Security Engineer

DigitalBridge Group, Inc.

• $235K — $290K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in information security with strong DevSecOps and application security expertise.
  • Proven experience in designing and operating security for SaaS platforms and cloud environments at enterprise scale.
  • Strong background in automated vulnerability management and security testing tools.
  • Demonstrated experience in leading red-team engagements and conducting adversarial testing.
  • Deep knowledge of secure development practices, including threat modeling and secure code review.
  • Experience securing AI-enabled applications, focusing on prompt injection and data-leakage controls.
  • Strong programming skills in Python and/or Go, with familiarity in Terraform and Kubernetes.

Responsibilities

  • Own security architecture for SaaS platforms and multi-cloud environments.
  • Build and operate a modern DevSecOps program with various security scanning tools.
  • Design and run an automated vulnerability management program prioritizing exploitability.
  • Lead application security across the software development lifecycle, including threat modeling and secure design reviews.
  • Direct red-team and adversarial testing, translating findings into architectural fixes.
  • Harden multi-tenant isolation and data protection for a regulated platform.
  • Set security standards for AI-enabled applications, focusing on prompt-injection defense.

Benefits

  • Mentorship opportunities for senior engineers in security and platform.
  • Participation in executive and board-facing risk reporting.
  • On-call participation for security incidents.
  • Collaboration with cross-functional teams on security initiatives.
Full Job Description
We are hiring a Principal Security Engineer / DevSecOps Lead to own the security posture of our SaaS platforms, cloud environments, and AI-enabled applications. This is a senior hands-on leadership role: you will design and drive the security architecture that protects a regulated, multi-tenant investment platform, embed automated security controls into how we build and ship software, and lead red-team-informed offensive testing that measurably reduces real risk. You will partner with SRE, platform, data, and application teams - and directly with the CISO to set the enterprise standard for secure development.

What you'll do
  • Own security architecture for our SaaS platforms, multi-cloud environments (AWS, Azure), and AI-enabled applications, including LLM- and agent-based workloads.
  • Build and operate a modern DevSecOps program: SAST, DAST, IaC scanning, SBOM/supply-chain (Sigstore, SLSA), secrets detection, container and Kubernetes admission control, and policy-as-code (OPA/Cedar).
  • Design and run an automated vulnerability management program that prioritizes by exploitability and business impact, drives closure SLAs, and holds engineering teams accountable through metrics.
  • Lead applicationsecurityacross the SDLC: threat modeling, secure design reviews, code review at critical seams, security champions program, and paved-road guardrails engineers actually adopt.
  • Direct red-team and adversarial testing - internal exercises, purple-teaming, and third-party engagements - and translate findings into durable architectural fixes, not just tickets.
  • Harden multi-tenant isolation, identity, and data protection for a regulated buy-side platform; own the security controls that map to SOC 2, SOX, and applicable regulatory obligations.
  • Set the security-by-design bar for AI-enabledapplications: prompt-injection defense, tool/agent boundary controls, model and data provenance, retention, and abuse monitoring.
  • Partner with IT/AI Platform, SRE, and Data Governance on identity, secrets, network segmentation, logging, and incident response; participate in on-call for security incidents.
  • Mentor senior engineers across security and platform; represent security in executive and board-facing risk reporting when required.


Required experience
  • 10+ years in information security with deep hands-on DevSecOpsand applicationsecurity expertise; senior-leader scope but still writes code and shipped controls.
  • Proven design and operation of security for SaaSplatformsand cloudenvironments(AWS and/or Azure) at enterprise scale, including multi-tenant workloads.
  • Strong background in automated vulnerability management and security testing - SAST/DAST/SCA, IaC/CSPM, container/K8s security, and SBOM/supply-chain tooling.
  • Demonstrated red-team /offensive security experience: leading engagements, conducting or overseeing adversarial testing, and running purple-team exercises against real production systems.
  • Deep secure-development expertise: threat modeling (STRIDE/attack trees), secure code review, cryptography fundamentals, identity/OAuth/OIDC, and API security.
  • Experience securing AI-enabled applications - LLM/agent security, prompt injection, data-leakage controls, and model/tool boundary design.
  • Strong hands-on skills in Python and/or Go; comfortable operating in Terraform, Kubernetes, and modern CI/CD.
  • Track record leading security architecture initiatives for large-scale enterprise and multi-tenant environments, with measurable risk reduction.


Nice to have
  • Prior financial services, buy-side, or otherwise regulated (SOC 2, SOX, GLBA, NYDFS 500) environment experience.
  • Offensive security certifications (OSCP, OSEP, OSCE, CRTO) or published research/CVEs.
  • Experience with red-team infrastructure (C2 frameworks, EDR evasion, cloud-native attack paths) and detection-engineering collaboration.
  • Familiarity with MCP, agent frameworks, and enterprise LLM gateways.


The compensation range for this position is for a full-time employee in New York. The base salary offered will depend on qualifications, market data and internal equity.

Base Salary Range

$235,000-$290,000 USD

Similar Jobs

More Jobs at DigitalBridge Group, Inc.

More Information Technology Jobs

Find similar Security Engineer jobs: