Principal Security Engineer, Product & Infrastructure

Posted 4 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
80K-120K Annually
Senior level
Software
The Role
Own Pigment’s product, infrastructure, and CI/CD security roadmap as a hands-on technical leader. Responsibilities include threat modeling, secure architecture and code reviews, vulnerability management, assurance testing, detection engineering, incident response, and secure SDLC guidance. The role partners closely with product, engineering, and SRE teams, designs security for AI features and agent identities, strengthens least privilege, and builds automation across cloud and production environments.
Summary Generated by Built In
Join Pigment: The AI Platform Redefining Business Planning
 
Pigment is the AI-powered business planning and performance management platform built for agility and scale. We connect people, data, and processes in one intuitive, feature-rich solution, empowering every team—from Finance to HR—to build, adapt, and align strategic plans in real time.
 
Founded in 2019, Pigment is one of the fastest-growing SaaS companies globally. Industry leaders like Unilever, Snowflake, Siemens, and DPD use Pigment daily to make more informed decisions and confidently navigate any scenario.
 
With a team of 600+ across Paris, London, New York, Toronto, San Francisco and Austin, we've raised nearly $400M from top-tier investors and were named a Visionary in the 2024 Gartner® Magic Quadrant™ for Financial Planning Software.
 
At Pigment, we take smart risks, celebrate bold ideas, and challenge the status quo—all while working as one team. If you're driven by innovation and ready to make an impact at scale, we’d love to hear from you.

Reporting to the CISO, you'll own the security roadmap for Pigment's product, infrastructure, and CI/CD environment, and you'll build much of it yourself.
This is a hands-on role: expect to read code, threat model new services, reproduce and triage vulnerabilities, dig through infrastructure configuration and build the automation that closes gaps.
You'll also set direction and bring product and engineering with you, but that influence comes from technical credibility and not process: the engineers you work with will take you seriously because you've been in the same code they have.

The scope is broad: application security, infrastructure security, detection and response, and the assurance work that keeps our certifications standing. You won't be covering it alone. The security team is seven people and growing, with colleagues already owning compliance, governance and security operations, so this role can go deep on product and infrastructure and not be spread too thin across everything. Nobody arrives fluent in all of it: we're looking for real depth in several of these areas and the judgement to grow into the rest.


Key responsibilities include:

  • Product & Infrastructure Security Design - Design security features into the product itself and strengthen defence-in-depth across the platform. Threat model new services before they ship, and make the architectural calls that are expensive to reverse later.

  • Security Review & Risk Assessment - Review code, architecture and configuration yourself, and be the person developers and PMs bring problems to early rather than late. Deliver solutions that balance risk against business benefit, and escalate the calls that genuinely need senior arbitration.

  • Assurance & Testing - Run our assurance programme: internal code, architecture and configuration reviews, red team exercises, and the bug bounty. Own the relationship with third-party auditors, and measure the control KPIs that keep our certifications defensible.

  • Vulnerability Management - Own vulnerabilities from detection through to verified fix: reproduce them, score and triage them, design or validate the mitigation, and confirm it actually worked. Improve the KPIs that tell you whether the process is holding.

  • Detection Engineering - Build and improve our detection capability alongside the infrastructure and engineering teams: identify the signals worth collecting, write rules that catch real attacks without drowning us in noise, and build the response playbooks behind them.

  • Incident Response - Lead security investigations into the production environment end to end, from first signal to root cause, across incidents and fraud. Flag the repetitive work worth automating and the detections worth building, and hand those to the security operations team.

  • SDLC - Set the technical direction for how engineers at Pigment build securely: guidance, paved paths, and reviews that teach and not just gate. Contribute to company-wide awareness where it counts, but your primary audience is product, engineering and SRE.


Example projects that would fall under your responsibilities (actual examples of recently completed or currently on the roadmap):

  • Secure the design and development of our AI features, including the MCP Server and Modeler Agent: threat modelling, design reviews, working alongside the engineers building them, and security assessments. 

  • Work out where AI-assisted analysis actually belongs in our pipeline. AI-powered security reviews reason about a diff semantically rather than pattern-matching it, which is genuinely different from classic SAST - but it's not a drop-in replacement, and figuring out the split between AI review, traditional SAST and SCA is an open question we'd like you to answer with evidence rather than vendor claims.

  • Migrate GitHub to managed identities: provisioning through Okta, retiring personal accounts and long-lived PATs, and moving CI to short-lived OIDC credentials instead of stored keys.

  • Design agent identity for the MCP Server - delegated access tokens, token exchange, and making sure an agent acting for a user can never exceed what that user could do themselves.

  • Push least privilege further across production and CI/CD. Better than it was, not where we want it.

For a concrete example: here's how we built a sandboxed execution environment for LLM-generated code.

Technical Environment

Mostly production, with the occasional internal IT-adjacent project: 

  • Main sites in Paris, London, Toronto and NYC 

  • MacOS, Windows, Linux workstations

  • GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault

  • Okta, OAuth, JWT, C#, .NET Core, TypeScript, React, Python, Go

  • Datadog (SIEM), CloudFlare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog

  • Google Workspace, Jumpcloud, Vanta, Hibob, Slack

  • GitHub, CircleCI, ArgoCD

  • SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001

Who you are

You have at least 8 years of experience in security as a Security Engineer, Pentester or Security consultant, with real depth in product and/or infrastructure security. We care more about the scope of what you've owned than the exact number of years.

What you've done

  • Owned a security roadmap for a product or platform end to end, rather than delivering items on someone else's

  • Driven security work through engineering teams you had no authority over

  • Been the person your organisation escalated to on hard architectural calls

  • Worked hands-on across a broad technical surface - development, databases, networking, web

How you work

  • You're hands-on and intend to stay that way (this position does not include people management)

  • You look for the workable answer, not the blocking one

  • You have a good dose of humility, and you help the people around you get better

  • You speak English fluently, French is a strong plus


How we hire

After a first call with our recruiter, five conversations, around four hours in total, usually over two to three weeks:

  1. Ways of working (45 min) — how you operate with people, and what draws you to this role specifically.

  2. Technical deep dive (1h30) with a security engineer — including a practical. We'll give you a real problem we've already solved and talk through how you'd approach it.

  3. Cross-functional (45 min) with an engineer from product or platform — someone who'd be on the receiving end of your work.

  4. Ownership and career (1h) with the CISO and a member of the security team.

  5. Final (45 min) with our co-founder and CTO.


What we offer

  • Competitive package
  • Stock options to ensure you have a stake in Pigment's growth
  • The best health insurance with Alan Blue, entirely free for you and your family 
  • Weekly Lunch and Lunch vouchers (Swile card) to cover your lunch breaks with total flexibility
  • Subscription to Egym Wellpass (ex-Gymlib) for full access to gyms, studios, and wellness spaces across France
  • A Learning Stipend per year, for you to develop into areas that amplify impact for your careers or personal development
  • Remote work stipend to have the best work station possible at home
  • Along with one company offsite every year, we have brand new offices at the heart of major cities including New York, San Francisco, Toronto, Paris, and London
  • High-end equipment (based on stock/availability) to do your work in the best conditions

We conduct background checks as part of our hiring process, in accordance with applicable laws and regulations in the countries where we operate. This may include verification of employment history, education, and, where legally permitted, criminal records. Any checks will be conducted lawfully prior to formal employment contracts being signed, with candidate consent, and information will be treated confidentially.
 
Pigment is an equal opportunity employer. We believe diversity is a strength and fosters innovation. We are committed to enabling everyone to feel included and valued at the workplace.  All qualified applicants will receive consideration for employment without regard to age, color, family, gender identity, marital status, national origin, physical or mental disability,  sex (including pregnancy), sexual orientation, social origin, or any other characteristic protected by applicable laws. We may process your personal data in accordance with our HR Data Protection Notice.

Skills Required

  • At least 8 years of experience in security as a Security Engineer, Pentester, or Security Consultant
  • Real depth in product security and/or infrastructure security
  • Experience owning a security roadmap for a product or platform end to end
  • Experience driving security initiatives through engineering teams without direct authority
  • Experience serving as an escalation point for difficult architectural security decisions
  • Hands-on experience across development, databases, networking, and web technologies
  • Fluent English
  • French language skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Paris
187 Employees
Year Founded: 2019

What We Do

In a world moving at an incredibly fast pace, businesses have grown accustomed to change. Transforming their business model, pivoting their strategy, rethinking their go-to-market, the list goes on. To enable these changes, they have also had to rethink the way they work. Breaking down silos isn’t a best practice anymore. It’s a given. And yet, when it comes to planning, little has changed. In fact, planning tools work the exact opposite way, reinforcing data and people silos, and preventing teams from working together toward their common goals. As a result, planning is usually seen as a dreadful process. But the truth is, planning drives strategy. It’s high time we serve it with the right tools. Pigment is the business planning platform for fast-growing companies. Our mission is to help companies make better, faster decisions in a changing world, and drive revenue growth. At Pigment we believe that: ✅ Real-time data informs better outcomes. Trim your sail, and make the best use of current winds. ✅ Reporting should be accurate, quick, and insightful. ✅ Planning should be simple, smooth, and delightful. ✅ Less time should be spent on data crunching, more time on bringing insights to the business. ✅ Collaboration should be at the heart of any planning process, so your organization works as one. Book your demo today ? https://www.gopigment.com/contact We’re hiring! Check out our offers: https://jobs.lever.co/pigment

Similar Jobs

Pfizer Logo Pfizer

Director R&D EHS Program Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
36 Locations
121990 Employees
177K-294K Annually

Samsara Logo Samsara

Consultant

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
France
4000 Employees

Mirakl Logo Mirakl

Enterprise Account Executive

eCommerce • Information Technology • Retail • Software
Remote or Hybrid
9 Locations
750 Employees

Cloudflare Logo Cloudflare

Sales Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Paris, Île-de-France, FRA
4400 Employees
178K-244K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account