CFC
Principal Product Security Engineer
Employment
Not statedLevel
PrincipalCategory
SecurityCountry assessment
Not doable from Austria because the employer's own board marks it as not remote.
Our assessment is guidance. Confirm arrangements with the employer.
Skills mentioned in this posting
Job description
At CFC, technology is at the heart of everything we do. We are looking for a Principal Product Security Engineer to lead the strategy and hands-on delivery of security across cloud platforms, code and CI/CD pipelines. This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy.
You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering. You will also help CFC adopt AI-assisted and agentic product engineering safely. As these practices develop, you will use proportionate guardrails, controlled experimentation and evidence-led assurance rather than assume settled industry practice.
Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity Lead threat modelling and security design reviews for complex products and platforms Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability Measure security coverage, control effectiveness, developer experience and remediation velocity Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation We are interested in engineers who combine principal-level judgement with sustained hands-on delivery.
You'll likely bring: Deep experience in product, application, cloud and DevOps security Proven experience implementing security tooling in production engineering environments Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling Ability to write maintainable code, scripts, integrations and policy-as-code Experience leading threat modelling and resolving complex security design trade-offs Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility