Principal Security Engineer
Smartsheet - Bellevue, WA
Hiring: Principal Security Engineer Company: Smartsheet Location: Bellevue, WA Job Posted Time: 2026-09-16 15:30:12 Employment Type: Full-time Target Skills & Keywords : Agile, CI/CD, Embedded Systems, GitLab CI, IaC, Java, JavaScript, LLM, OWASP, Penetration Testing, Python, SAST, SCA, SaaS, TypeScript About the job Experience: •10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering, including direct ownership of threat modeling programs and security review services at scale. Required Skills: •Engage product and engineering leadership directly, drive security requirements rather than advisory recommendations, and build team capability over time. Qualifications: •Demonstrated capacity to own threat modeling as a systematic practice (STRIDE, data-flow and architecture diagram driven), producing concrete, actionable test scenarios and abuse cases, embedded into agile design cycles as a repeatable, lightweight practice. •Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in the OWASP LLM Top 10 and current AI attack classes, plus experience using AI tooling to scale security review coverage. •Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to credibly influence toolchain direction, resolve standards decisions that span teams, and shape secure coding standards without primary operational ownership; cloud security fundamentals sufficient to tie application controls to the infrastructure they run on. •Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent); comfortable reading production codebases to surface issues tooling misses and writing or extending automation others can maintain. •Expertise communicating risk and security requirements (written and verbal) clearly across audiences from engineering ICs through executive leadership; recognized as a trusted technical voice by partner teams. •Demonstrated capacity to build trusted relationships across engineering, product, and security organizations; earns influence through technical credibility and sustained engagement. •Legally eligible to work in the U.S. on an ongoing basis. •GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration. •Penetration testing depth including exploit writing or vulnerability chaining to validate exploitability and prove real-world impact. •Public-facing security contributions: conference speaking, CVE credits, published research, or industry community recognition that reflects the technical authority expected at principal level. Compensation: •$205,000 - $257,500 / year •Employer subsidized medical/vision and dental coverage for full-time employees Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!