Principal Engineer - Product Security - DevSecOps
FICOAbout the role
FICO (NYSE: FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential!
The Opportunity
"As a Principal Engineer in FICO’s Product Security Software Trust, Innovation & Operations group, you will draw from your expertise with modern CI/CD systems to help establish the secure foundations for a new product development DevOps pipeline. As part of Product Security’s Engineering Engagement team you will be embedded with software development teams to accelerate their focus on addressing security and technical debt, and will work closely with security engineers and architects, the security assurance team, and software engineers to determine appropriate architectural and design security requirements, define and implement secure-by-default infrastructure- and policy-as-code, create onboarding guidance, deploy automated security posture validation, and participate in threat modeling exercises." - Senior Director, Cyber Security
What You’ll Contribute
Collaborate between Cybersecurity, DevOps, and Development teams to achieve alignment between security and business objectives.
Construct contextual security requirements for vendor tools and integrated systems.
Develop vendor tool secure onboarding guidance for system administrators and users.
Design and implement AWS based solutions using Terraform for automated Health Checks for security posture validation.
Actively participate in security review and threat modeling exercises to identify risks.
Provide technical guidance to development teams on security best practices, security architecture, and security controls.
Integrate Application and DevOps processes with CI/CD pipelines of the software development lifecycle.
Build CI/CD pipelines with Jenkins MPL and GitHub Actions for Security Artifacts.
Leverage orchestration systems including Docker and Kubernetes to deliver security services.
Integrate software service tools (Jenkins, jFrog Artifactory) into automation for security services.
Evaluate and on-board security tools and/or scanners into the Security DevOps lifecycle for multiple tech stacks.
Remediate code- and dependency-level security findings in partnership with product development teams.
Introduce and enhance Continuous Monitoring (Cloud Architecture, App Performance and Logs) for security services.
Evaluate the stability, compatibility, scalability, interoperability, and performance of software products.
Contribute feature enhancements to internally developed Cybersecurity tools.
Integrate Cybersecurity tools into the Security DevOps pipelines.
Drive continuous improvement to both the Security DevOps pipelines, and to the Cybersecurity tools, services, and processes.
Create and share practical demonstrations of proposed solutions.
Mentor and train other engineers and support knowledge sharing.
Drive technical discussions and serve as a source of technical expertise.
What We’re Seeking
Strong knowledge of programming, architecture, CI/CD, and automation.
Solid experience with AWS API, EKS, and Terraform.
Strong understanding and hands-on experience building CI/CD ecosystems to meet the demands of agile and secure development.
Extensive a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s