368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$128k – $279k per year (Estimated)
Location
In office (Bellevue)
Seniority
Principal · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Smartsheet is a leading enterprise work management platform that enables organizations to plan, track, automate, and report on work at scale. Combining the familiarity of spreadsheets with powerful features like automated workflows, dynamic dashboards, and project tracking tools, it enhances team collaboration and operational efficiency.

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

AI is reshaping what product security can accomplish, both as a target and as a tool. We're looking for a Principal Security Engineer to own the highest-leverage application security work at Smartsheet: leading threat modeling and product security reviews across a modern SaaS platform used by millions of customers, serving as the team's technical authority on AI security risk, and setting the technical standard for application security practice across the engineering organization.

This is the most senior individual contributor role on the Application Security team. The expectation is not just depth: it is reach. You will engage product and engineering leadership directly, drive security requirements rather than advisory recommendations, and build team capability over time. If you are a security engineer who thinks upstream, builds threat models that generate concrete test scenarios and can translate technical findings into architecture decisions and business outcomes, this role is built for you.

This role reports to the Manager, Application Security and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.

You Will: 

  • Lead Threat Modeling and Product Security Reviews: Own threat modeling and product security review as the team's primary upstream capability: build models from architecture and data-flow artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. Define and lead the product security review service (set the service model, triage criteria, and enforcement posture) and personally execute reviews for high-risk features with documented findings and remediation timelines. Engage product and engineering directly to establish security requirements at the design phase, with the technical credibility to influence architecture decisions.
  • Define AI Security Methodology and Drive It Across the Practice: Define how AI security risk is assessed, monitored, and mitigated across product, engineering, and third-party AI integrations, with recognized depth on the current threat landscape: LLM workflows, agentic pipelines, MCP-based integrations, and attack classes including prompt injection, indirect injection, and tool-calling authorization gaps. Own and evolve the AI-assisted security review capability: evaluate detection value, assess build-vs-buy tradeoffs, and shape toolchain coverage as Smartsheet's AI-integrated product surface scales.
  • Shape AppSec Technical Direction and SDLC Controls: Serve as the technical authority for the AppSec program's SDLC control surface (secure coding guidelines, CI/CD pipeline security strategy, and toolchain direction across SAST, SCA, secrets, and IaC scanning) with the depth to influence tool decisions and resolve standards decisions that span teams without primary operational ownership. Build runbooks, standards, and documentation that create consistency and reduce single-point-of-failure risk as the team scales.
  • Elevate Team Capability and Engineering Organization Influence: Mentor AppSec team members on threat modeling tradecraft and security review design, and serve as the trusted technical voice with product and engineering leadership, framing risk in terms that move architecture decisions. Your judgment shapes how the team prioritizes and how the broader organization understands and invests in application security.

You Have:

  • 10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering, including direct ownership of threat modeling programs and security review services at scale.
  • Ability to own threat modeling as a systematic practice (STRIDE, data-flow and architecture diagram driven), producing concrete, actionable test scenarios and abuse cases, embedded into agile design cycles as a repeatable, lightweight practice.
  • Hands-on experience securing AI-integrated applications (LLM workflows, agentic systems, model APIs, MCP-based integrations) with fluency in the OWASP LLM Top 10 and current AI attack classes, plus experience using AI tooling to scale security review coverage.
  • Experience doing architecture review and targeted manual code review for complex SaaS features, with a track record of driving remediation requirements through to implementation with enough technical credibility to influence design decisions at the engineering leadership level.
  • Experience mentoring engineers into threat modeling ownership and attacker-mindset review design; demonstrated track record of establishing security requirements as design-phase gates and sustaining engagement with engineering teams to drive implementation.
  • Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines to credibly influence toolchain direction, resolve standards decisions that span teams, and shape secure coding standards without primary operational ownership; cloud security fundamentals sufficient to tie application controls to the infrastructure they run on.
  • Fluent in one or more modern languages (Python, Java, TypeScript/JavaScript, Go, or equivalent); comfortable reading production codebases to surface issues tooling misses and writing or extending automation others can maintain.
  • Expertise communicating risk and security requirements (written and verbal) clearly across audiences from engineering ICs through executive leadership; recognized as a trusted technical voice by partner teams.
  • Ability to build trusted relationships across engineering, product, and security organizations; earns influence through technical credibility and sustained engagement.
  • Legally eligible to work in the U.S. on an ongoing basis.

Nice to Have:

  • GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration.
  • Experience building AI-assisted security tooling or LLM-integrated review workflows that scale security review coverage.
  • Penetration testing depth including exploit writing or vulnerability chaining to validate exploitability and prove real-world impact.
  • Public-facing security contributions: conference speaking, CVE credits, published research, or industry community recognition that reflects the technical authority expected at principal level.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range

$205,000—$257,500 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths-because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. 

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bellevue
$140k – $225k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Seattle
Python
TypeScript
Node JS
JavaScript
Python
FastAPI
Node JS
Fastify
Databases
PostgreSQL
Redis
Frontend
React.js
Vite
DevOps
Kubernetes
WebSockets
QA
Playwright
Vitest
Apply
$140k – $225k per year • Remote • Full-Time • 5+ years exp • Seattle
Python
Lua
Python
FastAPI
Celery
Pydantic
SQLAlchemy
Databases
pgvector
PostgreSQL
Redis
AI/ML
LLM
RAG
Hybrid Search
Reranking
Anthropic
LLM Evaluation
LLM Guardrails
OpenAI
Model Context Protocol
DevOps
OpenTelemetry
Apply
$98k – $132k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
R
SQL
Databases
Databricks
Snowflake
AI/ML
Embeddings
LangChain
LangGraph
LLM
NumPy
Pandas
Scikit-learn
Spark
TensorFlow
Transformers
Hugging Face
RAG
Analytics
Matplotlib
Seaborn
Apply
$98k – $132k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
R
SQL
Databases
Databricks
Snowflake
AI/ML
Embeddings
LangChain
LangGraph
LLM
NumPy
Pandas
Scikit-learn
Spark
TensorFlow
Transformers
Hugging Face
RAG
Analytics
Matplotlib
Seaborn
Apply
$98k – $132k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
R
SQL
Databases
Databricks
Snowflake
AI/ML
Embeddings
LangChain
LangGraph
LLM
NumPy
Pandas
Scikit-learn
Spark
TensorFlow
Transformers
Hugging Face
RAG
Analytics
Matplotlib
Seaborn
Apply
$159k – $285k per year (Estimated) • In office • Full-Time • 10+ years exp • Bellevue
AI/ML
AI Agents
Management
Smartsheet
Apply
$23k – $54k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
SQL
AI/ML
AI Agents
Time Series Forecasting
Analytics
Power BI
Tableau
Management
Smartsheet
Apply
Remote • 3+ years exp
Java
Kotlin
Objective-C
Swift
Java
RxJava
AI/ML
AI Agents
Mobile
Clean Architecture
JUnit
Management
Smartsheet
Apply
$31k – $81k per year (Estimated) • In office • Bengaluru
C++
Java
Python
SQL
AI/ML
AI Agents
Management
Smartsheet
Apply
$31k – $78k per year (Estimated) • In office • Bengaluru
Python
SQL
Databases
Databricks
AI/ML
AI Agents
AWS Bedrock
Fine-tuning
LangChain
LangGraph
MLFlow
RAG
Knowledge Graph
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Terraform
Vector
Management
Smartsheet
Apply
Engineering Manager 5 hours ago
$161k – $310k per year (Estimated) • In office • Bachelor's Degree • Bellevue
AI/ML
Edge AI
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Apply
$236k – $339k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bellevue
Java
Python
Databases
Snowflake
AI/ML
AI Agents
Feature Store
Apply
$160k – $210k per year • Remote/Hybrid • Full-Time • 6+ years exp • Denver • Bellevue
C#
C++
Go
Python
SQL
Databases
Azure Cosmos DB
Azure SQL Database
DynamoDB
MySQL
AI/ML
Edge AI
DevOps
AWS
Azure
Azure AKS
CI/CD
GCP
Google GKE
Kubernetes
SLI/SLO/SLA
Analytics
Power BI
Management
UiPath
Apply
$159k – $285k per year (Estimated) • In office • Full-Time • 10+ years exp • Bellevue
AI/ML
AI Agents
Management
Smartsheet
Apply
$152k – $278k per year (Estimated) • In office • 8+ years exp • Bellevue
SQL
Cybersecurity
GDPR
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.