Principal Security Engineer (DRI)
Company: TaxDome
Employment type: FULL_TIME
About TaxDome
At TaxDome, we’re building the #1 practice management platform for accounting firms in the US and globally. Founded in 2017, we’ve grown into a 400+ fully remote team across 40+ countries, serving tens of thousands of businesses worldwide with millions of end clients.
How we work
You’ll be part of a globally distributed team built on trust, ownership, and self-management. We focus on outcomes over activity — prioritizing clear ownership, pragmatic decision-making, and accountability for results over rigid processes. Collaboration is central to how we operate: we communicate openly, involve the right people early, and continuously improve how we build products and teams together.
About this role
We’re looking for a Principal Security Engineer (DRI) to join our Engineering organization and own application security across TaxDome’s platform during our AI-first engineering transformation. In this role, you’ll define and build the security model for AI-generated software delivery, embed security into product development and release gates, and directly impact product safety, platform resilience, and customer trust. It’s a fully remote role, we are hiring across European timezones.
What you’ll be responsible for
- Own and drive the Application Security workstream as the security DRI across all Domains and Pods.
- Build automated security controls across the delivery loop, including secret scanning, SAST, SCA, IaC, container, dependency, and DAST gates.
- Embed security into product discovery, threat modeling, acceptance criteria, and architecture decisions.
- Define controls for AI-generated code, including dependency risk, tenant isolation, prompt injection, agent misuse, and risky migrations.
- Own the security reviewer AI agent and improve its detection quality, escalation logic, and coverage.
- Partner on incident response, supply chain security, secrets management, and compliance-related technical controls.
- Raise security maturity through practical guidance, reusable rules, and developer education.
What you bring
Must-have
- 7+ years in Application/Product Security, including senior IC ownership at Staff/Principal level or equivalent.
- Experience securing multi-tenant SaaS products handling sensitive or regulated data.
- Strong hands-on background in DevSecOps and CI/CD security automation.
- Practical experience with AI/LLM security risks and controls.
- Ability to review code and work closely with engineering across modern backend/platform stacks.
- Strong written communication and ability to drive security through influence and clear ownership.
Nice-to-have
- Experience leading security through major engineering transformations such as AI-first, cloud, microservices, or platform-scale change.
- Background in fintech, tax, payments, or other heavily regulated environments.
- Experience building or operating security-focused AI agents in production.
- Strong AWS/GCP, Kubernetes, and cloud/runtime security expertise.
What we offer
At TaxDome, we aim to create an environment where people can do their best work and grow alongside the company.
- Competitive compensation, paid in USD
- Fully remote work with flexible hours
- 30 paid days off annually, plus sick days as needed
- Health & well-being support
- Learning & development budget to support your professional growth
- English lessons reimbursement
- Co-working space reimbursement
- Company-provided equipment (conditions may vary depending on the role)
- A high level of autonomy and ownership in your work
- The opportunity to make a real impact in a fast-growing global SaaS company
- A collaborative, international team with a strong product mindset