Principal Security Engineer
HybridDenver, Colorado, United States or Austin, Texas, United States
Job Summary
Jeppesen ForeFlight is seeking a Principal Security Architect to own the technical security strategy across enterprise IT and SaaS environments. As a senior individual contributor, you will set architecture, drive adoption, and measure outcomes while partnering with engineering, infrastructure, product security, and compliance teams. The role is hybrid in Denver, CO or Austin, TX, with case-by-case consideration for remote candidates. Responsibilities include defining and evolving enterprise security architecture across identity, endpoints, networks, cloud (AWS/Azure), and SaaS; implementing zero-trust, IAM/PAM, MFA, and privileged credential management using Okta and Entra ID; leading detection and response through EDR/XDR, SIEM, and DLP; vendor and platform reviews; and translating regulatory obligations (SOC 2, ISO 27001, aviation controls) into concrete engineering work. Mentoring security and infrastructure engineers and collaborating with executives on risk posture are also expected. The role emphasizes practical engineering outcomes and security leadership in safety-critical aviation software environments.
Required Qualifications
- 10+ years in security engineering or architecture, including 3+ years as a principal architect or staff-level IC with demonstrated enterprise ownership.
- Understanding of security as it flows across environments such as data centers, Azure, AWS. Hands-on familiarity with IAM and VPC security.
- Proven experience with enterprise identity platforms (Okta, Entra ID/Azure AD) and modern detection tooling (EDR/XDR, SIEM, SOAR).
- Solid working knowledge of NIST CSF, ISO 27001, and SOC 2; familiarity with FAA/EASA, DoD, or CMMC contexts is a meaningful advantage.
- Track record of turning risk assessments and audit findings into shipped engineering improvements — not just recommendations.
- Strong communicator across audiences: equally comfortable whiteboarding with engineers and presenting risk posture to executives.
- Bachelor's in CS, engineering, or equivalent experience. CISSP, OSCP, or GIAC certifications are valued, not required.
Desired Qualifications
- Experience in aviation, aerospace, defense, or other safety-critical software environments where the cost of a security failure extends beyond data.
- Hands-on experience integrating acquired companies onto a common enterprise security baseline — identity federation, endpoint standardization, and network segmentation.
- Familiarity with M&A security due diligence and post-close integration planning.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.