Product Security Engineer
Embeds security into product design and development lifecycle by analyzing architectures, conducting threat modeling and assessments, maturing vulnerability management, and guiding developers on secure practices. Requires 5+ years in product/application security with expertise in cloud, containers, and automation tools.
About the job
Responsibilities
- Analyze applications and system architectures from inception to release, identify vulnerabilities, integrate security controls, conduct architecture reviews and threat modeling.
- Conduct regular security assessments and utilize AI-assisted testing on products and systems to identify and mitigate vulnerabilities.
- Assist in maturing vulnerability management program and drive risk-contextualized resolutions, collaborating with development teams.
- Provide continuous guidance and education to developers on secure coding practices, emerging threats, and security best practices.
- Collaborate with incident response teams on security incidents impacting product operations and create remediation suggestions.
- Work with software engineers to mature automated SAST and DAST tooling to secure development frameworks and CI/CD pipelines.
Requirements
- 5+ years of experience as a Security Engineer, Application Security Engineer, or Product Security Engineer in a highly complex, rapidly scaling software organization.
- Proficiency in modern programming languages (Python, TypeScript, etc.), security tools (Burp Suite, OWASP ZAP), modern security protocols and encryption methods.
- Implemented AI to identify, validate, and scale security programs.
- Deep knowledge of container security (Kubernetes), compute constraints, securing ephemeral workloads across AWS, GCP, Azure, and on-premises environments.
- Hands-on experience deploying, tuning, and automating SAST, DAST, and CI/CD pipeline security tools.
- Experience configuring and driving remediation through cloud security platforms.
- Proven experience securing large-scale platform migrations and managing security lifecycles of legacy systems and modern microservices.
Nice to Haves
- Experience in autonomous vehicle, automotive, aerospace, or defense sectors.
- Familiarity with physics-based simulation environments, deterministic computing constraints, or HPC clusters.
- Contributions to open-source security tools, published vulnerability research, or CVEs.
Compensation
- Base salary: $125,000 - $160,000 USD annually.
- Includes equity, comprehensive health/dental/vision/life/disability insurance, 401k with employer match, learning/wellness stipends, paid time off.
Skills
Python, TypeScript, Kubernetes, AWS, GCP, Azure, Burp Suite, Owasp Zap, SAST, DAST, CI/CD, Sast Tooling, Dast Tooling
Similar jobs
Security Engineering jobsDevelops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.