Principal Product Security Engineer
Senior
Application Security
Application Security Engineering
DevSecOps
Engineer
Product Security
Product Security Engineering
Risk Governance
Risk Management
Sdlc Security Scorecard
Secure Development Lifecycle
Secure Sdlc
Secure Software Development Lifecycle
Security
Security Engineering
Security Standards
Security Standards And Frameworks
Security Testing
Software Security
Software Supply Chain Security
Job Description
Navy Federal Credit Union is seeking a senior individual contributor to define and integrate Secure Software Development Lifecycle (Secure SDLC) practices into software delivery workflows. This onsite role in Winchester, VA focuses on improving risk-informed release decisions, reducing security friction for engineering teams, and strengthening product integrity across the full lifecycle.
What you’ll do
- Define and mature Secure SDLC practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.
- Own and support a pre-production product security scorecard to enable risk-informed release decisions, communicating product security posture, open risks, exceptions, and required remediation actions to business and technology stakeholders.
- Act as the integration lead for embedding Secure Development Practice capabilities into engineering workflows, governance forums, and lifecycle activities.
- Map product security activities across software delivery, including intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.
- Create repeatable process patterns for integrating threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling into day-to-day engineering work.
- Reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy process steps that do not align with Navy Federal delivery practices.
- Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.
- Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.
- Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development practices with enterprise delivery processes.
- Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.
- Recommend process improvements that strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.
- Establish adoption and effectiveness measures to demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.
- Lead cross-functional working sessions and develop executive-ready recommendations, influencing process decisions across security and engineering stakeholders without direct authority.
What you bring
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.
- Experience defining, improving, or integrating secure development lifecycle practices into enterprise software delivery processes.
- Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.
- Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.
- Demonstrated experience developing process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.
- Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.
- Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.
Frameworks and tools you’ll work with
- Secure Software Development Lifecycle
- Threat modeling, secure coding, application security testing
- Software composition analysis, API security, software supply chain security
- Vulnerability management, DevSecOps
- NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework
- Agile, SAFe, DevOps, CI/CD, product-oriented delivery
- Architecture governance, release management
- CISSP, CISM, CSSLP, CCSP, GIAC
Desired qualifications
- Extensive hands-on experience in application security, secure SDLC, software engineering, DevSecOps, enterprise architecture, technology risk, or software delivery governance.
- Strong understanding of software delivery practices including Agile, SAFe, DevOps, DevSecOps, CI/CD, product-oriented delivery, architecture governance, and release management.
- Advanced degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, Business Administration, or related field.
- Experience with industry frameworks or models such as NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework, or similar security and software assurance practices.
- CISSP, CISM, CSSLP, CCSP, GIAC, cloud security, architecture, Agile, SAFe, or related professional certifications.
Schedule and location
Hours: Monday - Friday, 8:00AM - 4:30PM
Onsite locations: 820 Follin Lane, Vienna, VA 22180; 5510 Heritage Oaks Drive, Pensacola, FL 32526; 141 Security Drive, Winchester, VA 22602
Compliance
Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.