# Senior Product Security Engineer

**Company:** [Tessera Labs](https://hotfix.jobs/companies/tessera-labs)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $50k – $60k/yr
**Experience:** 5+ years
**Skills:** Application Security, Penetration Testing, Threat Modeling, Secure Code Review, SAST, DAST, Owasp Top 10, Oauth 2.0, Openid Connect, Burp Suite, Semgrep, Kubernetes, Cloud Security, Oscp, ISO 27001
**Posted:** 2026-09-01

> Senior Product Security Engineer who partners with developers to secure web applications and APIs throughout the SDLC. The role leads threat modeling, security reviews, penetration testing, secure code review, and security-tooling programs.

## Job Description

## Responsibilities
- Partner with developers throughout the software development lifecycle (SDLC) to embed security early.
- Lead security design and architecture reviews and perform threat modeling for new features and services.
- Conduct hands-on penetration testing of web applications and APIs; translate findings into prioritized remediation work.
- Perform secure code reviews and help define secure-coding standards and security acceptance criteria.
- Operate and tune SAST, DAST, dependency, and software supply-chain scanning; triage findings.
- Explain security risks to developers and help prevent recurring issue classes.
- Contribute security evidence and rigor to compliance programs such as SOC 2 and ISO 27001.

## Requirements
- Strong track record in product or application security.
- Hands-on penetration testing experience against web applications and APIs.
- Deep understanding of modern web applications, including single-page applications, APIs, authentication and authorization, OAuth 2.0, OpenID Connect, sessions, and OWASP Top 10 risks.
- Experience with security design reviews and threat modeling.
- Solid understanding of the SDLC and integrating security into development processes.
- Strong communication skills and ability to work directly with developers.

## Nice-to-haves
- Familiarity with OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy, Grype, and Nuclei.
- Offensive-security certification such as OSCP.
- Cloud security experience with Amazon Web Services, Microsoft Azure, or Google Cloud Platform.
- Container and Kubernetes security experience.
- Experience supporting SOC 2, ISO 27001, or similar compliance programs.
- Background in enterprise or regulated environments.

## Compensation
- ATS-listed salary range: 50,000–60,000 (currency not specified).

## Similar jobs

- [Technical GRC Analyst](https://hotfix.jobs/jobs/59eac364-5d69-4af7-a82d-99ebfcf9f7fc) - Tessera Labs - Remote - $50k – $60k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Compliance Engineer](https://hotfix.jobs/jobs/63197ba5-a12d-497a-a0b9-91e5e7050ac1) - Retell AI - Remote - $72k – $90k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/349d94de-bb90-497f-aff4-96221f8c389d
**Canonical:** https://hotfix.jobs/jobs/349d94de-bb90-497f-aff4-96221f8c389d