Principal Security Engineer

Smartsheet
Bellevue
Workplace: RemoteFull timeUSD 205,000 - 257,500 annuallyFunction: CybersecurityExperience: 10+ yearsSkills: ["Technical leadership","Mentoring","Risk communication","Stakeholder influence","Relationship building"]

Own Smartsheet’s highest-leverage application security work as the principal Application Security individual contributor. Lead upstream threat modeling and product security reviews, define AI security risk methodology for LLM/agent integrations, and set SDLC controls across SAST/SCA/secrets/IaC scanning and CI/CD security strategy. Influence architecture decisions through concrete abuse cases, enforceable security requirements, and mentoring that scales AppSec capability across the engineering organization.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Smartsheet
Smartsheet
2 days ago

Principal Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 18 hours agoStatus: Live

Job Summary

Own Smartsheet’s highest-leverage application security work as the principal Application Security individual contributor. Lead upstream threat modeling and product security reviews, define AI security risk methodology for LLM/agent integrations, and set SDLC controls across SAST/SCA/secrets/IaC scanning and CI/CD security strategy. Influence architecture decisions through concrete abuse cases, enforceable security requirements, and mentoring that scales AppSec capability across the engineering organization.
Location: Bellevue
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead threat modeling and product security reviews by deriving abuse cases and concrete test scenarios from architecture and data-flow artifacts, then driving security requirements into designs before they ship.
  • •Define and evolve AI security methodology for assessing, monitoring, and mitigating AI risk across product, engineering, and third-party AI integrations, including LLM/agentic/LLM-tooling workflows.
  • •Serve as technical authority for AppSec SDLC control surface, shaping secure coding guidelines and CI/CD pipeline security strategy across SAST, SCA, secrets, and IaC scanning.
  • •Execute high-risk feature product security reviews and establish the product security review service model (triage criteria and enforcement posture) with documented findings and remediation timelines.
  • •Mentor AppSec team members and act as the trusted technical voice with product and engineering leadership to frame risk in ways that guide architecture decisions and prioritization.

Pay and Benefits

Salary: USD 205,000 - 257,500 annually
Perks:Health InsuranceDentalVision401kStipendSick TimeLife InsurancePaid HolidaysParental LeaveVolunteer DayLearning BudgetRemote Work

Key Requirements

  • •10+ years in application security with sustained technical leadership in product security or AppSec engineering, including ownership of threat modeling programs or security review services at scale.
  • •Ability to own threat modeling as a systematic practice (e.g., STRIDE, data-flow and architecture diagram-driven) and produce concrete, actionable abuse cases and test scenarios embedded into agile design cycles.
  • •Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in OWASP LLM Top 10 and current AI attack classes.
  • •Experience conducting architecture reviews and targeted manual code review for complex SaaS features, driving remediation requirements through to implementation with credibility at the engineering leadership level.
  • •Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent) and sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to influence toolchain direction and shape secure coding standards.
Experience:10+ years
Skills:Technical leadershipMentoringRisk communicationStakeholder influenceRelationship building
Tech Stack:Threat modelingSTRIDEData-flow diagramsAI securityLLM workflowsAgentic pipelinesMCP-based integrationsPrompt injectionIndirect injectionTool-calling authorization gapsOWASP LLM Top 10SASTSCASecrets scanningIaC scanningCI/CD pipelinesSecure codingPythonJavaTypeScript

Company Brief

Smartsheet
Provides a cloud-based work management platform that enables teams to plan, track, automate, and report on work. Smartsheet combines spreadsheets, collaboration, and workflow automation to help organizations manage projects and processes at scale.
Industry: Enterprise Software
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Bellevue, United States
Founded: 2005
WebsiteLinkedIn