or apply directly on Smartsheet's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 22 days Smartsheet's roles stay open a median of 45 days
- Reposted
- No
- Salary listed
- No 0% of Smartsheet's roles list one
- Ghost-job risk at Smartsheet
- high 45 stale, 5 reposted of 89 open
- Hiring momentum
- 162 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from Smartsheet's own greenhouse board since 2026-08-03. Full hiring picture for Smartsheet.
About this role
The Principal Security Engineer at Smartsheet will lead application security efforts, focusing on threat modeling and product security reviews for a modern SaaS platform. This role involves defining AI security methodologies, shaping application security practices, and mentoring team members while engaging with product and engineering leadership to drive security requirements. The position requires a deep understanding of application security, particularly in the context of AI-integrated applications, and the ability to influence architectural decisions.
- benefits
- 5/5
- freshness
- 4/5
- career value
- 5/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Smartsheet as an employer.
What you need
- 10+ years in application security with a track record of sustained technical leadership in product security or AppSec engineering
- Ability to own threat modeling as a systematic practice, producing actionable test scenarios and abuse cases
- Hands-on experience securing AI-integrated applications with fluency in the OWASP LLM Top 10 and current AI attack classes
- Experience doing architecture review and targeted manual code review for complex SaaS features
- Experience mentoring engineers into threat modeling ownership and establishing security requirements as design-phase gates
- Sufficient depth in SAST, SCA, secrets, and IaC scanning in modern CI/CD pipelines
Nice to have
- GitLab CI/CD experience
- Experience building AI-assisted security tooling or LLM-integrated review workflows
- Penetration testing depth including exploit writing or vulnerability chaining
- Public-facing security contributions such as conference speaking or published research
What you get
- Employer subsidized medical/vision and dental coverage for full-time employees
- 401k Match
- Monthly stipend to support work and productivity
- Flexible Time Away Program, plus Sick Time Off
- Life insurance, short-term, and long-term disability plans
- 12 paid holidays per year
Worth weighing
- No specific mention of the tech stack beyond modern SaaS and AI integrations
- Role is remote-friendly but requires legal eligibility to work in the U.S.
- No salary listed for specific locations, only a range provided
Summarised from Smartsheet's posting. Read the full original.
Listed by Smartsheet on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at Smartsheet
- Strategic Account ExecutiveMunich, DE
- Senior Product Manager II - Applied AI (Remote Eligible)-REMOTE, USA-
- Principal Partner Enablement Manager, APJSydney, AU
- Account Executive, Commercial - Mid Market (West)Bellevue, WA, USA
- Marketing Platform Operations Manager-REMOTE, USA-
- Account Executive, Commercial - Mid Market (West)San Francisco, CA, USA
- Partner Enablement Manager (Remote Eligible - Costa Rica)San Jose, CR
- Software Engineer - Mobile (Remote Eligible in Bulgaria)-REMOTE, BULGARIA-