Principal Security Engineer
Coos Bay, Coos County, Oregon, 97458, USA
Listed on 2026-01-16
-
IT/Tech
Systems Engineer, Cybersecurity
About the team
The Application Security team at Zillow partners closely with engineering, platform, and product teams to embed security throughout the software development lifecycle. We play a critical role in strengthening cloud-native architectures and enabling the safe adoption of emerging technologies, such as AI, while supporting fast, reliable innovation across Zillow Group.
About the roleAs a Principal Security Engineer, you will be a senior technical leader responsible for identifying and reducing security risk across Zillow’s applications, cloud environments, and AI-enabled systems. You will drive change through influence, operate effectively in ambiguous spaces, and help shape how security is embedded into our evolving platform. Your work will have a direct impact on the safety and reliability of Zillow’s products and services.
Asa Principal Security Engineer, You Will Get To
Lead application security assessments, including scoping and managing penetration testing, threat modeling, and secure design reviews for high-impact systems.
Identify, validate, and prioritize complex security vulnerabilities across web applications, APIs, and cloud-native services.
Partner with software engineers to embed secure-by-default patterns into application architectures and development workflows.
Influence the security of primarily AWS-based systems, with exposure to GCP and Azure, focusing on identity, networking, data protection, and service integrations.
Drive AI security initiatives by establishing guardrails, patterns, and review practices, and assess AI-specific risks such as data exposure, misuse, and unintended behaviors in AI- and LLM-powered systems.
Develop and promote scalable application and AI security standards, guardrails, and best practices.
Mentor and coach security engineers, raising the technical bar and fostering a culture of security across the team.
Serve as a technical owner for application and AI security tooling, responsible for configuration, integration, and ongoing improvement in partnership with engineering and platform teams.
This role has been categorized as a Remote position. “Remote” employees do not have a permanent corporate office workplace and, instead, work from a physical location of their choice, which must be identified to the Company. U.S. employees may live in any of the 50 United States, with limited exceptions. In California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington state, and Washington DC the standard base pay range for this role is $ - $ annually.
This base pay range is specific to these locations and may not be applicable to other locations. In Colorado, Hawaii, Illinois, Minnesota, Nevada, Ohio, Rhode Island, and Vermont the standard base pay range for this role is $ - $ annually. The base pay range is specific to these locations and may not be applicable to other locations. In addition to a competitive base salary this position is also eligible for equity awards based on factors such as experience, performance and location.
Actual amounts will vary depending on experience, performance and location. Employees in this role will not be paid below the salary threshold for exempt employees in the state where they reside.
Minimum of 7+ years of security engineering experience, including at least 5+ years focused on Application Security or penetration testing.
Demonstrated experience driving or owning AI security initiatives (2+ years), including assessing and mitigating risks in AI- or LLM-enabled systems.
Deep understanding of common vulnerability classes and secure software development practices.
Hands‑on experience securing cloud‑native applications, particularly in AWS environments, and designing secure solutions across modern application and cloud environments.
Ability to read, write, and review code in at least one modern programming language.
Proven experience designing and implementing secure system architectures, including hands‑on threat modeling and security‑driven design decisions.
Experience communicating security risks clearly to both technical and non‑technical partners.
Demonstrated ability to mentor engineers and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).