1

Principal Security Engineer Jobs in California (NOW HIRING)

The Role As a Principal Security Engineer focused on Software Security Engineering at Block, you will be a technical leader reporting to the CISO responsible for setting the bar for security ...

Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In this role, security is built directly into the system's architecture rather than applied ...

New

Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In this role, security is built directly into the system\'s architecture rather than applied ...

New

We are looking for a Principal Security Engineer to join our team and help develop and enhance the DPU's security features. In this role, you will be responsible for designing and implementing key ...

next page

Showing results 1-20

Principal Security Engineer information

See California salary details

$73K

$145.3K

$209.7K

How much do principal security engineer jobs pay per year?

As of Aug 3, 2026, the average yearly pay for principal security engineer in California is $145,292.00, according to ZipRecruiter salary data. Most workers in this role earn between $116,900.00 and $170,700.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Principal Security Engineers in aligning security initiatives with business objectives?

Principal Security Engineers often encounter the challenge of balancing robust security measures with the need for business agility and growth. They must effectively communicate technical risks to non-technical stakeholders and advocate for security investments without hindering innovation or productivity. This role requires a proactive approach to integrating security early in the development lifecycle, collaborating closely with product, engineering, and executive teams to ensure that security strategies support overall business goals while mitigating threats.

What are Principal Security Engineers?

Principal Security Engineers are senior-level professionals responsible for overseeing the security architecture and strategy of an organization’s information systems. They lead the design, implementation, and maintenance of security protocols, ensuring compliance with industry standards and protecting against cyber threats. These engineers often mentor junior staff, conduct risk assessments, and collaborate with other departments to align security measures with business goals. Their expertise is critical for safeguarding sensitive data and ensuring the overall cybersecurity posture of the organization.

What is the difference between Principal Security Engineer vs Security Architect?

AspectPrincipal Security EngineerSecurity Architect
Required CredentialsCertifications like CISSP, CISM, CEH; Bachelor's or Master's in Cybersecurity or related fieldsSimilar certifications; often holds CISSP, SABSA, or TOGAF; background in security design
Work EnvironmentHands-on security implementation, incident response, vulnerability assessmentsDesigning security frameworks, creating security architecture, strategic planning
Employer & Industry UsageUsed across tech, finance, healthcare; focuses on security operationsCommon in large enterprises, consulting firms; focuses on security design
Search & Comparison IntentUnderstanding roles, responsibilities, career pathsDesigning security solutions, architecture planning

While both roles require strong cybersecurity credentials and involve security strategies, the Principal Security Engineer is more hands-on with security operations and incident response. In contrast, the Security Architect focuses on designing security frameworks and architecture to protect organizational assets.

Can you make $500,000 a year in cyber security?

Principal Security Engineers with extensive experience, advanced certifications, and expertise in areas like cloud security or threat management can potentially earn $500,000 or more annually, especially in high-cost-of-living regions or senior leadership roles. Achieving this level often requires a combination of technical skill, strategic responsibility, and industry reputation.

What engineers make $300,000 a year?

Principal Security Engineers and other senior cybersecurity professionals often earn $300,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and expertise in areas such as cloud security, threat management, or security architecture. Compensation varies by industry, location, and company size, with senior roles in high-demand sectors typically reaching or exceeding this level.

What does a principal security engineer do?

A principal security engineer designs, implements, and manages security systems to protect an organization’s information assets. They lead security initiatives, conduct risk assessments, and develop policies, often utilizing tools like intrusion detection systems and security frameworks. This role typically requires advanced knowledge of cybersecurity principles and relevant certifications such as CISSP or CISM.

What are the key skills and qualifications needed to thrive as a Principal Security Engineer, and why are they important?

To excel as a Principal Security Engineer, you need deep expertise in cybersecurity principles, risk management, and network/system architecture, often backed by a degree in computer science or a related field and extensive industry experience. Familiarity with tools such as SIEM platforms, vulnerability scanners, incident response systems, and certifications like CISSP or OSCP is typically required. Exceptional problem-solving, leadership, and communication skills set individuals apart in this role. These skills ensure robust security strategies, effective team guidance, and the ability to address complex threats in dynamic enterprise environments.

What engineer makes $500,000 a year?

A Principal Security Engineer can earn $500,000 or more annually, especially with extensive experience, advanced certifications, and leadership responsibilities in cybersecurity. High compensation often reflects expertise in areas like threat management, security architecture, and the use of specialized tools, typically in large organizations or high-demand sectors.
What job categories do people searching Principal Security Engineer jobs in California look for? The top searched job categories for Principal Security Engineer jobs in California are:
What cities in California are hiring for Principal Security Engineer jobs? Cities in California with the most Principal Security Engineer job openings:
Infographic showing various Principal Security Engineer job openings in California as of July 2026, with employment types broken down into 93% Full Time, 4% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $145,292 per year, or $69.9 per hour.

Principal Security Engineer

Block

Bodega Bay, CA • On-site

Other

Re-posted 3 days ago


Block rating

7.9

Company rating: 7.9 out of 10

Based on 16 frontline employees who took The Breakroom Quiz

10th of 21 rated payment service providers


Job description

Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.

The Role

As a Principal Security Engineer focused on Software Security Engineering at Block, you will be a technical leader reporting to the CISO responsible for setting the bar for security excellence and driving the creation of innovative, world-class software solutions to complex security problems. You will work across Engineering and Information Security (InfoSec) to champion a "Secure by Design" culture, directly influencing the architecture of Block's core products and infrastructure. Your mandate is to provide deep technical expertise and strategic direction to ensure that security is enabling fast, secure innovation across the business.

You Will
  • Software Security Innovation: Deliver world-class and innovative software solutions to security problems, tackling Block's top risks such as technology fragmentation and security after-the-fact.
  • Technical Strategy & Architecture: Define the multi-year technical strategy for software security at Block, guiding architectural decisions and ensuring alignment with engineering best practices.
  • Cross-Cutting Solution Leadership: Identify and lead the development and implementation of common, high-leverage security solutions and infrastructure across Block's business units (Square, Cash App, TBD, etc.) to combat data sprawl and overpermissioning.
  • Drive engineering excellence, specifically around security, for critical systems like tokenization platforms, ensuring integrity, performance, and scalability.
  • Spearhead the security strategy and engineering excellence for mobile software and platforms across Block's product ecosystem.
  • Champion security reliability engineering (SecRelEng) practices to improve the overall resilience and availability of security services and infrastructure.
  • Execution Excellence: Lead technical planning and implementation for high-priority security initiatives, acting as a technical decision maker/tie-breaker and upholding high technical standards.
  • Consultation & Guidance: Partner with engineering leaders to integrate security practices early into the development lifecycle (Secure SDLC) and provide security architecture review and threat modeling for critical systems.
  • Mentorship & Enablement: Foster technical excellence within InfoSec and mentor engineers on technical execution, system design, and technology choices, driving knowledge sharing and documentation.

You Have

  • Track record of exemplary technical leadership and decision-making at a Principal or equivalent level (L8+ technical capabilities preferred).
  • 10+ years of experience developing and shipping production software and critical services, with a minimum of 5 years focused on establishing and scaling security practices in a large, modern technology environment.
  • Mastery of system design and architecture, with demonstrable experience solving ambiguous, domain-heavy problems by structuring the approach, clarifying scope, and driving clarity among stakeholders.
  • Deep technical understanding of security vulnerabilities, risks, countermeasures, and compensating controls, particularly in high-volume, real-time transaction processing environments.
  • Exceptional collaboration and communication skills, with proven ability to influence executive leadership and direct engineering teams in prioritizing security roadmap items to balance security and business risks.
  • Demonstrable ability to write production-quality code/script for security automation and tooling.

Preferred: 

  • Experience leading and driving significant technical initiatives across multiple team, organizational and product boundaries.
  • Experience in the financial technology, payments, or cryptocurrency/bitcoin domain, reflecting Block's unique security characteristics.
  • Experience improving engineering standards and practices for security, and building systems to achieve sub-linear growth of security resources relative to the business (Design for Leverage, Not Coverage).

We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we're doing to build a workplace that is fair and square? Check out our I+D page.

While there is no specific deadline to apply for this role, U.S. roles are typically open for an average of 55 days before being filled by a successful candidate. Please refer to the date listed at the top of this job page for when this role was first posted.



What Block employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom