Talent.com
Principal Security Engineer
Principal Security EngineerSpire • Boulder, Colorado, United States
No longer accepting applications
Principal Security Engineer

Principal Security Engineer

Spire • Boulder, Colorado, United States
30+ days ago
Job type
  • Full-time
Job description

About the Role


You'll focus on hands-on design and implementation of security related software, to shift security left in our development processes. This includes embedding automated controls such as SBOMs and vulnerability scanning into CI/CD pipelines; maintaining and updating our internal shared libraries and infrastructure for authentication, authorization, and logging; and assisting with monitoring tools for operational services. Where needed, you'll help align systems with NIST 800-171/CMMC requirements, collaborating closely with the Principal Security Engineer, AWS infra team, dev tooling team, chief software engineer, and cybersecurity/GRC group.


You'll work in a lean, impact-focused environment—prioritizing deliverables like secure code and architecture with bureaucracy handled by the TPM/GRC org as much as possible. Occasional engagement in security discussions with government entities may be involved, under the principal security engineer's guidance.


~80-90% hands-on work, with the remainder on collaboration and learning.


Key Responsibilities:



  • Implement Security Controls in SDLC: Assist in integrating security automation into pipelines (e.g., GitHub Actions/ArgoCD for SAST/DAST/SCA, SBOM generation, and vulnerability scanning).

  • Support Shared Libraries and Infra: Contribute to evolving standard libraries/infra for authn/authz, logging, and other runtime security features, including testing and updates.

  • Contribute to CMMC Compliance: Hands-on support for implementing controls (e.g., encryption, secure configurations, monitoring) to meet/exceed CMMC Level 2 requirements in AC, IA, SC, and SI families, building on our ISO 27001 foundation.

  • Assist with Reviews and Models: Participate in security architecture reviews, code audits, and threat modeling; help identify and remediate issues like API vulnerabilities or supply chain risks.

  • Team Collaboration: Engage in code reviews, pair programming sessions, and tooling development to advance secure practices; provide peer support within the security engineering team.


Required Qualifications:



  • Experience: 5+ years in software or security engineering, with at least 3+ years in security-focused roles. Experience with secure cloud systems (AWS), CI/CD security, and compliance efforts (e.g., NIST, CMMC, or FedRAMP).

  • Technical Expertise: Proficiency in container security (Docker/Kubernetes), security tools (e.g., Trivy, Snyk, Falco, OPA), and programming languages for tooling (Python, Rust). Understanding of modern attacks and defenses.

  • Security Acumen: Knowledge of common threats (e.g., injection, lateral movement), controls (NIST 800-53 mappings), DevSecOps practices, SBOMs, zero-trust principles, and SIEM-integrated logging.

  • Interpersonal Skills: Ability to collaborate constructively with internal teams and contribute to external security discussions as needed.


Preferred Skills:



  • Familiarity with AWS security services (e.g., GuardDuty, Security Hub, Config) and IaC tools (Terraform).

  • Experience with embedded or satellite security (e.g., secure boot, over-the-air updates).

  • Contributions to open-source security projects.

  • Relevant certifications (e.g., CSSLP, OSCP, GIAC) demonstrating practical expertise.

  • Proven ability to work in small, agile teams and learn from senior mentors.


Bonus



  • Other: Experience in regulated industries (defense/aerospace); clearance for sensitive data handling.



Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office.


Access to US export-controlled software and/or technology may be for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. #LI-DC1

Create a job alert for this search

Principal Security Engineer • Boulder, Colorado, United States

Similar jobs

Marine Interdiction Agent

U.S. Customs and Border ProtectionLyons, CO, US
Full-time

NEW RECRUITMENT AND RETENTION INCENTIVES!.Air and Marine Operations (AMO), a component of U.Customs and Border Protection (CBP) offers those with Merchant Mariner Credentials the exceptional opport...Show more

 • Promoted

Senior Security Data Center Network Architect

SciTec, Inc.Boulder, CO, United States
Full-time

A dynamic small business seeks a Network Architect in Boulder, CO.The ideal candidate will have extensive experience in network engineering and security, designing secure data center networks, and ...Show more

 • Promoted

Staff Firmware Engineer

Particle Measuring SystemsNiwot, CO, United States
Full-time

Do you want to be part of a business that genuinely values.We partner with some of the biggest manufacturing companies in the world and our technical innovations are used to enhance well-known bran...Show more

 • Promoted

OT Security Engineer

Fervo EnergyGolden, CO, United States
Full-time

The OT Security Engineer is responsible for securing Fervo's industrial control systems, including SCADA, PLCs, HMIs, and associated control networks.This role partners closely with engineering, op...Show more

 • Promoted

Cybersecurity Engineer

Point Solutions Commercial, LLCBoulder, CO, USA
Full-time
Quick Apply

Point Solutions Security is hiring a Cybersecurity Engineer to support a client in the Boulder, CO area.This will be a hands-on engineering role responsible for end-to-end ownership, engineering, a...Show more

 • New!

Cyber Security Analyst/ISSO

Arete AssociatesNiwot, CO, United States
Full-time +1

At Arete, we are on the forefront of utilizing innovative solutions, with great minds from all backgrounds, to help solve the nation's most complex security challenges.We strive for an inclusive, c...Show more

 • Promoted

Engineer Supervisor

La Quinta Denver - GoldenGolden, CO, United States
Full-time +1

Highgate is a premier real estate investment and hospitality management company widely recognized as an innovator in the industry.Highgate is the dominant player in U.New York, Boston, Miami, San F...Show more

 • Promoted

Director of Security

Monarch Casino Resort Spa - Black HawkBlack Hawk, CO, United States
Full-time

Job Title: Director of Security.This position is responsible for the planning, implementation, and day-to-day operations of Security/Risk Management for Monarch Casino Resort Spa.The Director’s pri...Show more

 • Promoted

Engineer Principal Systems

BAE Systems USABoulder, CO, United States
Full-time

Join the Systems Engineering team at BAE Systems Inc, Space and Mission Systems a group of motivated problem solvers.We like to have fun and enjoy life - both at work, and in our free time.We're ex...Show more

 • Promoted

Cybersecurity Engineer

Rule4Boulder, CO, United States
Full-time

Join us in changing the world!.If you are an extraordinary technologist who loves creative problem solving, can interface with clients just as well as operating systems, and wants to build an endur...Show more

 • Promoted

Engineer Supervisor

Highgate HotelsGolden, CO, United States
Full-time +1

Highgate is a premier real estate investment and hospitality management company widely recognized as an innovator in the industry.Highgate is the dominant player in U.New York, Boston, Miami, San F...Show more

 • Promoted

Cybersecurity SIEM Engineer ( Security Information Event Mgmt. Engineer)

BTI ServicesGolden, CO, United States
Full-time

Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutio...Show more

 • Promoted

Senior / Principal DevSecOps Engineer

SciTecBoulder, CO, United States
Full-time

SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.For the past forty-five plus years, we ha...Show more

 • Promoted

Senior/Principal Systems Engineer

SciTec, Inc.Boulder, CO, United States
Full-time

Be among the first 25 applicants.We support customers throughout the Department of Defense and U.Government in building innovative new tools to deliver unique world-class data exploitation capabili...Show more

 • Promoted

Senior / Principal DevSecOps Engineer

SciTec IncorporatedBoulder, CO, United States
Full-time

SciTech is a dynamic small business, with the mission to deliver advanced sensor data processing technologies and scientific instrumentation capabilities in support of National Security and Defense...Show more

 • Promoted

Psychiatric Nurse Practitioner (PMHNP) - Hygiene, CO

LifeStance HealthHygiene, CO, US
Full-time

At LifeStance Health, we believe in a truly healthy society where mental and physical healthcare are unified to make lives better.Our mission is to help people lead healthier, more fulfilling lives...Show more

 • Promoted

Senior Security Engineer - Harden CI/CD & SDLC

nexus IT groupBoulder, CO, United States
Full-time

A leading technology firm located in Boulder, Colorado, is seeking an experienced engineer to design and implement security-focused software that embeds security early in the development lifecycle....Show more

 • Promoted

Engineer Senior Principal - Systems

BAE Systems USABoulder, CO, United States
Full-time

Join the Systems Engineering team at BAE Systems Inc, Space and Mission Systems – a group of motivated problem solvers.We like to have fun and enjoy life - both at work, and in our free time.We're ...Show more