Principal Security Engineer, Product & Infrastructure
Pigment
Principal Security Engineer, Product & Infrastructure Overview
| Company Name | Pigment |
| Job Role | Principal Security Engineer, Product & Infrastructure |
| Qualifications | Not Specified |
| Category | IT Jobs |
| Job Type | Full Time |
| Location | London |
Pigment is seeking a highly experienced Principal Security Engineer to lead security initiatives across its product and infrastructure domains. This role involves designing and embedding security features into the platform, performing threat modeling on new services, and making critical architectural decisions to prevent future vulnerabilities. The successful candidate will review code, architecture, and configurations personally, acting as the primary contact for early problem detection and resolution by developers and product managers.
In addition, you will develop and oversee comprehensive assurance programs, including internal audits, red team exercises, and managing relationships with third-party auditors to maintain certifications such as ISO and SOC standards. You will own vulnerability management processes from detection through to verified remediation, ensuring effective mitigation strategies are implemented and validated.
Building and refining detection capabilities is a key aspect of this role, involving identifying meaningful signals, creating detection rules that accurately catch real threats without generating excessive noise, and developing incident response playbooks. You will lead investigations into security incidents and potential fraud in the production environment, from initial detection to root cause analysis, and identify opportunities for automation to streamline repetitive tasks.
Setting technical security standards for the software development lifecycle is essential, including providing guidance, review processes, and educational resources primarily aimed at product, engineering, and SRE teams. You will collaborate on specific projects such as securing AI features like MCP Server and Modeler Agent through threat modeling, design reviews, and security assessments. Additionally, you will contribute to the migration of GitHub to managed identities, including provisioning via Okta, retiring personal accounts, and transitioning CI credentials to short-lived OIDC tokens.
Designing secure agent identity mechanisms for the MCP Server, including delegated access tokens and token exchange processes, will be part of your responsibilities, ensuring least privilege principles are upheld across production and CI/CD environments.
The ideal candidate will have at least 8 years of experience in security, with a proven record of owning security roadmaps end-to-end, influencing engineering teams without direct authority, and possessing hands-on expertise across development, databases, networking, and web security. A collaborative, humble approach and fluency in English are essential, with French language skills considered a strong plus.
Our hiring process involves multiple stages, including initial discussions, technical deep dives, cross-functional interviews, and final meetings with senior leadership. We offer a competitive salary, stock options, comprehensive health coverage, wellness benefits, professional development stipends, and flexible remote working arrangements. Our offices are located in key global cities, and we provide high-end equipment to support your work.
Note that this role does not specify any visa sponsorship support. We do not mention any support for UK visa or work sponsorship, and the job posting indicates that sponsorship is not provided.
Degree Requirement: Not Specified
Visa Sponsorship May be
To apply for this job please visit jobs.lever.co.