EngineerJobs.io
← Back to all jobs

Job Description

Principal Product Security Engineer (Secure Development Lifecycle) is a senior individual contributor role focused on defining and embedding secure software development practices into Navy Federal’s software delivery environment.

Responsibilities

  • Define and mature Secure Software Development Lifecycle (Secure SDLC) practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.
  • Lead the integration of Secure Development Practice capabilities into engineering workflows, governance forums, and lifecycle activities.
  • Define and support a pre-production product security scorecard to enable risk-informed release decisions, including communication of product security posture, open risks, exceptions, and required remediation actions to business and technology stakeholders.
  • Map product security activities across the software delivery lifecycle: intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.
  • Establish repeatable process patterns to integrate threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling.
  • Identify and reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy steps that do not align with Navy Federal delivery practices.
  • Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.
  • Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.
  • Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development with enterprise delivery processes.
  • Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.
  • Recommend process improvements to strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.
  • Establish adoption and effectiveness measures to demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.
  • Lead cross-functional working sessions, develop executive-ready recommendations, and influence process decisions across security and engineering stakeholders without direct authority.

Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.
  • Experience defining, improving, or integrating secure development lifecycle practices into enterprise software delivery processes.
  • Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.
  • Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.
  • Demonstrated experience creating process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.
  • Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.
  • Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.

Desired Qualifications

  • Extensive hands-on experience in application security, secure SDLC, software engineering, DevSecOps, enterprise architecture, technology risk, or software delivery governance.
  • Strong understanding of software delivery practices including Agile, SAFe, DevOps, DevSecOps, CI/CD, product-oriented delivery, architecture governance, and release management.
  • Advanced degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, Business Administration, or related field.
  • Experience with industry frameworks/models such as NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework, or similar security and software assurance practices.
  • CISSP, CISM, CSSLP, CCSP, GIAC, cloud security, architecture, Agile, SAFe, or related professional certifications.

Work Location and Schedule

  • Location: Vienna, VA (onsite)
  • Addresses: 820 Follin Lane, Vienna, VA 22180; 5510 Heritage Oaks Drive, Pensacola, FL 32526; 141 Security Drive, Winchester, VA 22602
  • Hours: Monday - Friday, 8:00AM - 4:30PM

Compliance

  • Adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.

Similar Jobs