Principal Product Security Engineer
Quick Summary
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more.
We’re looking for a Principal Product Security Engineer to lead and scale Obsidian’s product security program across our SaaS product, cloud infrastructure, CI/CD pipelines, and related services. This is a senior, highly technical role for someone who can combine deep security engineering expertise with strong ownership, judgment, and cross-functional leadership.
You’ll partner closely with Engineering, Product, GRC, IT, DevOps, SRE, and Platform teams to embed security throughout the SDLC, strengthen cloud and infrastructure security, mature threat modeling and secure design practices, and drive automation across detection, response, vulnerability management, and security testing.
This role reports to the Head of Security and is ideal for a seasoned product security leader who thrives in a fast-moving, high-growth cybersecurity startup and wants to make a meaningful impact on the security of our product, customers, and organization.
Responsibilities
~1 min read- →Lead and evolve Obsidian’s product security program, including standards, runbooks, technical documentation, and operational practices.
- →Provide technical leadership, mentorship, and secure design guidance to security and engineering teams.
- →Drive security architecture reviews, threat modeling, secure coding practices, and scalable security design reviews.
- →Integrate security deeply into the SDLC through code review, SAST/DAST, fuzzing, SBOMs, dependency scanning, and CI/CD security controls.
- →Partner with infrastructure teams to harden AWS, GCP, Kubernetes, GitLab, Terraform, data pipelines, secrets management, and service-to-service access controls.
- →Improve security automation, monitoring, metrics, dashboards, and reporting.
- →Lead technical response for product security incidents, vulnerability remediation, penetration testing, and red team findings.
- →Support customer and prospect security reviews as a senior technical security expert.
- 10+ years of product security and/or engineering experience in cloud-native environments, ideally in cybersecurity, financial services, or another high-security industry.
- Strong software engineering skills, especially in Python.
- Hands-on expertise with Terraform, Kubernetes, AWS, GCP, GitLab, security automation, and security metrics.
- Deep knowledge across application security, cloud security, detection and response, vulnerability management, and secure SDLC practices.
- Experience partnering with engineering, product, IT, GRC, and external stakeholders during security reviews and incidents.
- Strong communication skills with the ability to influence, educate, and raise security maturity across the company.
- A mission-driven, ownership-oriented mindset and the ability to thrive in a dynamic startup environment.
What We Offer
~1 min readWhat We Offer
~1 min readPlease note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.
At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization. If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com
Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.
Location & Eligibility
Listing Details
- Posted
- April 28, 2026
- First seen
- April 28, 2026
- Last seen
- May 3, 2026
Posting Health
- Days active
- 4
- Repost count
- 0
- Trust Level
- 71%
- Scored at
- May 3, 2026
Signal breakdown
Please let Obsidiansecurity know you found this job on Jobera.
3 other jobs at Obsidiansecurity
View all →Explore open roles at Obsidiansecurity.
Similar Product Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.