Description:
Protecting a continuously evolving, multi-tenant SaaS platform requires security decisions that distinguish genuine customer risk from an increasing volume of automated findings. As a Principal Cloud Application Security Engineer in Genesys Cloud Product Security, you will shape how application security scales across cloud accounts, regions, APIs, applications, distributed services, software supply chains, and AI-powered product capabilities.
You will own the technical direction of a small Application Security team while remaining hands-on with complex security analysis, detection engineering, vulnerability triage, and cloud security. Your work will determine where security coverage needs to deepen, which findings represent meaningful exploitability, and how specialist engineering capacity is focused on risks that could affect customer data, tenant isolation, platform integrity, or service security.
AI-assisted development and security analysis are changing both the speed of software delivery and the volume of potential vulnerabilities that security teams must evaluate. You will define how Genesys uses AI and automation to improve vulnerability triage, identify gaps across source code and security tooling, reduce false positives, and establish appropriate human validation for security decisions where context and judgment remain essential.
Genesys Cloud primarily runs on AWS, and you will apply deep cloud security expertise to reason across identity, attack paths, infrastructure exposure, application behavior, and distributed architectures at enterprise scale. This Principal-level individual contributor role provides visibility across enterprise security initiatives, close partnership with engineering and senior leaders, and the opportunity to influence how application and cloud security capabilities evolve as the Genesys Cloud platform and its AI capabilities expand.
Key Responsibilities:
Lead the technical direction of a small Application Security team, strengthening engineering judgment, security standards, and team capability through hands-on leadership and mentoring
Own the end-to-end application security operating model, directing how detection coverage evolves, how increasing finding volume is absorbed, and where engineering investment delivers the greatest reduction in exploitable risk
Drive scalable detection coverage across SAST, SCA, DAST, secrets scanning, mobile application security testing, cloud security posture management, and emerging security capabilities, partnering with security teams to shape tool selection, configuration, tuning, and rule sets
Expand security visibility across web applications, APIs, mobile applications, cloud environments, AI-powered product capabilities, and software supply chains to identify systemic risks and coverage gaps that individual tools cannot reveal
Establish meaningful security coverage metrics that demonstrate both what testing discovers and how effectively the relevant application and platform attack surface is assessed
Own exploitability assessment across automated findings, bug bounty submissions, customer penetration tests, internal assessments, and AI-generated analysis, evaluating reachability, tenant isolation, customer data exposure, affected assets, and blast radius
Drive consistent and defensible vulnerability decisions through evidence, reproduction, severity rationale, triage runbooks, validation checklists, and known-issue patterns that separate exploitable vulnerabilities from false positives, duplicates, theoretical findings, and accepted risk
Lead investigation and escalation of high-risk application and cloud security issues, including cross-tenant access, authentication and authorization bypass, sensitive data exposure, production secrets, and externally reachable cloud resources
Develop AI and automation capabilities that increase security team capacity by improving vulnerability triage, analyzing penetration-test-style reports, identifying false positives, drafting responses, prioritizing findings requiring specialist judgment, and exposing detection gaps across tools and source code
Define appropriate trust boundaries for AI-assisted security decisions, establishing human validation points and evolving those controls as models, security tooling, attack techniques, and engineering practices change
Strengthen vulnerability intake and tracking across security tools, bug bounty submissions, customer penetration tests, internal assessments, and other detection sources to improve consistency, traceability, and scalability
Coordinate the bug bounty program and customer penetration testing workflows, partnering with Sales, Technical Account Managers, Customer Success Managers, penetration testers, and product teams to validate, communicate, and route security findings effectively
Produce clear, evidence-based security findings, severity decisions, and reusable customer responses that engineering teams, account teams, and customer security stakeholders can act on without additional interpretation
Partner across Product Security, Security Architecture, Security Development, Security Operations, Penetration Testing, DevOps, engineering, and product teams to convert recurring vulnerabilities and security anti-patterns into scalable preventive controls
Influence application security strategy across Genesys Cloud by connecting individual findings, systemic weaknesses, detection gaps, and emerging attack techniques to longer-term platform security priorities
Required Qualifications:
10+ years of relevant experience across application security, product security, penetration testing, vulnerability management, cloud security, or closely related security engineering disciplines, including significant recent depth in web and API security
Demonstrated expertise assessing real-world exploitability across authorization flaws, authentication weaknesses, injection vulnerabilities, SSRF, business logic abuse, sensitive data exposure, and multi-tenant isolation risks
Strong experience implementing, configuring, or tuning application security capabilities such as SAST, SCA, DAST, secrets scanning, mobile application security testing, or cloud security posture management
Proven experience building or materially expanding security detection capabilities, with sound judgment across coverage depth, false positives, operational cost, engineering effort, and security trade-offs
Demonstrated success building automation that improved security team capacity, consistency, coverage, or triage efficiency, combined with the judgment to identify where automated decisions require human oversight
Strong understanding of cloud-hosted, multi-tenant architectures and the ability to reason about attack paths, trust boundaries, identity, authorization, data isolation, and externally exposed services
Strong cloud security experience, preferably with AWS, including security controls, identity, attack paths, infrastructure exposure, and security posture across large-scale cloud environments
Demonstrated technical leadership through formal or informal leadership of a small team, mentoring security engineers, leading complex initiatives, or setting technical direction across multiple contributors
Strong written and verbal communication skills, with the ability to explain exploitability, severity, security findings, and remediation considerations to engineering, product, senior leadership, customer-facing teams, and non-specialist audiences
Proven ability to collaborate across shared areas of ownership with security, engineering, DevOps, and product teams while maintaining clear accountability and productive working relationships
Demonstrated discretion when handling sensitive vulnerability information, customer security findings, researcher communications, and confidential security data
| Organization | Genesys |
| Industry | Engineering |
| Occupational Category | Principal Cloud Application Security Engineer |
| Job Location | Dublin,Ireland |
| Shift Type | Morning |
| Job Type | Full Time |
| Gender | No Preference |
| Career Level | Experienced Professional |
| Experience | 10 Years |
| Posted at | 2026-09-24 10:36 pm |
| Expires on | 2026-11-08 |