Principal Security Engineer at Avalara
$191,400–$315,800
Jul 7, 2026
—
Jul 20, 2026
What this job asks for AI summary
A senior technical lead role focused on building and scaling security capabilities across a cloud-based SaaS platform. The work centers on designing secure-by-default infrastructure, embedding security controls into CI/CD pipelines and cloud environments, and driving adoption of zero-trust and least-privilege principles across multiple engineering teams. The role also involves developing AI-assisted approaches to vulnerability management and mentoring engineers on platform security practices. Suited to someone with 12+ years of experience, including deep cloud and platform security expertise.
Senior level · 12+ years · Remote · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 840 people nationally plausibly meet what this posting asks for (information security analysts). range 250–1,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The title 'Technical Lead, Platform Security' carries no explicit seniority level word, so the title states no level; however, the 12+ years requirement and cross-org technical leadership scope firmly support Senior.
The role sits at the boundary of 15-1212 (Information Security Analysts) and 15-1252 (Software Developers): it requires strong programming skills and platform engineering work, but the primary day-to-day mission is security architecture, posture management, and security program leadership — 15-1212 is the better fit.
The degree requirement is a hard gate: 'Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or a related technical discipline' with no equivalent-experience escape clause.
The 12+ years figure is the overall role-level experience gate; the 5+ years focused on cloud/infrastructure/platform security is a sub-requirement within that total, not a separate named-technology years demanded.
AI-enabled security tooling appears only under Preferred Qualifications.
Security certifications (CISSP, CCSP, GCSA) appear only under Preferred Qualifications.
No compensation figures are provided in the posting.
Remote status is set per caller declaration; no metro is inferred.
Ignored 5 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): cloud security posture management, software supply chain security, secrets management, zero-trust architecture, AI-enabled security tooling.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.