Principal Security Engineer DevSecOps Lead
DigitalBridge Group, Inc. is a global alternative asset manager focused on investing in, owning, operating, and building digital infrastructure. It serves limited partners, shareholders, corporate borrowers, entrepreneurs, and technology and telecommunications companies.
Funding history
Investors
About DigitalBridge Group, Inc.
DigitalBridge manages investment strategies spanning digital infrastructure equity, core-plus assets, private credit, liquid public-market strategies, and software-defined infrastructure ventures. Its focus includes data centers, cell towers, fiber networks, small cells, edge infrastructure, and related technologies. The firm invests in and actively manages portfolio companies while providing financing and capital solutions to institutional investors, companies, and entrepreneurs.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will design security architecture for SaaS, cloud, and AI-enabled applications. You will build DevSecOps controls, lead vulnerability management and offensive testing, strengthen application and data protections, support security incidents, and mentor senior engineers.
Requirements
- 10+ years in information security
- DevSecOps
- Application security
- SaaS security
- AWS
- Azure
- Vulnerability management
- SAST
- DAST
- SCA
- IaC security
- CSPM
- Container security
- Kubernetes security
- SBOM
- Supply-chain security
- Red teaming
- Offensive security
- Threat modeling
- Secure code review
- Cryptography
- OAuth
- OIDC
- API security
- LLM security
- Prompt injection
- Python
- Go
- Terraform
- CI/CD
Responsibilities
- Own security architecture for SaaS platforms, multi-cloud environments, and AI-enabled applications
- Build and operate DevSecOps controls, including security testing, IaC scanning, supply-chain security, secrets detection, and policy-as-code
- Design and run automated vulnerability management
- Lead application security across the software development lifecycle
- Direct red-team, adversarial-testing, and purple-team exercises
- Harden multi-tenant isolation, identity, and data protection
- Set security-by-design controls for AI-enabled applications
- Partner on identity, secrets, network segmentation, logging, and incident response
- Participate in on-call for security incidents
- Mentor senior engineers and contribute to executive and board risk reporting
