Job Description
Chewy is seeking a hands-on Principal Cybersecurity Engineer to join our technology organization in Boston, MA, or Plantation, FL. This role is for a senior technical leader who actively designs, builds, reviews, and evolves security capabilities across large-scale cloud-native systems-not a purely advisory or compliance-focused position. As a Principal Cybersecurity Engineer, you will operate at the intersection of architecture, engineering, and execution, owning critical security domains and influencing security outcomes across dozens of teams. You will work deeply within AWS-based platforms, Kubernetes, EKS, and data services, setting technical direction while remaining directly engaged in solving complex security engineering problems. This role requires sustained hands-on technical contribution, deep system-level thinking, and the ability to lead through influence in a fast-moving, high-scale e-commerce environment.
What Youll Do
• Design, review, and contribute to security architectures and implementations across cloud application, data, and platform layers. • Own and evolve core security engineering capabilities, such as cloud security patterns, workload identity, network segmentation, secrets management, data protection, from design through production. • Develop and maintain threat models, security requirements, and architectural guardrails for distributed systems running on public clouds. • Partner directly with engineering teams to embed security into system design and code, not as an after-the-fact review function. • Define and implement secure-by-default patterns that teams can adopt without centralized friction. • Lead technical decision-making for high-risk, high-impact security tradeoffs, including incident learnings and architectural remediation. • Build and refine security engineering standards, reference architectures, and reusable components, and actively ensure they are implemented correctly. • Diagnose and resolve the most complex security failures and design flaws in production systems. • Establish measurable security outcomes, not just controls, and track progress against them. • Mentor engineers by reviewing designs, code, and implementations, raising the bar through direct technical engagement. • Influence hiring by setting clear expectations for senior and principal-level engineering excellence and participating directly in interview loops.
What Youll Need
• Bachelors degree or equivalent practical experience in computer science or engineering. • 15+ years of engineering experience with substantial hands-on work in cybersecurity engineering and architecture. • Demonstrated experience building and operating security controls in production, not just designing or recommending them. • Deep practical expertise in securing AWS environments, including IAM, networking, compute, and managed data services. • Strong hands-on experience with Kubernetes, EKS, security, including pod, workload, identity, network policies, and runtime controls. • Proven experience securing distributed data systems, including DynamoDB and PostgreSQL-based platforms. • Ability to read, review, and meaningfully influence production code and infrastructure-as-code. • Track record of owning security outcomes across multiple teams through influence, rather than direct authority. • Experience turning ambiguous risk and business requirements into concrete technical designs and implementations. • Strong written and verbal communication skills, with the ability to explain complex technical decisions to senior engineers and leadership. • Comfortable operating in environments with incomplete information, evolving requirements, and real operational risk.
Bonus (if applicable)
• Prior experience securing high-scale e-commerce or consumer-facing platforms. • Experience building self-service security platforms or guardrails used by multiple engineering teams. • Strong infrastructure-as-code background, such as Terraform, with security-first design. • Experience integrating security into CICD pipelines and developer workflows. • History of leading or significantly contributing to post-incident architectural improvements.
Salary and Benefits
The base salary range for this role is $137,500 - $245,000. The specific salary offered to a candidate may be influenced by various factors, including relevant experience, education, and work location. This position is eligible for 401(k) and a new hire and annual equity grant. C08 positions may also be eligible for an annual bonus.
We offer a range of insurance and benefits, including:
• Medical, Rx, vision, dental, life, disability, hospital, indemnity, critical illness, and accident insurance. • Parental leave, family services, benefits, backup dependent care, flexible spending accounts, telemedicine, pet adoption reimbursement, employee assistance program, and many discounts, including 10% off pet insurance and 20% off at Chewy.com.
Exempt salary team members have unlimited PTO, subject to manager approval. Team members will receive six paid holidays per year. Team members may be eligible for paid sick and family leave in compliance with applicable state and local regulations.
Chewy is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, ancestry, national origin, gender, citizenship, marital status, religion, age, disability, gender identity, results of genetic testing, veteran status, or any other legally protected characteristic. If you have a disability under the Americans with Disabilities Act or similar law and need an accommodation during the application process or to perform these job requirements, or if you need a religious accommodation, please contact CAAR@chewy.com.
To access Chewys California CPRA Job Applicant Privacy Policy, please click here: https://chewyinc.phenompro.com/us/privacy-policy.