We are hiring a Principal Security Engineer / DevSecOps Lead to own the security posture of our SaaS platforms, cloud environments, and AI-enabled applications. This is a senior hands-on leadership role: you will design and drive the security architecture that protects a regulated, multi-tenant investment platform, embed automated security controls into how we build and ship software, and lead red-team-informed offensive testing that measurably reduces real risk. You will partner with SRE, platform, data, and application teams - and directly with the CISO to set the enterprise standard for secure development.
What you'll do- Own security architecture for our SaaS platforms, multi-cloud environments (AWS, Azure), and AI-enabled applications, including LLM- and agent-based workloads.
- Build and operate a modern DevSecOps program: SAST, DAST, IaC scanning, SBOM/supply-chain (Sigstore, SLSA), secrets detection, container and Kubernetes admission control, and policy-as-code (OPA/Cedar).
- Design and run an automated vulnerability management program that prioritizes by exploitability and business impact, drives closure SLAs, and holds engineering teams accountable through metrics.
- Lead applicationsecurityacross the SDLC: threat modeling, secure design reviews, code review at critical seams, security champions program, and paved-road guardrails engineers actually adopt.
- Direct red-team and adversarial testing - internal exercises, purple-teaming, and third-party engagements - and translate findings into durable architectural fixes, not just tickets.
- Harden multi-tenant isolation, identity, and data protection for a regulated buy-side platform; own the security controls that map to SOC 2, SOX, and applicable regulatory obligations.
- Set the security-by-design bar for AI-enabledapplications: prompt-injection defense, tool/agent boundary controls, model and data provenance, retention, and abuse monitoring.
- Partner with IT/AI Platform, SRE, and Data Governance on identity, secrets, network segmentation, logging, and incident response; participate in on-call for security incidents.
- Mentor senior engineers across security and platform; represent security in executive and board-facing risk reporting when required.
Required experience- 10+ years in information security with deep hands-on DevSecOpsand applicationsecurity expertise; senior-leader scope but still writes code and shipped controls.
- Proven design and operation of security for SaaSplatformsand cloudenvironments(AWS and/or Azure) at enterprise scale, including multi-tenant workloads.
- Strong background in automated vulnerability management and security testing - SAST/DAST/SCA, IaC/CSPM, container/K8s security, and SBOM/supply-chain tooling.
- Demonstrated red-team /offensive security experience: leading engagements, conducting or overseeing adversarial testing, and running purple-team exercises against real production systems.
- Deep secure-development expertise: threat modeling (STRIDE/attack trees), secure code review, cryptography fundamentals, identity/OAuth/OIDC, and API security.
- Experience securing AI-enabled applications - LLM/agent security, prompt injection, data-leakage controls, and model/tool boundary design.
- Strong hands-on skills in Python and/or Go; comfortable operating in Terraform, Kubernetes, and modern CI/CD.
- Track record leading security architecture initiatives for large-scale enterprise and multi-tenant environments, with measurable risk reduction.
Nice to have- Prior financial services, buy-side, or otherwise regulated (SOC 2, SOX, GLBA, NYDFS 500) environment experience.
- Offensive security certifications (OSCP, OSEP, OSCE, CRTO) or published research/CVEs.
- Experience with red-team infrastructure (C2 frameworks, EDR evasion, cloud-native attack paths) and detection-engineering collaboration.
- Familiarity with MCP, agent frameworks, and enterprise LLM gateways.
The compensation range for this position is for a full-time employee in New York. The base salary offered will depend on qualifications, market data and internal equity.
Base Salary Range
$235,000-$290,000 USD