Principal Security Engineer, Product & Infrastructure
Quick Summary
Join Pigment: The AI Platform Redefining Business Planning Pigment is the AI-powered business planning and performance management platform built for agility and scale.
Reporting to the CISO, you'll own the security roadmap for Pigment's product, infrastructure, and CI/CD environment, and you'll build much of it yourself.
This is a hands-on role: expect to read code, threat model new services, reproduce and triage vulnerabilities, dig through infrastructure configuration and build the automation that closes gaps.
You'll also set direction and bring product and engineering with you, but that influence comes from technical credibility and not process: the engineers you work with will take you seriously because you've been in the same code they have.
The scope is broad: application security, infrastructure security, detection and response, and the assurance work that keeps our certifications standing. You won't be covering it alone. The security team is seven people and growing, with colleagues already owning compliance, governance and security operations, so this role can go deep on product and infrastructure and not be spread too thin across everything. Nobody arrives fluent in all of it: we're looking for real depth in several of these areas and the judgement to grow into the rest.
Responsibilities
~1 min read- →
Mostly production, with the occasional internal IT-adjacent project:
- →
Main sites in Paris, London, Toronto and NYC
- →
MacOS, Windows, Linux workstations
- →
GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
- →
Okta, OAuth, JWT, C#, .NET Core, TypeScript, React, Python, Go
- →
Datadog (SIEM), CloudFlare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog
- →
Google Workspace, Jumpcloud, Vanta, Hibob, Slack
- →
GitHub, CircleCI, ArgoCD
- →
SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001
- →
Owned a security roadmap for a product or platform end to end, rather than delivering items on someone else's
- →
Driven security work through engineering teams you had no authority over
- →
Been the person your organisation escalated to on hard architectural calls
- →
Worked hands-on across a broad technical surface - development, databases, networking, web
- →
You have at least 8 years of experience in security as a Security Engineer, Pentester or Security consultant, with real depth in product and/or infrastructure security. We care more about the scope of what you've owned than the exact number of years.
-
You're hands-on and intend to stay that way (this position does not include people management)
-
You look for the workable answer, not the blocking one
-
You have a good dose of humility, and you help the people around you get better
-
You speak English fluently, French is a strong plus
After a first call with our recruiter, five conversations, around four hours in total, usually over two to three weeks:
-
Ways of working (45 min) — how you operate with people, and what draws you to this role specifically.
-
Technical deep dive (1h30) with a security engineer — including a practical. We'll give you a real problem we've already solved and talk through how you'd approach it.
-
Cross-functional (45 min) with an engineer from product or platform — someone who'd be on the receiving end of your work.
-
Ownership and career (1h) with the CISO and a member of the security team.
-
Final (45 min) with our co-founder and CTO.
Location & Eligibility
Listing Details
- Posted
- March 18, 2026
- First seen
- March 26, 2026
- Last seen
- September 17, 2026
Posting Health
- Days active
- 176
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- September 18, 2026
Signal breakdown

Pigment is a cutting-edge planning platform designed for agility and scale, empowering businesses to make informed decisions and adapt quickly to changes.
View company profilePlease let Pigment know you found this job on Jobera.
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.