Principal Security Engineer
144k - 176k USD
Remote
Full Time
#Engineering
#Security
#Privacy
#Security Architecture
#Monitoring
#Risk Assessment
#Incident Response
#Compliance
#Mentoring
#Collaboration
#Technology Research
#Communication
#DevSecOps
At Code for America, we believe that government should work for everyone in the digital age. For over a decade, we have dedicated ourselves to using technology to break down barriers and provide real solutions for communities. By merging the best practices of the technology sector, nonprofits, and government, we create tools that inspire change and support those who need it most. We are building a movement of change agents who are driven by empathy and a commitment to equity, and we invite you to join us in our mission to drive lasting, generational impact.
About the Role
We are looking for a Principal Security Engineer to join our team on a full-time basis. In this role, you will act as a key contributor to our security practice, ensuring that our products meet high standards of security and privacy. You will collaborate with our Product Engineering and DevSecOps teams to understand our systems, identify opportunities for improvement, and serve as an advisor across the organization. This position requires a balance of proactive prevention and reactive response, and you will have the opportunity to shape our security policies and best practices.
Key Responsibilities
- Lead Security Initiatives: Take charge of major security projects, from setting goals and timelines to defining technical templates and ensuring successful implementation across the organization.
- Security Architecture and Design: Oversee the development of secure software architectures, including threat modeling and the implementation of secure coding practices throughout the development lifecycle.
- Incident Response and Forensics: Lead the response to security incidents, conduct thorough investigations into breaches, and implement measures to prevent future vulnerabilities.
Requirements
To be successful in this role, you should possess the following qualifications:
- At least 10 years of experience in software engineering or information security, with at least 4 years specifically in a security-focused role.
- Extensive experience with privacy protection and deep subject matter expertise across multiple information security domains.
- Strong coding skills and practical experience with agile development, DevSecOps, and securing production environments using tools like AWS and Terraform.
- Excellent communication skills and a collaborative, pragmatic approach to problem-solving.
- A strong background in incident response and security operations.
Location
This position is remote and is open to candidates located anywhere within the United States.
Compensation and Benefits
The annual salary range for this position is $143,884 - $176,138. We offer a comprehensive and holistic benefits package designed to support our mission and our employees, including:
- Medical, dental, and vision insurance with significant employer contributions.
- A 401k retirement plan with employer matching.
- A $1,000 annual stipend for professional development.
- Generous time off, including 16 paid holidays, paid sick time, and a paid sabbatical after four years of service.
- Support for your remote work environment, including a laptop, a $700 setup stipend, and a monthly internet or cell phone reimbursement.
- Equity compensation and life insurance.
- Access to an employee assistance program.



