1

Principal Security Engineer Jobs (NOW HIRING)

Principal Security Engineer

Natick, MA · On-site

$160K - $209K/yr

Learn More: We're looking for a hands-on, highly collaborative Principal Security Engineer to secure our software delivery pipeline. You'll take ownership of protecting our CI/CD processes ...

Principal Security Engineer

Boston, MA · On-site

$135K - $194K/yr

Role Summary The Principal Security Engineer provides technical leadership across the security domain, defining architecture, standards, and strategy for securing enterprise and managed services ...

The Principal Security Engineer, under the direction of the Director of Security Engineering and Operations, is responsible for managing the Firm's information security systems and processes ...

We are looking for a Principal Security Engineer to join our team in one of today's most exciting technologies. This role will report to our Chief Security Officer and based in San Jose, CA. This is ...

Description The Principal Security Engineer role will support the cyber team that handles the mergers and acquisitions within in Citizens bank, working closely with technology and the business on ...

The Principal Security Engineer role is for a hands-on systems architect who can turn ambiguous risk into enforceable controls, drive adoption across engineering organizations, and make security ...

Principal Security Engineer

San Jose, CA · On-site

$178K - $257K/yr

We are looking for a Principal Security Engineer to join our team in one of today's most exciting technologies. This role will report to our Chief Security Officer and based in San Jose, CA. This is ...

We are looking for a Principal Security Engineer to join our team in one of today's most exciting technologies. This role will report to our Chief Security Officer and based in San Jose, CA. This is ...

As Marqeta's Principal Security Engineer you will serve as the technical lead across our security engineering function. This role combines three critical responsibilities: leading product security ...

Principal Security Engineer

Johnston, RI · On-site

$140K - $180K/yr

The Principal Security Engineer role will support the cyber team that handles the mergers and acquisitions within in Citizens bank, working closely with technology and the business on requirements ...

Description The Principal Security Engineer role will support the cyber team that handles the mergers and acquisitions within in Citizens bank, working closely with technology and the business on ...

Principal Security Engineer

Johnston, RI · On-site

$140K - $180K/yr

The Principal Security Engineer role will support the cyber team that handles the mergers and acquisitions within in Citizens bank, working closely with technology and the business on requirements ...

Our Security Engineers write code to fix vulnerabilities and improve our overall security posture, ensuring the isolation integrity of our GPU powered cloud platform. * Integrated Security: We ...

next page

Showing results 1-20

Principal Security Engineer information

See salary details

$74K

$147.2K

$212.5K

How much do principal security engineer jobs pay per year?

As of Jun 21, 2026, the average yearly pay for principal security engineer in the United States is $147,220.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,500.00 and $173,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Principal Security Engineers in aligning security initiatives with business objectives?

Principal Security Engineers often encounter the challenge of balancing robust security measures with the need for business agility and growth. They must effectively communicate technical risks to non-technical stakeholders and advocate for security investments without hindering innovation or productivity. This role requires a proactive approach to integrating security early in the development lifecycle, collaborating closely with product, engineering, and executive teams to ensure that security strategies support overall business goals while mitigating threats.

What are Principal Security Engineers?

Principal Security Engineers are senior-level professionals responsible for overseeing the security architecture and strategy of an organization’s information systems. They lead the design, implementation, and maintenance of security protocols, ensuring compliance with industry standards and protecting against cyber threats. These engineers often mentor junior staff, conduct risk assessments, and collaborate with other departments to align security measures with business goals. Their expertise is critical for safeguarding sensitive data and ensuring the overall cybersecurity posture of the organization.

What is the difference between Principal Security Engineer vs Security Architect?

AspectPrincipal Security EngineerSecurity Architect
Required CredentialsCertifications like CISSP, CISM, CEH; Bachelor's or Master's in Cybersecurity or related fieldsSimilar certifications; often holds CISSP, SABSA, or TOGAF; background in security design
Work EnvironmentHands-on security implementation, incident response, vulnerability assessmentsDesigning security frameworks, creating security architecture, strategic planning
Employer & Industry UsageUsed across tech, finance, healthcare; focuses on security operationsCommon in large enterprises, consulting firms; focuses on security design
Search & Comparison IntentUnderstanding roles, responsibilities, career pathsDesigning security solutions, architecture planning

While both roles require strong cybersecurity credentials and involve security strategies, the Principal Security Engineer is more hands-on with security operations and incident response. In contrast, the Security Architect focuses on designing security frameworks and architecture to protect organizational assets.

Can you make $500,000 a year in cyber security?

Principal Security Engineers with extensive experience, advanced certifications, and leadership roles can potentially earn $500,000 or more annually, especially in high-cost-of-living areas or within large organizations. Achieving this level often requires expertise in areas like threat management, security architecture, and strong technical skills with tools such as SIEMs and cloud security platforms.

What engineers make $300,000 a year?

Principal Security Engineers and other senior cybersecurity professionals often earn $300,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and expertise in areas such as cloud security, threat management, or security architecture. Compensation varies by industry, location, and company size, with senior roles in high-demand sectors typically reaching or exceeding this salary level.

What does a principal security engineer do?

A principal security engineer designs, implements, and oversees security systems and policies to protect an organization’s information assets. They analyze security risks, lead incident response efforts, and often hold certifications like CISSP or CISM. This role requires strong technical skills, leadership, and the ability to communicate security strategies to stakeholders.

What are the key skills and qualifications needed to thrive as a Principal Security Engineer, and why are they important?

To excel as a Principal Security Engineer, you need deep expertise in cybersecurity principles, risk management, and network/system architecture, often backed by a degree in computer science or a related field and extensive industry experience. Familiarity with tools such as SIEM platforms, vulnerability scanners, incident response systems, and certifications like CISSP or OSCP is typically required. Exceptional problem-solving, leadership, and communication skills set individuals apart in this role. These skills ensure robust security strategies, effective team guidance, and the ability to address complex threats in dynamic enterprise environments.

What engineers make $500,000?

Principal Security Engineers and other senior cybersecurity professionals with extensive experience, advanced certifications, and specialized skills can earn $500,000 or more annually, especially in high-demand industries or senior leadership roles. Compensation often includes base salary, bonuses, and stock options, reflecting their expertise in areas like threat management, security architecture, and compliance.
More about Principal Security Engineer jobs
What cities are hiring for Principal Security Engineer jobs? Cities with the most Principal Security Engineer job openings:
What states have the most Principal Security Engineer jobs? States with the most job openings for Principal Security Engineer jobs include:
Infographic showing various Principal Security Engineer job openings in the United States as of June 2026, with employment types broken down into 90% Full Time, 5% Part Time, and 5% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $147,220 per year, or $70.8 per hour.
Principal Security Engineer

Principal Security Engineer

The Mathworks

Natick, MA • On-site

$160K - $209K/yr

Full-time

Posted 16 days ago


Job description

Job Summary
MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.
We're looking for a hands-on, highly collaborative Principal Security Engineer to secure our software delivery pipeline. You'll take ownership of protecting our CI/CD processes, Artifactory, and Internal Developer Platform against supply chain risks and malware attacks. This is a technical, impact-driven role where your expertise in threat modeling, security architecture, and systems design will shape our approach to secure software delivery at scale.
MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.
Responsibilities
  • Design, implement, and continuously improve security controls across our CI/CD pipeline, Artifactory, and developer platforms
  • Collaborate with various teams and key stakeholders within the organization to embed security best practices in software delivery workflows
  • Lead threat modeling and risk assessments for our build and release pipelines
  • Build and deploy custom security solutions and integrations as needed
  • Monitor, detect, and respond to threats targeting our development infrastructure
  • Drive innovation in automation, security architecture, and systems design
  • Foster a strong security culture through knowledge sharing and mentorship
  • Stay ahead of the latest threats, attacker methodologies, and evolving security trends to continuously refine our efforts

Minimum Qualifications
  • A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

Additional Qualifications
  • Proficiency in programming languages such as Python, Rust, or Go
  • Experience with security threat modeling, penetration testing, and security reviews.
  • Deep understanding of the software development lifecycle (SDLC), particularly in large, complex enterprise environments, and a passion for improving the developer experience
  • Deep understanding of modern attack vectors targeting software supply-chain through malicious code, third-party libraries, and CI/CD systems
  • Advanced knowledge of developer tools, internal build and dependency systems
  • Experience with trusted software supply chain concepts, including security standards and best practices (e.g., SLSA), dependency/package management, vulnerability scanning, signing, provenance, and tools such as TeamCity, Jenkins, GitHub, GitLab, Artifactory, and Kubernetes
  • Experience with Cloud Native Computing Foundation (CNCF) projects related to CI/CD, security, and developer workflow
  • Ability to collaborate with large, distributed engineering teams to contextualize and prioritize supply chain threats