For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.
AI is reshaping what product security can accomplish, both as a target and as a tool. We're looking for a Principal Security Engineer to own the highest-leverage application security work at Smartsheet: leading threat modeling and product security reviews across a modern SaaS platform used by millions of customers, serving as the team's technical authority on AI security risk, and setting the technical standard for application security practice across the engineering organization.
This is the most senior individual contributor role on the Application Security team. The expectation is not just depth: it is reach. You will engage product and engineering leadership directly, drive security requirements rather than advisory recommendations, and build team capability over time. If you are a security engineer who thinks upstream, builds threat models that generate concrete test scenarios and can translate technical findings into architecture decisions and business outcomes, this role is built for you.
This role reports to the Manager, Application Security and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.
Own threat modeling and product security review as the team's primary upstream capability: build models from architecture and data-flow artifacts, derive concrete abuse cases and test scenarios, and drive security requirements into designs before they ship. Define and lead the product security review service (set the service model, triage criteria, and enforcement posture) and personally execute reviews for high-risk features with documented findings and remediation timelines. Engage product and engineering directly to establish security requirements at the design phase, with the technical credibility to influence architecture decisions.
Define how AI security risk is assessed, monitored, and mitigated across product, engineering, and third-party AI integrations, with recognized depth on the current threat landscape: LLM workflows, agentic pipelines, MCP-based integrations, and attack classes including prompt injection, indirect injection, and tool-calling authorization gaps. Own and evolve the AI-assisted security review capability: evaluate detection value, assess build-vs-buy tradeoffs, and shape toolchain coverage as Smartsheet's AI-integrated product surface scales.
Serve as the technical authority for the AppSec program's SDLC control surface (secure coding guidelines, CI/CD pipeline security strategy, and toolchain direction across SAST, SCA, secrets, and IaC scanning) with the depth to influence tool decisions and resolve standards decisions that span teams without primary operational ownership. Build runbooks, standards, and documentation that create consistency and reduce single-point-of-failure risk as the team scales.
Mentor AppSec team members on threat modeling tradecraft and security review design, and serve as the trusted technical voice with product and engineering leadership, framing risk in terms that move architecture decisions. Your judgment shapes how the team prioritizes and how the broader organization understands and invests in application security.