Talent.com
Principal Security Engineer
Principal Security EngineerSpire • Boulder, Colorado, United States
No se aceptan más aplicaciones
Principal Security Engineer

Principal Security Engineer

Spire • Boulder, Colorado, United States
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

About the Role


You'll focus on hands-on design and implementation of security related software, to shift security left in our development processes. This includes embedding automated controls such as SBOMs and vulnerability scanning into CI/CD pipelines; maintaining and updating our internal shared libraries and infrastructure for authentication, authorization, and logging; and assisting with monitoring tools for operational services. Where needed, you'll help align systems with NIST 800-171/CMMC requirements, collaborating closely with the Principal Security Engineer, AWS infra team, dev tooling team, chief software engineer, and cybersecurity/GRC group.


You'll work in a lean, impact-focused environment—prioritizing deliverables like secure code and architecture with bureaucracy handled by the TPM/GRC org as much as possible. Occasional engagement in security discussions with government entities may be involved, under the principal security engineer's guidance.


~80-90% hands-on work, with the remainder on collaboration and learning.


Key Responsibilities:



  • Implement Security Controls in SDLC: Assist in integrating security automation into pipelines (e.g., GitHub Actions/ArgoCD for SAST/DAST/SCA, SBOM generation, and vulnerability scanning).

  • Support Shared Libraries and Infra: Contribute to evolving standard libraries/infra for authn/authz, logging, and other runtime security features, including testing and updates.

  • Contribute to CMMC Compliance: Hands-on support for implementing controls (e.g., encryption, secure configurations, monitoring) to meet/exceed CMMC Level 2 requirements in AC, IA, SC, and SI families, building on our ISO 27001 foundation.

  • Assist with Reviews and Models: Participate in security architecture reviews, code audits, and threat modeling; help identify and remediate issues like API vulnerabilities or supply chain risks.

  • Team Collaboration: Engage in code reviews, pair programming sessions, and tooling development to advance secure practices; provide peer support within the security engineering team.


Required Qualifications:



  • Experience: 5+ years in software or security engineering, with at least 3+ years in security-focused roles. Experience with secure cloud systems (AWS), CI/CD security, and compliance efforts (e.g., NIST, CMMC, or FedRAMP).

  • Technical Expertise: Proficiency in container security (Docker/Kubernetes), security tools (e.g., Trivy, Snyk, Falco, OPA), and programming languages for tooling (Python, Rust). Understanding of modern attacks and defenses.

  • Security Acumen: Knowledge of common threats (e.g., injection, lateral movement), controls (NIST 800-53 mappings), DevSecOps practices, SBOMs, zero-trust principles, and SIEM-integrated logging.

  • Interpersonal Skills: Ability to collaborate constructively with internal teams and contribute to external security discussions as needed.


Preferred Skills:



  • Familiarity with AWS security services (e.g., GuardDuty, Security Hub, Config) and IaC tools (Terraform).

  • Experience with embedded or satellite security (e.g., secure boot, over-the-air updates).

  • Contributions to open-source security projects.

  • Relevant certifications (e.g., CSSLP, OSCP, GIAC) demonstrating practical expertise.

  • Proven ability to work in small, agile teams and learn from senior mentors.


Bonus



  • Other: Experience in regulated industries (defense/aerospace); clearance for sensitive data handling.



Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office.


Access to US export-controlled software and/or technology may be for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. #LI-DC1

Crear una alerta de empleo para esta búsqueda

Principal Security Engineer • Boulder, Colorado, United States

Ofertas similares
Mechatronics & Robotics Tech

Mechatronics & Robotics Tech

Amazon Stores • Hygiene, CO, US
A tiempo completo
Application deadline: Applications will be accepted on an ongoing basis.Operations is at the heart of Amazon’s business.We are known for our speed, accuracy, and exceptional service.Our buildings d...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Fire Protection Alarm Technician

Fire Protection Alarm Technician

Emcor UK • Golden, CO, United States
A tiempo completo
From commercial office space and manufacturing to multi-site retail portfolios, we manage and support over 1 billion square feet of facilities space for the nation's leading organizations.We provid...Mostrar más
Última actualización: hace 6 horas • Oferta promocionada • Nueva oferta
Principal Analog/Mixed-Signal ASIC Architect

Principal Analog/Mixed-Signal ASIC Architect

Ralliant Corporation • Boulder, CO, United States
A tiempo completo
A leading technology company in Boulder, CO is looking for a Principal Analog/Mixed-Signal ASIC Designer to lead the design of advanced RF integrated circuits.The ideal candidate will have a master...Mostrar más
Última actualización: hace 5 días • Oferta promocionada
Fire Protection | Alarm Tech - Golden, CO

Fire Protection | Alarm Tech - Golden, CO

Seneca • Golden, CO, United States
A tiempo completo
Fire Protection / Alarm Technician.Competitive, based on experience.Join a dedicated fire life and safety team as a Fire Protection / Alarm Technician, supporting the inspection, testing, and maint...Mostrar más
Última actualización: hace 4 horas • Oferta promocionada • Nueva oferta
Senior Security Data Center Network Architect

Senior Security Data Center Network Architect

SciTec, Inc. • Boulder, CO, United States
A tiempo completo
A dynamic small business seeks a Network Architect in Boulder, CO.The ideal candidate will have extensive experience in network engineering and security, designing secure data center networks, and ...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
OB/GYN Physician

OB/GYN Physician

HealthEcareers - Client • Golden, CO, USA
A tiempo completo
OB/GYN Physician – Private Practice Opportunity.We are a well-established, well-respected private OB/GYN practice with 5 physicians and 2 nurse practitioners.We provide exceptional women’s healthca...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Principal Mixed-Signal-Analog ASIC Designer Boulder, CO, US + 1 more Posted 13 hours ago

Principal Mixed-Signal-Analog ASIC Designer Boulder, CO, US + 1 more Posted 13 hours ago

Ralliant Corporation • Boulder, CO, United States
Indefinido
Hybrid## Principal Mixed-Signal-Analog ASIC DesignerBoulder, CO, United States**Position Overview**Tektronix is seeking a highly skilled and innovative Principal Analog/Mixed-Signal ASIC Designer t...Mostrar más
Última actualización: hace 12 días • Oferta promocionada
Surveillance Observer

Surveillance Observer

Ameristar • Black Hawk, CO, United States
A tiempo completo
We're always looking for talent that believes in having fun.At PENN Entertainment, you'll get to be a part of an exciting industry, where the days and nights are fast paced.You'll work with an incr...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
MEP Superintendent Data Center

MEP Superintendent Data Center

Pkaza LLC • Boulder, CO, United States
A tiempo completo
Data Center MEP Superintendent – Gary, IN.This opportunity is with an established General Contractor that specializes in converting existing Buildings and Structures into complex buildings / indust...Mostrar más
Última actualización: hace 16 días • Oferta promocionada
Senior/Principal Data Engineer

Senior/Principal Data Engineer

SciTec, Inc. • Boulder, CO, United States
A tiempo completo
SciTec has been awarded multiple government contracts and is growing our creative Team! SciTec, Inc.We support customers throughout the Department of Defense and U.Government in building innovative...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Senior Subcontracts Manager

Senior Subcontracts Manager

NNData • Niwot, CO, United States
A tiempo completo
At Aret, we are on the forefront of developing innovative solutions, with great minds from all backgrounds, to help solve the nation's most complex security challenges.We strive for an inclusive, c...Mostrar más
Última actualización: hace 20 horas • Oferta promocionada • Nueva oferta
Engineering Technician

Engineering Technician

Trexon • Conifer, CO, United States
A tiempo completo
ConexSmart's Engineering Technician is a dynamic team player who uses math and science to solve complex technical problems in the avionics industry.This position joins a team who enjoys developing ...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Senior / Principal DevSecOps Engineer

Senior / Principal DevSecOps Engineer

SciTec Incorporated • Boulder, CO, United States
A tiempo completo
SciTech is a dynamic small business, with the mission to deliver advanced sensor data processing technologies and scientific instrumentation capabilities in support of National Security and Defense...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Director of Software Engineering

Director of Software Engineering

Infleqtion • Boulder, CO, United States
A tiempo completo
We are seeking self‑motivated, energetic individuals with exceptional problem‑solving and technical skills to help drive our.We break down barriers between disciplines, stepping in wherever we can ...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Senior Security Engineer - Harden CI/CD & SDLC

Senior Security Engineer - Harden CI/CD & SDLC

nexus IT group • Boulder, CO, United States
A tiempo completo
A leading technology firm located in Boulder, Colorado, is seeking an experienced engineer to design and implement security-focused software that embeds security early in the development lifecycle....Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Program Controls Analyst Principal

Program Controls Analyst Principal

BAE Systems USA • Boulder, CO, United States
A tiempo completo
Working as a Program Controls Analyst at BAE Systems Space and Mission Systems is an exciting opportunity to become part of a high-tech team of people developing innovative products for the Aerospa...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Fire Protection Alarm Technician

Fire Protection Alarm Technician

EMCOR Group • Golden, CO, United States
A tiempo completo
From commercial office space and manufacturing to multi-site retail portfolios, we manage and support over 1 billion square feet of facilities space for the nation's leading organizations.We provid...Mostrar más
Última actualización: hace 14 horas • Oferta promocionada • Nueva oferta
Administrator/Executive Director/POST ACUTE

Administrator/Executive Director/POST ACUTE

FullShift Staffing, LLC • Boulder, CO, United States
A tiempo completo
The Administrator oversees the day to day operations of the facility to meet State and Federal regulations and supervises all department managers to ensure the facility is in compliance.The Adminis...Mostrar más
Última actualización: hace 3 días • Oferta promocionada