1

Principal Security Engineer Jobs in California (NOW HIRING)

The Role As a Principal Security Engineer focused on Software Security Engineering at Block, you will be a technical leader reporting to the CISO responsible for setting the bar for security ...

The Principal Security Engineer, under the direction of the Director of Security Engineering and Operations, is responsible for managing the Firm's information security systems and processes ...

Principal Security Engineer

Santa Clara, CA · On-site

$188K - $304K/yr

We are looking for a Principal Security Engineer to join our team and help develop and enhance the DPU's security features. In this role, you will be responsible for designing and implementing key ...

We are looking for an experienced Security Engineer to help modernize our enterprise directory services and identity infrastructure while improving reliability, scalability, and security across a ...

New

We are looking for a Principal Security Engineer who ships - someone who turns architectural thinking into running systems, operating controls, and measurable outcomes at enterprise scale. This is ...

next page

Showing results 1-20

Principal Security Engineer information

See California salary details

$73K

$145.3K

$209.7K

How much do principal security engineer jobs pay per year?

As of Sep 8, 2026, the average yearly pay for principal security engineer in California is $145,292.00, according to ZipRecruiter salary data. Most workers in this role earn between $116,900.00 and $170,700.00 per year, depending on experience, location, and employer.

What is a principal security engineer?

Principal Security Engineers are senior-level professionals responsible for overseeing the security architecture and strategy of an organization’s information systems. They lead the design, implementation, and maintenance of security protocols, ensuring compliance with industry standards and protecting against cyber threats. These engineers often mentor junior staff, conduct risk assessments, and collaborate with other departments to align security measures with business goals. Their expertise is critical for safeguarding sensitive data and ensuring the overall cybersecurity posture of the organization.

What are the key skills and qualifications needed to thrive as a principal security engineer?

To excel as a Principal Security Engineer, you need deep expertise in cybersecurity principles, risk management, and network/system architecture, often backed by a degree in computer science or a related field and extensive industry experience. Familiarity with tools such as SIEM platforms, vulnerability scanners, incident response systems, and certifications like CISSP or OSCP is typically required. Exceptional problem-solving, leadership, and communication skills set individuals apart in this role. These skills ensure robust security strategies, effective team guidance, and the ability to address complex threats in dynamic enterprise environments.

What are some common challenges faced by principal security engineers in aligning security initiatives with business objectives?

Principal Security Engineers often encounter the challenge of balancing robust security measures with the need for business agility and growth. They must effectively communicate technical risks to non-technical stakeholders and advocate for security investments without hindering innovation or productivity. This role requires a proactive approach to integrating security early in the development lifecycle, collaborating closely with product, engineering, and executive teams to ensure that security strategies support overall business goals while mitigating threats.

What is the difference between Principal Security Engineer vs Security Architect?

AspectPrincipal Security EngineerSecurity Architect
Required CredentialsCertifications like CISSP, CISM, CEH; Bachelor's or Master's in Cybersecurity or related fieldsSimilar certifications; often holds CISSP, SABSA, or TOGAF; background in security design
Work EnvironmentHands-on security implementation, incident response, vulnerability assessmentsDesigning security frameworks, creating security architecture, strategic planning
Employer & Industry UsageUsed across tech, finance, healthcare; focuses on security operationsCommon in large enterprises, consulting firms; focuses on security design
Search & Comparison IntentUnderstanding roles, responsibilities, career pathsDesigning security solutions, architecture planning

While both roles require strong cybersecurity credentials and involve security strategies, the Principal Security Engineer is more hands-on with security operations and incident response. In contrast, the Security Architect focuses on designing security frameworks and architecture to protect organizational assets.

What job categories do people searching Principal Security Engineer jobs in California look for?

The top searched job categories for Principal Security Engineer jobs in California are:

What cities in California are hiring for Principal Security Engineer jobs?

Cities in California with the most Principal Security Engineer job openings:

Infographic showing various Principal Security Engineer job openings in California as of August 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $145,292 per year, or $69.9 per hour.

Principal Security Engineer

Tixy Services LLC

San Jose, CA • On-site

Other

Posted 12 days ago


Job description

Principal Security Engineer

Location: San Jose, CA
Work Arrangement: Fully On-Site – 5 Days a Week
Employment Type: Full-Time

About the Role

We are seeking an experienced Principal Security Engineer to join our security organization and provide technical leadership across enterprise security architecture, security engineering, cloud security, security operations, cyber resilience, and product security.

This is a senior technical leadership position reporting directly to the Chief Security Officer (CSO). The Principal Security Engineer will design and implement security solutions across enterprise infrastructure, cloud environments, networks, applications, products, data, endpoints, and connected devices.

The ideal candidate will combine deep hands-on security engineering expertise with strong architecture, risk management, incident response, communication, and technical leadership capabilities.

Key ResponsibilitiesSecurity Architecture & Engineering
  • Design, implement, and continuously improve enterprise security architectures aligned with business objectives and security requirements.
  • Define security controls and reference architectures across on-premises, cloud, network, endpoint, application, product, and IoT environments.
  • Establish security standards, design principles, technical controls, and engineering best practices.
  • Evaluate emerging security technologies and recommend solutions to strengthen the organization''s security posture.
Security Governance & Risk Management
  • Develop and maintain security policies, standards, procedures, and technical controls.
  • Align security programs with frameworks such as NIST and ISO 27001.
  • Conduct security risk assessments, threat assessments, vulnerability reviews, and architecture assessments.
  • Identify security gaps and develop practical remediation and mitigation strategies.
  • Prioritize security risks based on business impact, threat exposure, and likelihood.
  • Support security assessments for new technologies, applications, products, cloud services, and infrastructure.
Security Operations & Threat Detection
  • Provide technical leadership across SIEM, SOAR, XDR, IDS/IPS, threat intelligence, vulnerability management, and security monitoring capabilities.
  • Develop and improve security detections, monitoring strategies, correlation rules, and automated response capabilities.
  • Support proactive threat hunting and investigation of sophisticated security threats.
  • Partner with SOC and Security Operations teams to improve detection, response, and remediation capabilities.
Incident Response & Cyber Resilience
  • Lead and coordinate technical response activities during security incidents and potential breaches.
  • Develop, test, and continuously improve incident response and cyber-resiliency plans.
  • Analyze threat intelligence and use findings to strengthen defensive controls.
  • Support business continuity and recovery efforts following significant cyber incidents.
  • Conduct post-incident reviews and drive corrective and preventive actions.
Cloud Security
  • Design and implement security controls across AWS and Azure environments.
  • Apply cloud-native security principles across infrastructure, workloads, identities, applications, and data.
  • Establish secure cloud architecture and configuration standards.
  • Monitor and improve cloud security posture through appropriate security technologies and controls.
Zero Trust Security
  • Design and implement Zero Trust security architectures and strategies.
  • Implement strong authentication, authorization, segmentation, and continuous verification.
  • Apply least-privilege and risk-based access principles.
  • Integrate identity, device, network, application, and data security into Zero Trust initiatives.
Network Security
  • Design and maintain secure enterprise and hybrid network architectures.
  • Provide expertise in network protocols, segmentation, encryption, firewalls, IDS/IPS, and secure connectivity.
  • Review network security configurations and identify opportunities for improvement.
  • Support security architecture across enterprise, cloud, hybrid, and connected environments.
Identity & Access Management
  • Define and implement enterprise IAM strategies based on Zero Trust and least-privilege principles.
  • Provide expertise in RBAC, SSO, MFA, identity governance, authentication, authorization, and PAM.
  • Partner with IT and application teams to improve identity lifecycle management and access controls.
Data Security
  • Develop and implement enterprise data security and protection strategies.
  • Establish controls for encryption, secure storage, data integrity, and data access.
  • Provide technical leadership for Data Loss Prevention (DLP) initiatives.
  • Ensure appropriate security controls are incorporated into enterprise data platforms and cloud environments.
Endpoint & IoT Security
  • Define endpoint protection, hardening, and device security strategies.
  • Implement and improve EDR, anti-malware, host-based security, device hardening, and MDM capabilities.
  • Develop security strategies for IoT and connected-device environments.
  • Apply identity, authentication, encryption, network segmentation, and access-control principles to IoT ecosystems.
DevSecOps & Product Security
  • Integrate security throughout the Software Development Lifecycle (SDLC).
  • Implement DevSecOps, automated security testing, continuous security monitoring, and security gates within CI/CD pipelines.
  • Partner with software engineering and product teams to identify and mitigate application and product security risks.
  • Establish secure coding, vulnerability management, threat modeling, and security testing practices.
  • Ensure products and services meet applicable security standards and industry best practices.
Security Technology & Automation

Evaluate, implement, optimize, and integrate security technologies including:

  • SIEM
  • SOAR
  • XDR / EDR
  • Firewalls
  • IDS/IPS
  • Email Security
  • DLP
  • CASB
  • CNAPP
  • Vulnerability Management
  • Threat Intelligence
  • IAM / PAM
  • Automated Security Testing
  • Identify opportunities to automate security processes and improve operational efficiency.
  • Develop security automation and response workflows where appropriate.
Required Qualifications
  • Bachelor''s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related technical field.
  • 8–10+ years of professional cybersecurity/security engineering experience, including at least 3 years in a Senior, Staff, Principal, or Security Architecture role.
  • Strong hands-on experience designing and implementing enterprise security architectures.
  • Strong knowledge of modern security engineering and security operations technologies.
  • Experience with security frameworks including NIST and ISO 27001.
  • Strong knowledge of network security, firewalls, IDS/IPS, encryption, segmentation, and secure network architecture.
  • Strong understanding of IAM, RBAC, SSO, MFA, identity governance, PAM, and least-privilege principles.
  • Hands-on experience securing AWS and/or Azure environments.
  • Strong understanding and practical experience with Zero Trust architecture.
  • Experience with incident response, threat intelligence, vulnerability management, and cyber resilience.
  • Experience implementing DevSecOps and security controls within CI/CD pipelines.
  • Experience with product security and secure software development practices.
  • Understanding of IoT and connected-device security principles.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written, verbal, communication, and technical leadership skills.
Preferred Qualifications
  • Experience working within a SOC, Security Operations, or Threat Detection environment.
  • Experience with enterprise-scale SIEM/SOAR/XDR platforms.
  • Experience with CNAPP, CASB, DLP, EDR, vulnerability management, and automated security testing platforms.
  • Experience developing security automation and response workflows.
  • Experience with threat modeling and security architecture reviews.
  • Experience working in highly regulated or security-sensitive enterprise environments.
  • Experience leading security initiatives across multiple technology and business teams.
  • Relevant certifications such as CISSP, CCSP, CISM, GIAC, OSCP, or cloud security certifications are a plus.
Core Technical Skills

Security Architecture: Enterprise Security Architecture, Security Engineering, Security Governance, Risk Management

Security Operations: SIEM, SOAR, XDR, EDR, Threat Detection, Threat Hunting, Incident Response

Cloud Security: AWS, Azure, Cloud Security Architecture, Cloud Security Posture Management

Zero Trust: Zero Trust Architecture, IAM, RBAC, SSO, MFA, PAM, Least Privilege

Network Security: Firewalls, IDS/IPS, Network Segmentation, Encryption, Secure Connectivity

Data Security: DLP, Encryption, Data Protection, Data Access Controls

Application Security: DevSecOps, Secure SDLC, Threat Modeling, CI/CD Security, Vulnerability Management

Endpoint & IoT: EDR, Endpoint Hardening, MDM, IoT Security, Device Security

Security Frameworks: NIST, ISO 27001

Key Competencies
  • Enterprise Security Architecture
  • Security Engineering
  • Cloud Security
  • Zero Trust
  • Security Operations / SOC
  • Threat Detection & Response
  • Incident Response & Cyber Resilience
  • Network Security
  • IAM / PAM
  • Data Security & DLP
  • Endpoint & IoT Security
  • DevSecOps & Product Security
  • Vulnerability Management
  • Threat Intelligence
  • SIEM / SOAR / XDR
  • Security Risk Management
  • Security Governance
  • Technical Leadership & Mentorship