Skip to main content

Security Engineer

DigitalBridge · DigitalBridge is an investment firm that owns, operates, and invests in all aspects of digital infrastructure.

Boca Raton, Florida; New York, New York251-500 employeesPosted 4 days ago
Post-IPO Debt · $400Mraised 5 months agoled by Public Investment Fund

This board only lists companies whose most recent round closed in the last 180 days.

Apply on DigitalBridge’s site
<p><span style="font-family: arial, helvetica, sans-serif;">We are hiring a Principal Security Engineer / DevSecOps Lead to own the security posture of our SaaS platforms, cloud environments, and AI-enabled applications. This is a senior hands-on leadership role: you will design and drive the security architecture that protects a regulated, multi-tenant investment platform, embed automated security controls into how we build and ship software, and lead red-team-informed offensive testing that measurably reduces real risk. You will partner with SRE, platform, data, and application teams — and directly with the CISO </span><span style="font-family: arial, helvetica, sans-serif;">to set the enterprise standard for secure development.</span></p> <p>&nbsp;</p> <h2><span style="font-family: arial, helvetica, sans-serif;"><strong>What you</strong><strong>'ll do</strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Own security architecture for our SaaS platforms, multi-cloud environments (AWS, Azure), and AI-enabled applications, including LLM- and agent-based workloads.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Build and operate a modern <strong>DevSecOps </strong>program: SAST, DAST, IaC scanning, SBOM/supply-chain (Sigstore, SLSA), secrets detection, container and Kubernetes admission control, and policy-as-code (OPA/Cedar).</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Design and run an <strong>automated vulnerability management </strong>program that prioritizes by exploitability and business impact, drives closure SLAs, and holds engineering teams accountable through metrics.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Lead <strong>application</strong><strong> </strong><strong>security</strong><strong> </strong>across the SDLC: threat modeling, secure design reviews, code review at critical seams, security champions program, and paved-road guardrails engineers actually adopt.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Direct <strong>red</strong><strong>-</strong><strong>team</strong><strong> and adversarial testing </strong>— internal exercises, purple-teaming, and third-party engagements — and translate findings into durable architectural fixes, not just tickets.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Harden multi-tenant isolation, identity, and data protection for a regulated buy-side platform; own the security controls that map to SOC 2, SOX, and applicable regulatory obligations.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Set the security-by-design bar for <strong>AI</strong><strong>-</strong><strong>enabled</strong><strong> </strong><strong>applications</strong>: prompt-injection defense, tool/agent boundary controls, model and data provenance, retention, and abuse monitoring.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Partner with IT/AI Platform, SRE, and Data Governance on identity, secrets, network segmentation, logging, and incident response; participate in on-call for security incidents.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Mentor senior engineers across security and platform; represent security in executive and board-facing risk reporting when required.</span></li> </ul> <p>&nbsp;</p> <h2><span style="font-family: arial, helvetica, sans-serif;"><strong>Required experience</strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">10+ years in information security with deep hands-on <strong>DevSecOps</strong><strong> </strong>and <strong>application</strong><strong> </strong><strong>security </strong>expertise; senior-leader scope but still writes code and shipped controls.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Proven design and operation of security for <strong>SaaS</strong><strong> </strong><strong>platforms</strong><strong> </strong>and <strong>cloud</strong><strong> </strong><strong>environments</strong><strong> </strong>(AWS and/or Azure) at enterprise scale, including multi-tenant workloads.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Strong background in <strong>automated vulnerability management </strong>and <strong>security testing </strong>— SAST/DAST/SCA, IaC/CSPM, container/K8s security, and SBOM/supply-chain tooling.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Demonstrated <strong>red</strong><strong>-</strong><strong>team </strong><strong>/</strong><strong> </strong><strong>o</strong><strong>ff</strong><strong>ensive security </strong>experience: leading engagements, conducting or overseeing adversarial testing, and running purple-team exercises against real production systems.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Deep secure-development expertise: threat modeling (STRIDE/attack trees), secure code review, cryptography fundamentals, identity/OAuth/OIDC, and API security.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Experience securing <strong>AI</strong><strong>-</strong><strong>enabled applications </strong>— LLM/agent security, prompt injection, data-leakage controls, and model/tool boundary design.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Strong hands-on skills in Python and/or Go; comfortable operating in Terraform, Kubernetes, and modern CI/CD.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Track record leading <strong>security architecture initiatives for large</strong><strong>-</strong><strong>scale enterprise and multi</strong><strong>-</strong><strong>tenant environments</strong>, with measurable risk reduction.</span></li> </ul> <p>&nbsp;</p> <h2><span style="font-family: arial, helvetica, sans-serif;"><strong>Nice to have</strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Prior financial services, buy-side, or otherwise regulated (SOC 2, SOX, GLBA, NYDFS 500) environment experience.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Offensive security certifications (OSCP, OSEP, OSCE, CRTO) or published research/CVEs.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Experience with red-team infrastructure (C2 frameworks, EDR evasion, cloud-native attack paths) and detection-engineering collaboration.</span></li> <li style="font-family: arial, helvetica, sans-serif;"><span style="font-family: arial, helvetica, sans-serif;">Familiarity with MCP, agent frameworks, and enterprise LLM gateways.</span></li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p>The compensation range for this position is for a full-time employee in New York. The base salary offered will depend on qualifications, market data and internal equity.</p></div><div class="title">Base Salary Range</div><div class="pay-range"><span>$235,000</span><span class="divider">&mdash;</span><span>$290,000 USD</span></div></div></div><div class="content-conclusion"><p></p> <p><em>At DigitalBridge, we strive to create an inclusive environment where diverse employees want to work and where they can flourish professionally. In furtherance of our culture, all qualified applicants will receive consideration for employment without regard to race, national origin, gender, age, religion, disability, sexual orientation, veteran status, marital status or any other characteristics protected by law.</em></p> <p>&nbsp;</p> <p></p></div>
Apply on DigitalBridge’s site

Applications go straight to the employer. VCBacked does not sit between you and the company.

1,821 more roles posted in the last 48 hours

You are seeing the board after its 48-hour member window. Job Seeker opens that window and sends an alert the moment a role hits — applicants in the first 24 hours land 90 percent of interviews.

Back to all roles at freshly funded companies