Principal Engineer
Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense.
The world has fundamentally changed. We are growing from 400 employees into the next phase of our journey, and we need passionate talent filled with empathy and agility. The right candidate for the job is ethical, hyper‑organized, fanatical about seeing things through to completion, service‑oriented, and humble enough to take feedback and coaching yet confident enough to provide feedback and coaching.
AboutThe Role
Menlo Security is seeking a Principal Software Engineer I for the R&D Policy Team. This team owns the full lifecycle of Menlo’s cybersecurity policy platform – the engine that defines how the product protects enterprise customers from web‑based threats. That spans policy storage and management (authoring, versioning, and serving the rules that govern customer security posture), policy distribution (propagating policy changes reliably and at scale to enforcement points globally), and real‑time enforcement (applying policies at traffic inspection time to block, isolate, or allow web activity).
You will architect critical services across this stack, lead cross‑functional initiatives, and help shape how the team builds software in an era where AI is a first‑class engineering tool.
- Architect, design, and own services across the policy platform — from policy storage and versioning APIs, to the distribution pipeline that propagates rule changes to enforcement nodes, to the enforcement layer that applies policies at inspection time with low latency and high availability.
- Evaluate the current state of policy management, distribution, and enforcement; design and lead a seamless modernization of the architecture that eliminates technical debt and scales for the future — without impacting customers or altering enforcement behavior.
- Lead design reviews and gain consensus on architectural decisions within the Policy Team; keep module designs current and sign off on significant code and design changes.
- Champion AI‑assisted development practices (LLM‑based coding assistants, automated test generation) and identify opportunities to embed ML/AI into policy features such as intelligent policy recommendations or anomaly‑based threat detection.
- Own complex projects end‑to‑end — requirements through deployment and monitoring — breaking work into well‑scoped tasks for junior engineers and unblocking teammates to maintain velocity.
- Partner with Product Management, Security, and Operations to align on requirements and schedules; produce accurate estimates and surface risks early.
- Mentor engineers through code reviews and design discussions; contribute to documentation and knowledge transfer across teams.
- 8+ years of hands‑on backend development in Python, Node.js, or Go; 5+ years with cloud platforms (AWS or GCP), including managed Kubernetes (EKS/GKE).
- Proven experience architecting distributed systems with strong reliability, scalability, and low‑latency requirements — ideally in a security, networking, or high‑throughput data path context.
- Hands‑on experience developing, debugging, and troubleshooting backend services in Linux environments; working knowledge of networking fundamentals (TCP/IP, TLS, HTTP/2, DNS, proxying) relevant to policy enforcement work.
- Experience with policy or rules engines, configuration distribution systems, or real‑time traffic inspection is a strong plus.
- Demonstrated experience designing and executing large‑scale data or schema migrations in live production systems — ideally with multi‑tenant, zero‑downtime, and behavioral‑equivalence requirements.
- Proficiency with data storage and analytics technologies such as Redis, Postgre
SQL, MySQL, and Apache Druid or similar OLAP systems. - Hands‑on experience with AI‑assisted development tools (Git Hub Copilot, Cursor, Claude Code, Gemini, or similar) and familiarity with LLM APIs and responsible AI practices in…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: