Procore Technologies · 3 days ago
Principal Security Engineer
Procore Technologies is seeking a Principal Security Engineer to join their Security Engineering team. In this role, you will be responsible for designing and implementing security controls that protect the platform and users, while partnering with various teams to embed security into the development lifecycle.
ConstructionInternetSaaSSoftware
Responsibilities
Design and implement scalable IAM guardrails for cloud (AWS/GCP/Azure) and corporate (Okta) environments, including identity governance, PAM, and service-to-service authentication
Architect, build, and deploy automated pipelines for authoritative asset inventory and Software Bill of Materials (SBOM) generation
Lead the technical strategy and roadmap for data protection, including key management (KMS), encryption-at-rest/in-transit, and tokenization
Develop and enforce secure-by-default configurations for our containerized (Kubernetes, EKS) and IaC (Terraform) workflows
Partner with product engineering teams to perform threat modeling, conduct secure code reviews, and integrate automated security testing (SAST/DAST/SCA) into the CI/CD pipelines
Mentor junior engineers and act as a force multiplier, scaling security knowledge and best practices across all of engineering
Drive the selection and implementation of new security technologies and platforms from proof-of-concept to production
Partner with Product & Technology teams to engineer technical resilience patterns, auto-healing systems, and verifiable disaster recovery capabilities
Serve as the key technical expert to provide authoritative context on security controls and designs to our GRC and Internal Audit teams
Provide on-call support on a rotational basis
Qualification
Required
Bachelor's degree in Computer Science or equivalent practical experience
8+ years of experience in a hands-on technical security role, with at least 4 years focused on cloud security in a large-scale environment
Expert-level knowledge in multiple security domains including product/application security, IAM, IaaS, network, endpoint, etc
Expert-level knowledge of at least one major cloud provider (AWS preferred) and its security services (IAM, KMS, Security Hub, GuardDuty)
Deep experience with identity and access management platforms (IdP, IGA, PAM), joiner-mover-leaver (JML) mechanisms, and concepts (SAML, OAuth 2.0, OIDC, SCIM)
Proven experience building security guardrails for IaC (Terraform), CI/CD pipelines, and container orchestration (Kubernetes)
Strategic vision to align security initiatives with business growth and product velocity
Mastery of assessing third-party/M&A product risk and integrating diverse tech stacks securely
Strong understanding of data protection principles, including encryption, key management, tokenization, and data loss prevention (DLP)
A 'builder' mindset with a passion for automation (Python, Go, or similar) and shipping solutions as code
Excellent communication skills with the ability to translate complex technical concepts for non-technical stakeholders and executive leadership
Benefits
Equity Compensation
Company
Procore Technologies
Procore Technologies, Inc. (NYSE: PCOR) is a leading technology partner for every stage of construction.
H1B Sponsorship
Procore Technologies has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (37)
2024 (45)
2023 (35)
2022 (51)
2021 (43)
2020 (14)
Funding
Current Stage
Public CompanyTotal Funding
$654.02MKey Investors
12 West CapitalGlobal Secure InvestD1 Capital Partners
2023-09-21Post Ipo Secondary· $4.07M
2021-05-20IPO
2020-07-10Secondary Market
Leadership Team
Recent News
Crunchbase News
2026-01-08
Company data provided by crunchbase