Pigment logo

Pigment

Principal Security Engineer, Product & Infrastructure

Region Restricted

Remote work allowed only within certain countries or regions.

Employer listed it 6 months ago · Added today

Been open since 6 months ago. Long-running listings are sometimes left up after the role is filled.

Salary

Not stated

Location

Timezone

CET ±2

Contract

Full-time

Experience

Lead

Category

Software

This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in France, United Kingdom.

What the employer says

  • Source listing states candidate location: "France, London, remote"

What Nomaders makes of it

  • Applications outside the listed area are usually rejected
  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Join Pigment: The AI Platform Redefining Business Planning

Pigment is the AI-powered business planning and performance management platform built for agility and scale. We connect people, data, and processes in one intuitive, feature-rich solution, empowering every team—from Finance to HR—to build, adapt, and align strategic plans in real time.

Founded in 2019, Pigment is one of the fastest-growing SaaS companies globally. Industry leaders like Unilever, Snowflake, Siemens, and DPD use Pigment daily to make more informed decisions and confidently navigate any scenario.

With a team of 600+ across Paris, London, New York, Toronto, San Francisco and Austin, we've raised nearly $400M from top-tier investors and were named a Visionary in the 2024 Gartner® Magic Quadrant™ for Financial Planning Software.

At Pigment, we take smart risks, celebrate bold ideas, and challenge the status quo—all while working as one team. If you're driven by innovation and ready to make an impact at scale, we’d love to hear from you.

Reporting to the CISO, you'll own the security roadmap for Pigment's product, infrastructure, and CI/CD environment, and you'll build much of it yourself. This is a hands-on role: expect to read code, threat model new services, reproduce and triage vulnerabilities, dig through infrastructure configuration and build the automation that closes gaps. You'll also set direction and bring product and engineering with you, but that influence comes from technical credibility and not process: the engineers you work with will take you seriously because you've been in the same code they have.

The scope is broad: application security, infrastructure security, detection and response, and the assurance work that keeps our certifications standing. You won't be covering it alone. The security team is seven people and growing, with colleagues already owning compliance, governance and security operations, so this role can go deep on product and infrastructure and not be spread too thin across everything. Nobody arrives fluent in all of it: we're looking for real depth in several of these areas and the judgement to grow into the rest.

Key responsibilities include:

Product & Infrastructure Security Design - Design security features into the product itself and strengthen defence-in-depth across the platform. Threat model new services before they ship, and make the architectural calls that are expensive to reverse later.

Security Review & Risk Assessment - Review code, architecture and configuration yourself, and be the person developers and PMs bring problems to early rather than late. Deliver solutions that balance risk against business benefit, and escalate the calls that genuinely need senior arbitration.

Assurance & Testing - Run our assurance programme: internal code, architecture and configuration reviews, red team exercises, and the bug bounty. Own the relationship with third-party auditors, and measure the control KPIs that keep our certifications defensible.

Vulnerability Management - Own vulnerabilities from detection through to verified fix: reproduce them, score and triage them, design or validate the mitigation, and confirm it actually worked. Improve the KPIs that tell you whether the process is holding.

Detection Engineering - Build and improve our detection capability alongside the infrastructure and engineering teams: identify the signals worth collecting, write rules that catch real attacks without drowning us in noise, and build the response playbooks behind them.

Incident Response - Lead security investigations into the production environment end to end, from first signal to root cause, across incidents and fraud. Flag the repetitive work worth automating and the detections worth building, and hand those to the security operations team.

SDLC - Set the technical direction for how engineers at Pigment build securely: guidance, paved paths, and reviews that teach and not just gate. Contribute to company-wide awareness where it counts, but your primary audience is product, engineering and SRE.

Example projects that would fall under your responsibilities (actual examples of recently completed or currently on the roadmap):

Secure the design and development of our AI features, including the MCP Server and Modeler Agent: threat modelling, design reviews, working alongside the engineers building them, and security assessments.

Work out where AI-assisted analysis actually belongs in our pipeline. AI-powered security reviews reason about a diff semantically rather than pattern-matching it, which is genuinely different from classic SAST - but it's not a drop-in replacement, and figuring out the split between AI review, traditional SAST and SCA is an open question we'd like you to answer with evidence rather than vendor claims.

Migrate GitHub to managed identities: provisioning through Okta, retiring personal accounts and long-lived PATs, and moving CI to short-lived OIDC credentials instead of stored keys.

Design agent identity for the MCP Server - delegated access tokens, token exchange, and making sure an agent acting for a user can never exceed what that user could do themselves.

Push least privilege further across production and CI/CD. Better than it was, not where we want it.

For a concrete example: here 's how we built a sandboxed execution environment for LLM-generated code.

Technical Environment

Mostly production, with the occasional internal IT-adjacent project:

Requirements

  • ·You speak English fluently, French is a strong plus
  • ·After a first call with our recruiter, five conversations, around four hours in total, usually over two to three weeks:
  • ·Ways of working (45 min) — how you operate with people, and what draws you to this role specifically.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Pigment, mentioning your remote working experience and working hours (CET ±2).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 22h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $200k to $275k per year · You'll be taken to the employer's careers page.