Senior Security Engineer
Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.
About the job
Responsibilities
- Execute a product security strategy aligned with company goals and risk appetite.
- Build and operate security automation across code, infrastructure, and CI/CD, including agents, services, and pipelines for detecting, preventing, and remediating risks.
- Design SDLC security automation for code scanning, dependency risk management, secrets detection, and policy-as-code.
- Perform manual security design and implementation reviews of products and services.
- Establish secure development standards covering API security, security patterns, and infrastructure as code.
- Serve as a subject-matter expert for AI and LLM security; lead threat modeling for novel AI systems.
- Continuously test, fuzz, and validate products and platform components for security issues.
- Perform penetration testing and retesting to validate fixes.
- Triage security researcher findings and lead PSIRT incident response and product security events.
- Partner with engineering, product, and platform teams on secure-by-design patterns, threat modeling, vulnerability remediation, and developer guardrails.
- Develop software supply-chain protections, including SBOM generation and verification, artifact signing and attestation, and provenance enforcement.
- Build static and dynamic analysis automation and reusable security frameworks.
- Use telemetry to measure control effectiveness and build dashboards and alerts.
- Document runbooks and APIs, mentor engineers, and promote secure engineering practices.
- Stay current on security threats, vulnerabilities, and industry practices.
Requirements
- 5+ years of experience finding security vulnerabilities, conducting security code reviews, and applying secure coding practices.
- 2–4 years of experience with threat modeling and identifying design flaws from technical architectures and data-flow diagrams.
- Experience exploiting common security vulnerabilities.
- Deep knowledge of web and mobile application security, common vulnerabilities, exploit mitigations, and secure architecture patterns.
- Experience integrating or building AI-powered tools for vulnerability detection, code review, or threat modeling.
- Experience creating software and automation that enables security processes, including AI/ML-enabled automation.
- Experience implementing and managing product security tools such as API security, mobile protection, SAST, and runtime scanning.
- Strong understanding of CI/CD pipelines and security tooling for web and mobile applications.
- Hands-on experience with SAST, DAST, IAST, and penetration-testing tools.
- Scripting, automation, and exploit-writing skills.
- Strong understanding of AWS cloud security principles.
- Strong communication and collaboration skills.
Nice to Have
- Fuzzing expertise.
- Ability to turn bespoke security engagements into reusable patterns and reference implementations.
- Security assessment experience for IoT hardware and firmware.
- Contributions to the security community through research, bug bounties, presentations, or blogs.
- Experience in fintech or other regulated industries.
- Startup experience and a curious, adaptable mindset.
Skills
AWS, Kubernetes, Node.js, Kotlin, Java, Go, React, GraphQL, MySQL, Redis, CI/CD, Threat Modeling, SAST, DAST, Penetration Testing
Similar jobs
Security Engineering jobsLeads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.
The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.