Principal Software Engineer II - Product Security
Lead Product Security as senior technical authority, defining long-term security architecture and strategy for Snowflake's platform. Requires 15+ years experience in software engineering, security domains like AI/ML, cryptography, and languages including Java, Go, Python.
About the job
Responsibilities
- Serve as the senior technical authority and architectural leader for Product Security, defining the long-term technical vision and security architecture for Snowflake.
- Drive the security strategy across key domains, including AI security, authentication, authorization, data protection, and software supply chain security.
- Design and develop scalable, secure-by-default frameworks, services, and tools to secure Snowflake's infrastructure and protect customer data and accounts.
- Define and implement proactive strategies to mitigate emerging AI-related threats, both by securing Snowflake’s AI offerings and leveraging AI to enhance the company's overall security posture.
- Anticipate emerging security risks and proactively define long-term mitigation strategies aligned with business and product goals.
- Ensure cohesive execution by driving alignment across engineering, infrastructure, AI/ML, and security teams.
- Partner with product and engineering teams to implement security best practices.
- Mentor engineers, influence the engineering culture, and promote a strong security mindset company-wide.
Requirements
- 15+ years of software engineering experience building and securing large-scale distributed systems and cloud-native platforms.
- Bachelor’s or Master’s degree in Computer Science or related field (or equivalent practical experience).
- Demonstrated company-level technical leadership with cross-organizational impact.
- Deep expertise in multiple security domains, including AI/ML system security, applied cryptography, identity and access management, secure distributed system design, cloud and infrastructure security and/or software supply chain security.
- Experience securing AI/ML systems or building security controls for AI-driven platforms.
- Strong systems thinking with experience identifying and mitigating systemic risks at scale.
- Track record of leading complex, multi-year technical initiatives with broad organizational impact.
- Experience in software development working with one or more of the following languages: Java, Go, Python, C, C++.
- Exceptional communication skills and the ability to influence senior technical and executive audiences.
Skills
Java, Go, Python, C, C++, Applied Cryptography, Identity And Access Management, Cloud Security, Ai/Ml Security, Software Supply Chain Security, Distributed Systems, Threat Modeling
Similar jobs
Security Engineering jobsLeads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Leads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.
Leads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.