Senior Product Security Engineer
Senior Product Security Engineer who partners with developers to secure web applications and APIs throughout the SDLC. The role leads threat modeling, security reviews, penetration testing, secure code review, and security-tooling programs.
About the job
Responsibilities
- Partner with developers throughout the software development lifecycle (SDLC) to embed security early.
- Lead security design and architecture reviews and perform threat modeling for new features and services.
- Conduct hands-on penetration testing of web applications and APIs; translate findings into prioritized remediation work.
- Perform secure code reviews and help define secure-coding standards and security acceptance criteria.
- Operate and tune SAST, DAST, dependency, and software supply-chain scanning; triage findings.
- Explain security risks to developers and help prevent recurring issue classes.
- Contribute security evidence and rigor to compliance programs such as SOC 2 and ISO 27001.
Requirements
- Strong track record in product or application security.
- Hands-on penetration testing experience against web applications and APIs.
- Deep understanding of modern web applications, including single-page applications, APIs, authentication and authorization, OAuth 2.0, OpenID Connect, sessions, and OWASP Top 10 risks.
- Experience with security design reviews and threat modeling.
- Solid understanding of the SDLC and integrating security into development processes.
- Strong communication skills and ability to work directly with developers.
Nice-to-haves
- Familiarity with OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy, Grype, and Nuclei.
- Offensive-security certification such as OSCP.
- Cloud security experience with Amazon Web Services, Microsoft Azure, or Google Cloud Platform.
- Container and Kubernetes security experience.
- Experience supporting SOC 2, ISO 27001, or similar compliance programs.
- Background in enterprise or regulated environments.
Compensation
- ATS-listed salary range: 50,000–60,000 (currency not specified).
Skills
Application Security, Penetration Testing, Threat Modeling, Secure Code Review, SAST, DAST, Owasp Top 10, Oauth 2.0, Openid Connect, Burp Suite, Semgrep, Kubernetes, Cloud Security, Oscp, ISO 27001
Similar jobs
Security Engineering jobsThe Technical GRC Analyst evaluates technical controls, validates evidence, performs risk assessments, and advances AI governance, compliance automation, and assurance reporting. The role requires 8+ years in technical security, Security GRC, or regulatory compliance, with cloud and enterprise technology experience.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.