Skip to content

Open nowPosted 29 days ago

Principal, Product Security

itron26 open roles

Pay
$96,000 – $165,000 a year
Where
United States of America Texas Austin
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal, Product Securityitron · United States of America Texas Austin
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on itron's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. itron postings stay open a median of 7 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 29 days ago

itron median: 7 days open

The posting

Itron is innovating new ways for utilities and cities to manage energy and water. We create a more resourceful world to protect essential resources for today and tomorrow. Join us.

Itron, Inc. (NASDAQ: ITRI) is a global technology and services company dedicated to the resourceful use of energy and water. With more than 300 million deployed endpoints worldwide, Itron is a leader in IoT innovation, helping utilities and cities create a more sustainable, connected, and resourceful future.

As a member of the Information Security team, you will serve as the senior technical leader responsible for advancing Itron's product security program across software development, cloud, and engineering environments. This role focuses on securing source code, software supply chains, CI/CD pipelines, and product architectures while enabling agile, customer-centric development practices. You will collaborate closely with Product Development, DevOps, Cloud Engineering, Enterprise Architecture, and Cybersecurity teams to design and implement scalable security solutions that protect Itron products and services throughout the development lifecycle.

Duties & Responsibilities

  • Lead the architecture and engineering of security controls that protect source code repositories, development environments, build systems, software supply chains, and release processes.
  • Design and implement secure CI/CD pipeline patterns, artifact management controls, signing services, and deployment workflows that ensure software integrity from code commit through product release.
  • Partner with security-by-design and application security testing teams to operationalize security requirements, vulnerability management, threat modeling outcomes, and release controls.
  • Establish and promote secure application and API security standards, including authentication, authorization, secure coding practices, data protection, logging, and abuse prevention.
  • Collaborate with engineering teams to reduce application, API, and cloud attack surfaces through secure architecture, identity management, and least-privilege access models.
  • Drive modernization of development and engineering environments to mitigate risks associated with credential compromise, malicious code, dependency attacks, and unauthorized releases.
  • Integrate security capabilities across source control, CI/CD platforms, cloud services, artifact repositories, governance tools, and security monitoring solutions.
  • Automate security controls and operational processes using APIs, infrastructure-as-code, and scripting technologies such as Python, PowerShell, Terraform, GitHub Actions, Azure DevOps, Jenkins, and GitLab.
  • Establish security logging, monitoring, and detection requirements for software development and release environments in partnership with security operations teams.
  • Develop secure architecture guardrails, reference standards, operational procedures, and technical documentation that support scalable and innovative product delivery.
  • Ensure auditable evidence exists for software supply chain controls, artifact integrity, release approvals, SBOM generation, and regulatory or customer assurance requirements.
  • Mentor engineers and influence cross-functional teams to adopt secure, customer-focused, collaborative, and accountable engineering practices across global product environments.

Required Skills & Experience

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education and experience.
  • 7+ years of experience in cybersecurity, product security, application security, software engineering, DevSecOps, cloud security, or a related technical discipline.
  • 5+ years of hands-on experience securing software development environments, source code platforms, CI/CD pipelines, or software supply chains.
  • Expert-level experience designing and operating security controls across cloud, SaaS, enterprise, and product engineering environments.
  • Strong knowledge of software supply chain security, source code protection, secrets management, privileged access management, artifact integrity, dependency governance, and secure release practices.
  • Deep understanding of application and API security principles, including OWASP Top 10, OWASP API Security Top 10, secure coding practices, and modern authentication and authorization models.
  • Experience troubleshooting complex issues involving source control systems, build platforms, deployment pipelines, artifact repositories, and release management processes.
  • Experience implementing path-to-production controls including policy enforcement, release gates, exception management, evidence collection, and deployment readiness criteria.
  • Demonstrated ability to communicate technical risk and recommendations effectively to engineering leadership and executive stakeholders.
  • Proven ability to influence diverse teams and drive adoption of secure, innovative, and agile engineering practices.
  • Strong written, verbal, and stakeholder-management skills.

Preferred Skills & Experience

  • Professional certifications such as CISSP, CSSLP, CCSP, GIAC GWEB, GWAPT, GCSA, AWS Security Specialty, Microsoft Certified: Cybersecurity Architect Expert, or equivalent security certifications.
  • Hands-on experience with GitHub, GitLab, Azure DevOps, Bitbucket, or similar platforms, including branch protection, code review workflows, signed commits, repository permissions, and secret scanning.
  • Experience securing CI/CD platforms such as Jenkins, GitHub Actions, Azure DevOps, and GitLab CI, along with artifact repositories, package registries, and deployment automation solutions.
  • Knowledge of secure product architecture, deployment security, artifact signing, provenance, SBOM practices, and release integrity controls.
  • Familiarity with software supply chain security frameworks and practices including SLSA, NIST SSDF, OWASP SAMM, and OWASP Top 10.
  • Experience applying application and API security principles across web, cloud, mobile, embedded, and service-based architectures.
  • Experience using Terraform, AWS CloudFormation, Open Policy Agent, Python, PowerShell, and policy-as-code approaches to automate security controls.
  • Understanding of modern product security threats including dependency confusion, malicious packages, source code tampering, credential theft, build pipeline compromise, and release artifact manipulation.
  • Experience supporting regulated environments aligned with ISO 27001, SOC 2, NIST, CMMC, IEC 62443, or comparable frameworks.

Travel: Less than 25%.

Benefits Info: This position also includes a competitive benefit package including; financial, social, health and wellbeing programs, paid vacation, 401k matching, employee stock purchase program, hybrid work schedule, and more!

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills and experience and may vary by location. The base salary is $96,000-165,000 annually. This position is eligible for our annual bonus program.

#LI-EP1

Itron is committed to building an inclusive and diverse workforce and providing an authentic workplace experience for all employees. If you are excited about this role but your past experiences don't perfectly align with every requirement, we encourage you to apply anyway. In the end, you may be just who we are looking for!

The successful candidate's starting wage will be determined based on permissible, non-discriminatory factors such as skills and experience.

Itron is proud to be an Equal Opportunity Employer. If you require an accommodation to apply, please contact a recruiting representative at 1-800-635-5461 or email [email protected].

Itron is transforming how the world manages energy, water and city services. Our trusted intelligent infrastructure solutions help utilities and cities improve efficiency, build resilience and deliver safe, reliable and affordable service. With edge intelligence, we connect people, data insights and devices so communities can better manage the essential resources they rely on to live. Join us as we create a more resourceful world: www.itron.com

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against itron's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on itron's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    itron's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.