Principal Security Engineer
Ethoslife · Bangalore, India · 2026-06-24
About this role
<div class="content-intro"><h3><strong>About Ethos</strong></h3> <p>Ethos is a leading life insurance technology company on a mission to protect families by democratizing access to life insurance and empowering agents at scale. With its robust three-sided technology platform, Ethos is transforming the life insurance experience for consumers, agents, and carriers alike. Ethos offers instant, accessible products and a seamless online process that requires no medical exams and just a few health questions; it eliminates traditional barriers, making it easier than ever for everyone to protect their families. Ethos is redefining how life insurance is bought, sold, and underwritten.</p></div><h3><strong>About the Role</strong></h3> <p>We’re seeking a <strong>Principal Security Engineer</strong> with deep expertise in <strong>application security, AI security,</strong> and <strong>security architecture</strong> to join our growing security team. This role reports directly to the CISO. You’ll lead the design and implementation of scalable, secure systems across cloud platforms and modern application stacks — including AI-powered tooling — guiding both strategic security initiatives and day-to-day security engineering operations.</p> <p>This is a high-impact role that will shape the security posture of our platforms and development practices, working across engineering, DevOps, architecture, and compliance teams.</p> <h3><strong>Responsibilities</strong></h3> <p><strong>Core Security Engineering</strong></p> <ul> <li>Design and implement secure architectures for applications, APIs, microservices, and containerized workloads.</li> <li>Develop and enforce application security best practices across SDLC; partner with DevOps and engineering teams to integrate security into CI/CD pipelines.</li> <li>Conduct threat modeling, security design reviews, and risk assessments for new and existing systems.</li> <li>Evaluate and implement security tools, controls, and frameworks</li> <li>Provide technical leadership and mentorship to security engineers, software developers, and DevOps personnel.</li> <li>Lead response to complex security incidents or architectural flaws; conduct root cause analysis and recommend strategic remediations.</li> <li>Contribute to and influence security policies, standards, and governance.</li> <li>Stay current with emerging threats, vulnerabilities, and security technologies, advising stakeholders on evolving risks and mitigations.</li> </ul> <p><strong>AI Security</strong></p> <ul> <li>Own the AI security program, including risk frameworks, threat models, and governance policies for AI/ML systems and LLM integrations.</li> <li>Review new AI tool features and model updates for security risks prior to adoption, covering prompt injection, data leakage, model poisoning, and supply chain threats.</li> <li>Track and apply industry guidance from NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, and CISA; translate standards into actionable internal controls and secure configuration baselines.</li> <li>Embed AI security reviews into the feature development lifecycle, including pre-deployment red-teaming and adversarial testing of AI-powered features.</li> <li>Monitor AI regulatory developments and advise on security and compliance implications for the organisation.</li> </ul> <p><strong>Requirements</strong></p> <p><strong>Required Qualifications</strong></p> <ul> <li>10+ years of experience in security engineering or architecture roles.</li> <li>Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field from a reputable institution.</li> <li>Deep expertise in cloud platforms (particularly AWS), including infrastructure-as-code (e.g., Terraform, CloudFormation).</li> <li>Strong experience in secure software development and application security (e.g., OWASP Top 10, SAST, DAST, threat modeling).</li> <li>Experience designing and implementing zero-trust architectures, secure API gateways, and identity/access controls.</li> <li>Proficient in scripting or development languages (e.g., Python, Go, JavaScript) and secure coding practices.</li> <li>Demonstrated leadership in cross-functional security initiatives and technical mentorship.</li> <li>Hands-on experience assessing security risks of AI/ML systems, including familiarity with OWASP LLM Top 10, MITRE ATLAS, or NIST AI RMF.</li> <li>Demonstrated ability to evaluate new AI tool features and vendor releases for security implications, and to produce clear risk assessments and secure configuration guidance.</li> <li>Experience researching and applying industry security guidance, translating standards and frameworks into organisational controls and policies.</li> </ul> <p><strong>Preferred Qualifications</strong></p> <ul> <li>Certifications such as CISSP, CCSP, AWS Security Specialty, GIAC (GCSA, GWEB, GDSA).</li> <li>Familiarity with Kubernetes security, service mesh, and cloud-native security tooling.</li> <li>Experience in regulated industries (e.g., fintech, healthcare, SaaS at scale).</li> <li>Experience with AI red-teaming, adversarial ML, or LLM security assessment tooling.</li> <li>Familiarity with secure configuration benchmarks for AI/ML platforms (e.g., AWS Bedrock).</li> <li>Knowledge of emerging AI regulatory frameworks (e.g., EU AI Act, NIST AI…
Skills asked for
- devops
- microservices
- ci/cd
- llm
- cybersecurity
- aws
- terraform
- python
Similar jobs
- Principal Software Engineer (AI Security)Cyberhaven · Bangalore
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.