Principal Security Engineer, Secure Posture Management

Autodesk Autodesk · Enterprise · Croatia, EMEA

Autodesk is seeking a Principal Security Engineer to lead secure configuration and hardening efforts within their Secure Posture Management team. The role involves designing, implementing, and advancing the company's strategy for secure configurations, cloud hardening, IaC security, vulnerability visibility, and golden image pipelines. This requires deep technical expertise, automation skills, and the ability to influence engineering teams. The engineer will ensure systems meet high security standards and align with industry best practices and regulatory requirements.

What you'd actually do

  1. Define and execute a unified security posture management strategy including CSPM, secure configuration, golden image pipelines, IaC templates, and vulnerability management.
  2. Develop and refine standards for secure cloud configurations in alignment with industry frameworks, such as CIS or NIST benchmarks.
  3. Develop and maintain hardened baselines (CIS, NIST) across cloud environments, Windows, Linux, and container platforms.
  4. Develop security artifacts, tooling and automations using tools such as Python, PowerShell, Groovy or Ruby.
  5. Use Cloud Security Posture Management (CSPM) tooling to continuously monitor multiple cloud environments (AWS, Azure, GCP) for misconfigurations, security gaps and compliance issues.

Skills

Required

  • 8+ years of experience in information security or development
  • focus on secure configuration, enterprise security, cloud security, posture management, and vulnerability management
  • Deep understanding of secure configuration and hardening frameworks, such as CIS Benchmarks, DISA STIG, NIST 800-53/190
  • Strong proficiency in development, building automation and security tooling, such as Git, Artifactory, Jenkins, Spinnaker, scripting languages such as Python, PowerShell, Groovy or Ruby
  • Extensive experience with CSPM tools and secure configuration tools and platforms such as Tenable, Prisma Cloud, Orca, or Wiz
  • Experience in developing/managing golden image pipelines, CI/CD and IaC templates (Terraform)
  • Hands-on experience with cloud providers, AWS, Azure or GCP, and strong knowledge of native security services

Nice to have

  • Master's degree in computer science, information security, or a related field
  • Certifications such as CISSP, CCSP, OSCP, AWS Security Specialty, or similar
  • Hands-on experience across multiple cloud platforms: AWS, Azure, and GCP
  • Expertise in secure software development, API automation, and integrating security checks into CI/CD pipelines
  • Ability to design and deliver complex security automation at scale (IaC modules, policy-as-code, cloud guardrails)
  • Strong understanding of compliance frameworks (SOC2, ISO 27001, FedRAMP, PCI-DSS) as they relate to configuration and vulnerability management
  • Proven ability to identify potential threats and vulnerabilities
  • Ability to lead complex security projects, with hands-on experience to create and develop systems and services

What the JD emphasized

  • secure configuration
  • cloud hardening
  • IaC security
  • vulnerability visibility
  • golden image pipelines
  • secure configuration
  • cloud hardening
  • CSPM
  • secure configuration
  • golden image
  • IaC
  • secure configurations
  • security standards
  • security posture management
  • secure software development
  • security automation
  • policy-as-code
  • cloud guardrails
  • compliance frameworks