Skip to content

Open nowPosted 11 hours ago

Security Engineer

DigitalBridge7 open roles

Pay
$235,000 – $290,000 a year
Where
Boca Raton, Florida; New York, New York
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerDigitalBridge · Boca Raton, Florida; New York, New York
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on DigitalBridge's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 11 hours ago

The posting

We are hiring a Principal Security Engineer / DevSecOps Lead to own the security posture of our SaaS platforms, cloud environments, and AI-enabled applications. This is a senior hands-on leadership role: you will design and drive the security architecture that protects a regulated, multi-tenant investment platform, embed automated security controls into how we build and ship software, and lead red-team-informed offensive testing that measurably reduces real risk. You will partner with SRE, platform, data, and application teams — and directly with the CISO to set the enterprise standard for secure development.

What you'll do

  • Own security architecture for our SaaS platforms, multi-cloud environments (AWS, Azure), and AI-enabled applications, including LLM- and agent-based workloads.
  • Build and operate a modern DevSecOps program: SAST, DAST, IaC scanning, SBOM/supply-chain (Sigstore, SLSA), secrets detection, container and Kubernetes admission control, and policy-as-code (OPA/Cedar).
  • Design and run an automated vulnerability management program that prioritizes by exploitability and business impact, drives closure SLAs, and holds engineering teams accountable through metrics.
  • Lead application security across the SDLC: threat modeling, secure design reviews, code review at critical seams, security champions program, and paved-road guardrails engineers actually adopt.
  • Direct red-team and adversarial testing — internal exercises, purple-teaming, and third-party engagements — and translate findings into durable architectural fixes, not just tickets.
  • Harden multi-tenant isolation, identity, and data protection for a regulated buy-side platform; own the security controls that map to SOC 2, SOX, and applicable regulatory obligations.
  • Set the security-by-design bar for AI-enabled applications: prompt-injection defense, tool/agent boundary controls, model and data provenance, retention, and abuse monitoring.
  • Partner with IT/AI Platform, SRE, and Data Governance on identity, secrets, network segmentation, logging, and incident response; participate in on-call for security incidents.
  • Mentor senior engineers across security and platform; represent security in executive and board-facing risk reporting when required.

Required experience

  • 10+ years in information security with deep hands-on DevSecOps and application security expertise; senior-leader scope but still writes code and shipped controls.
  • Proven design and operation of security for SaaS platforms and cloud environments (AWS and/or Azure) at enterprise scale, including multi-tenant workloads.
  • Strong background in automated vulnerability management and security testing — SAST/DAST/SCA, IaC/CSPM, container/K8s security, and SBOM/supply-chain tooling.
  • Demonstrated red-team / offensive security experience: leading engagements, conducting or overseeing adversarial testing, and running purple-team exercises against real production systems.
  • Deep secure-development expertise: threat modeling (STRIDE/attack trees), secure code review, cryptography fundamentals, identity/OAuth/OIDC, and API security.
  • Experience securing AI-enabled applications — LLM/agent security, prompt injection, data-leakage controls, and model/tool boundary design.
  • Strong hands-on skills in Python and/or Go; comfortable operating in Terraform, Kubernetes, and modern CI/CD.
  • Track record leading security architecture initiatives for large-scale enterprise and multi-tenant environments, with measurable risk reduction.

Nice to have

  • Prior financial services, buy-side, or otherwise regulated (SOC 2, SOX, GLBA, NYDFS 500) environment experience.
  • Offensive security certifications (OSCP, OSEP, OSCE, CRTO) or published research/CVEs.
  • Experience with red-team infrastructure (C2 frameworks, EDR evasion, cloud-native attack paths) and detection-engineering collaboration.
  • Familiarity with MCP, agent frameworks, and enterprise LLM gateways.

The compensation range for this position is for a full-time employee in New York. The base salary offered will depend on qualifications, market data and internal equity.

Base Salary Range

$235,000—$290,000 USD

At DigitalBridge, we strive to create an inclusive environment where diverse employees want to work and where they can flourish professionally. In furtherance of our culture, all qualified applicants will receive consideration for employment without regard to race, national origin, gender, age, religion, disability, sexual orientation, veteran status, marital status or any other characteristics protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against DigitalBridge's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on DigitalBridge's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    DigitalBridge's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.