Principal Security Engineer

Zillow Zillow · Consumer · United States · Remote

This Principal Security Engineer role focuses on embedding security into Zillow's applications, cloud environments, and AI-enabled systems. The role involves leading security assessments, identifying vulnerabilities, strengthening cloud security, and driving AI security initiatives by establishing guardrails and secure design patterns for AI systems. It also includes assessing AI-specific risks like data exposure and model abuse, and improving AI security tooling.

What you'd actually do

  1. Lead security assessments for high-impact applications and services, including threat modeling, secure design reviews, and penetration testing.
  2. Identify, validate, and prioritize complex vulnerabilities across web applications, APIs, and cloud-native services, and partner with engineers to drive secure-by-default outcomes.
  3. Drive AI security initiatives by establishing guardrails, review practices, and secure design patterns for AI-enabled features and systems.
  4. Assess AI-specific risks, including data exposure, misuse, model abuse, prompt-based attacks, and unintended system behavior.
  5. Develop and promote scalable application and AI security standards, best practices, and guardrails across teams.

Skills

Required

  • 7+ years of security engineering experience
  • strong experience in application security
  • ownership of complex security outcomes
  • experience driving or owning AI security initiatives
  • assessing or mitigating risks in AI- or LLM-enabled systems
  • leading advanced security assessments across modern applications, cloud infrastructure, and AI-enabled systems
  • strong understanding of common vulnerability classes
  • secure software development practices
  • threat modeling
  • hands-on experience securing cloud-native environments, especially AWS
  • designing secure system or cloud architectures
  • read, write, and review code in at least one modern programming language
  • communicate security risks clearly to both technical and non-technical partners
  • influence decisions without formal authority
  • experience mentoring engineers

Nice to have

  • exposure to GCP and Azure

What the JD emphasized

  • AI security initiatives
  • AI-enabled systems
  • AI-specific risks
  • AI security standards

Other signals

  • AI security initiatives
  • guardrails for AI
  • assess AI-specific risks
  • secure design patterns for AI-enabled features