each year, with all mitigations tracked to verified closure before launch.
- Reduce crown-jewel attack paths by 60 percent across the estate, measured rigorously through continuous adversary emulation exercises.
- Set the multi-year technical roadmap for detection, identity, and data protection, and secure the executive funding required to deliver it.
- Establish an internal security review process that ships secure designs without slowing product launches, holding review cycle time under 10 days consistently.
What you will bring
Must-haves
- 12+ years across security engineering, security architecture, or offensive security roles with steadily increasing scope and impact.
- Track record setting technical direction that was genuinely adopted across multiple teams or entire business units.
- Expert-level threat modeling and secure architecture review skills applied to real, revenue-generating systems.
- Deep understanding of identity, network, application, and data security controls and how they compose into coherent defense in depth.
- Experience quantifying cyber risk in concrete business terms for executive and board-level audiences.
- History of mentoring senior engineers into technical leadership roles with visible, lasting career growth.
- Judgment to know when to insist on a control and when a compensating measure is the pragmatic answer.
Nice-to-haves
- Published research, conference talks, or widely used open-source security tooling to your name.
- CISSP, SABSA, or an equivalent enterprise architecture credential.
- Experience with M&A security diligence or large-scale platform migrations.
- Familiarity with regulated industry requirements shaping architecture choices.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta