Skip to content
PigmentPigment

Principal Security Engineer, Product & Infrastructure

Own the product and infrastructure security roadmap as a hands-on individual contributor, covering threat modeling, vulnerability management, detection, incident response, assurance, and secure SDLC practices. Requires 8+ years of security experience and deep technical breadth.

About the job

Responsibilities

  • Own and execute the security roadmap for the product, infrastructure, and CI/CD environment.
  • Design product security features and strengthen platform defense in depth.
  • Threat-model new services and make security-sensitive architectural decisions.
  • Conduct code, architecture, and infrastructure-configuration reviews; provide pragmatic risk assessments and solutions.
  • Run assurance activities, including internal reviews, red-team exercises, bug-bounty operations, third-party auditor relationships, and certification control KPIs.
  • Manage vulnerabilities from detection through verified remediation, including reproduction, scoring, triage, mitigation validation, and process improvement.
  • Build detection capabilities, detection rules, signal collection, and incident-response playbooks.
  • Lead production security and fraud investigations from initial signal through root cause.
  • Define secure SDLC direction through guidance, paved paths, and engineering reviews.
  • Secure AI features, including MCP Server and Modeler Agent implementations.
  • Evaluate the appropriate use of AI-assisted security analysis alongside SAST and SCA.
  • Migrate GitHub to managed identities and short-lived OIDC credentials.
  • Design agent identity and delegated-access controls for the MCP Server.
  • Advance least-privilege controls across production and CI/CD.

Requirements

  • At least 8 years of professional security experience as a Security Engineer, Pentester, or Security Consultant.
  • Deep experience in product and/or infrastructure security.
  • Ownership of a security roadmap for a product or platform.
  • Experience driving security initiatives through teams without direct authority.
  • Experience making and escalating complex architectural security decisions.
  • Hands-on experience across development, databases, networking, and web technologies.
  • Fluent English.
  • French is a strong plus.
  • This is an individual-contributor role with no people-management responsibility.

Technical Environment

  • GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
  • Okta, OAuth, JWT, C#, .NET Core, TypeScript, React, Python, Go
  • Datadog, Cloudflare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog
  • GitHub, CircleCI, ArgoCD
  • SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001
  • macOS, Windows, Linux

Compensation and Benefits

  • Annual compensation of €80,000–€120,000.
  • Stock options.
  • Fully paid health insurance for the employee and family.
  • Weekly lunches and flexible lunch vouchers.
  • Egym Wellpass membership across France.
  • Annual learning stipend.
  • Remote-work stipend.
  • Annual company offsite.
  • High-end work equipment.

Skills

GCP, Kubernetes, Terraform, Postgres, Vault, Okta, OAuth, Jwt, C#, .Net Core, TypeScript, React, Python, Go, Datadog

Mozilla

Mozilla

United States
Staff Security Engineer
No salary listedRemote7+ YOESecurity Engineering

Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.

Datadog

Datadog

Paris, France

Senior Platform Security Engineer
No salary listedHybrid5+ YOESecurity Engineering

Secures Datadog’s cloud infrastructure, platform building blocks, and SaaS applications by implementing scalable solutions across a multi-cloud Kubernetes environment. The role requires hands-on software engineering, application and cloud security experience, and expertise with modern security frameworks and technologies.