Active listing
Principal Security Engineer
About the role
R&D team at AiDASH builds a unified platform securing electric grid infrastructure with AI-driven insights. The Principal Security Engineer leads the AppSec program, hardens AI/LLM deployments, and embeds security across the SDLC while collaborating with Platform, ML, and DevOps teams across the US and India. Bengaluru, hybrid (2 days/week in Palo Alto).
What you’ll do
- Own and mature AppSec toolchain (SAST, DAST, SCA, secrets scanning)
- Champion shift‑left security with threat modeling and secure‑design reviews
- Run SBOM/AIBOM tooling and enforce risk‑tiered dependency controls
- Write and enforce IaC policy‑as‑code (OPA/Rego, Checkov, Kyverno)
- Harden production GenAI deployments on AWS (IAM, VPC, guardrails)
- Codify OWASP LLM Top 10 and MITRE ATLAS controls into SDLC
- Govern internal AI‑assisted tooling (DLP, data discovery, usage telemetry)
- Support ISO 27001, ISO 42001, and SOC 2 Type II compliance
What you’ll bring
- 10+ years security engineering with AppSec depth
- Hands‑on production LLM/agentic AI security
- Cloud‑native AWS security experience
- IaC policy‑as‑code in live pipelines
- SBOM/AIBOM tooling at scale
- SOC 2 Type II or ISO 27001 audit experience
- SF Bay Area based, hybrid 2 days/week Palo Alto