Principal Security Engineer
Libertas Funding · Greenwich, CT
$160,000–$225,000from the description
Jul 25, 2026
Greenwich, CT
Jul 26, 2026
What this job asks for AI summary
A senior individual contributor role responsible for owning security as an engineering discipline across cloud infrastructure, corporate networks, and physical systems. The work spans hardening AWS environments, securing CI/CD pipelines and the SDLC, managing identity and access, and applying offensive security techniques to proactively find and fix weaknesses. Suited to an engineer who writes production code and brings hands-on DevSecOps and cloud security experience.
Senior level · 7+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
Advertised as Principal, but the requirements read as Senior.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 240 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 50–430
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The role is titled 'Principal Security Engineer' but the actual scope — a senior individual contributor owning security for a single firm's environment — is consistent with a Senior-level position. 'Principal' here reads as a title convention rather than an org-wide technical authority role, so seniority is assessed as Senior.
SOC classification is Medium confidence. The role blends deep security analysis/offensive work (15-1212) with substantial software/infrastructure engineering (15-1252, DevSecOps, IaC, production code). The primary day-to-day framing leans toward security analysis and hardening, so 15-1212 is chosen, with 15-1252 as a close runner-up.
The company is headquartered in Greenwich, CT. Greenwich falls within the New York-Newark-Jersey City CBSA (35620); state is noted as CT.
Terraform and OPA appear in the required qualifications under an 'e.g.' qualifier ('infrastructure-as-code and policy-as-code (e.g., Terraform, OPA, or similar)') — the qualifier signals the specific tools are interchangeable, but the capability itself is a hard gate. Alternatives are populated accordingly.
Okta is listed in required qualifications with 'or equivalent' — treated as a hard gate on IAM capability; alternatives reflect common enterprise IAM substitutes.
Microsoft 365 and Google Workspace are listed together as a single IAM/identity scope requirement; emitted as one skill with Google Workspace as an alternative.
NIST CSF is referenced in the responsibilities narrative as a mapping framework rather than in the required qualifications block, so it is marked preferred.
Red team experience, financial-services regulatory frameworks (SOC 2, GLBA, FFIEC), and NIST are listed under the 'Preferred' section.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.