Principal Security Engineer

ForeFlight

$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in security engineering or architecture, including 3+ years as a principal architect or staff-level individual contributor.
  • Deep understanding of security flows across environments like data centers and major cloud platforms (AWS, Azure).
  • Proven expertise with enterprise identity platforms (Okta, Entra ID/Azure AD) and modern detection tools (EDR/XDR, SIEM).
  • Working knowledge of frameworks such as NIST CSF, ISO 27001, SOC 2, with benefits to experience in FAA/EASA or DoD contexts.
  • Successful at translating risk assessments and audit findings into actionable engineering improvements.
  • Strong communication skills for both technical discussions and executive presentations.
  • Bachelor's degree in Computer Science, engineering, or equivalent experience; relevant certifications like CISSP, OSCP, or GIAC are advantageous.

Responsibilities

  • Define and continuously evolve the enterprise security architecture across identity, endpoint, network, cloud, and SaaS; produce threat models and translate them into engineering roadmaps.
  • Design and oversee the implementation of zero-trust access models, IAM/PAM, MFA, and credential management using Okta and Entra ID.
  • Lead technical responses to high-severity security incidents, maturing EDR/XDR and SIEM programs, and driving post-incident hardening with measurable outcomes.
  • Evaluate and approve security designs for new platforms, integrations, and M&A activities before production launch.
  • Collaborate with GRC on compliance initiatives (SOC 2, ISO 27001) and translate findings into actionable engineering tasks.
  • Mentor security and infrastructure engineers, enhancing security practices in architecture reviews and serving as a high-level technical advisor.

Benefits

  • Medical, dental, and vision insurance with employer-paid premiums.
  • Open PTO Policy allowing flexible time off.
  • 401(k) plan with up to 10% company matching and immediate vesting.
  • 12 Weeks Paid Maternity Leave.
  • 4 Weeks Paid Paternity Leave.
  • Unique Flight Training Rewards to support aviation skills.
Full Job Description
As Principal Security Architect, you'll own the technical security strategy across our enterprise IT and SaaS environments, partnering closely with engineering, infrastructure, product security, and compliance functions to protect pilot, operator, and avaiation data.

This is a senior individual contributor role with real authority: you set the architecture, drive adoption, and measure outcomes. You'll report into IT leadership while serving as the senior technical security voice across the enterprise while partnering with your security peers within product engineering. Please note this role is hybrid in Denver, CO or Austin, TX, but remote candidates will be considered on a case by case basis.

Key Responsibilities

Security Architecture

  • Define and continuously evolve the enterprise security architecture across identity, endpoint, network, cloud (AWS/Azure), and SaaS. Produce explicit threat models for each tier; translate them into prioritized engineering roadmaps.


Zero Trust & Identity.

  • Design and oversee implementation of zero-trust access, IAM/PAM, MFA, and privileged credential management - with Okta and Entra ID as the primary platforms.


Detection & Response.

Lead technical response to high-severity incidents. Operate and mature EDR/XDR, SIEM, and DLP programs; drive post-incident hardening with measurable outcomes.

Platform & Vendor Review.

  • Evaluate and approve security designs for new platforms, SaaS integrations, infrastructure initiatives, and M&A activity before they reach production.


Compliance Engineering.

  • Partner with GRC on SOC 2, ISO 27001, and aviation-specific control requirements. Translate auditor findings and regulatory obligations into concrete engineering work - not policy binders.


Technical Leadership.

  • Mentor security and infrastructure engineers, raise the security bar in cross-functional architecture reviews, and serve as a credible peer to product security engineering leaders.


Basic Qualifications

  • 10+ years in security engineering or architecture, including 3+ years as a principal architect or staff-level IC with demonstrated enterprise ownership.

  • Understanding of security as it flows across environments such as data centers, Azure, AWS. Hands-on familiarity with IAM and VPC security.

  • Proven experience with enterprise identity platforms (Okta, Entra ID/Azure AD) and modern detection tooling (EDR/XDR, SIEM, SOAR).

  • Solid working knowledge of NIST CSF, ISO 27001, and SOC 2; familiarity with FAA/EASA, DoD, or CMMC contexts is a meaningful advantage.

  • Track record of turning risk assessments and audit findings into shipped engineering improvements - not just recommendations.

  • Strong communicator across audiences: equally comfortable whiteboarding with engineers and presenting risk posture to executives.

  • Bachelor's in CS, engineering, or equivalent experience. CISSP, OSCP, or GIAC certifications are valued, not required.


Preferred Qualifications

  • Experience in aviation, aerospace, defense, or other safety-critical software environments where the cost of a security failure extends beyond data.

  • Hands-on experience integrating acquired companies onto a common enterprise security baseline - identity federation, endpoint standardization, and network segmentation.

  • Familiarity with M&A security due diligence and post-close integration planning.


Why Join Us

At Jeppesen ForeFlight, we know you want a rewarding career. To do that, you need challenging projects, a good work environment, and awesome coworkers. We believe in our employees, and we empower them to make a direct impact on our products and services. We strive to provide our employees with a world-class benefits experience, focused on supporting their physical, financial, and emotional wellbeing. Our benefits package includes but is not limited to the following:

  • Medical, dental, vision insurance with Employer paid health premiums

  • Open PTO Policy

  • 401(k) with up to 10% company matching and immediate vesting

  • 12 Weeks Paid Maternity Leave

  • 4 Weeks Paid Paternity Leave

  • Flight Training Rewards


Pay is based upon candidate experience and qualifications, as well market and business considerations: Summary Pay Range:

Jeppesen ForeFlight - EOE including Disability/Vets | Pay Transparency | E-Verify Participant | Equal Opportunity Employer

Similar Jobs

More Jobs at ForeFlight

More Information Technology Jobs

Find similar Principal Security Engineer jobs: