Bonterra is a company dedicated to increasing the giving rate as a percentage of GDP through innovative technology. They are seeking a Principal Security Engineer to work closely with development teams on vulnerability remediation and to build AI-powered workflows that enhance security practices.
Responsibilities:
- Report directly to the Head of Application Security
- Build, extend, and operate AI-powered agents and workflows that automate vulnerability remediation tasks
- Drive vulnerabilities to closure by working directly with development teams
- Act as a security champion embedded across Bonterra's engineering organizations, building trust and normalizing secure development practices
- Triage and prioritize findings from SAST, SCA, IaC scanners, filtering noise and surfacing what needs immediate attention
- Integrate security validation into CI/CD pipelines and developer workflows
- Support SOC 2, PCI-DSS, HIPAA, and other audits as needed
Requirements:
- Demonstrated experience building AI agents, LLM-powered workflows, or automated pipelines
- Working knowledge of software vulnerability classes, how CVEs are assessed, and what good remediation looks like
- Understand how software gets built and where security integrates into the development process
- You can translate a security finding into language a developer can act on without a security background
- An extensive track record of building AI agents to solve real operational problems that accelerate outcomes
- Experience with SAST/SCA platforms at an engineering team level
- Prior work building or running a security champion program
- Familiarity with AWS security services or cloud environment security
- Knowledge of application security frameworks -- OWASP Top 10, NIST, CVSS scoring
- Previous software development experience