Product Security Engineer
Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.
What You Will Do
- Partner with product and engineering teams to support security architecture reviews for product features and the GCP environment; facilitate threat modeling and document risks, existing controls, and actionable recommendations.
- Coordinate and support penetration testing engagements by assisting with vendor selection and scoping, establishing rules of engagement, coordinating testing activities, validating findings, supporting severity assessment, and tracking remediation and retesting in collaboration with engineering teams.
- Serve as a GCP security subject matter expert for project teams, advising on secure patterns across networking (VPC, private access, perimeter controls), data protection (KMS, secrets), compute runtimes (GKE, Cloud Run, GCE), CI/CD (Cloud Build, Artifact Registry), and logging and monitoring.
- Support the implementation and ongoing improvement of least-privilege IAM in GCP by advising on role design (custom vs. predefined), service account lifecycle management, workload identity, IAM Conditions, organization and folder policy constraints, and periodic access reviews.
- Assist with triage and routing of product security findings to appropriate engineering owners; help tune detection rules to reduce noise, support severity and SLA definition, and track remediation progress, including documenting justified exceptions.
- Contribute to security guardrails through policy and infrastructure-as-code (e.g., org policies, constraints, reusable Terraform modules, admission or policy controllers) and support integration of pre-merge security checks into CI/CD workflows.
- Develop and maintain practical documentation and runbooks (e.g., design review checklists, IAM standards, exception processes) and deliver targeted enablement sessions for engineers and product managers.
- Provide visibility into progress and risk through metrics and regular status updates to security leadership; proactively surface blockers and suggest options and tradeoffs.
- Coach and mentor engineers and code owners on secure-by-default coding practices and architectural patterns.
What We Are Looking For
- 5–7 years of experience in product security, cloud security engineering, or a related field.
- Strong knowledge of Google Cloud Platform (GCP) services and security best practices, including IAM, networking, data protection, and workload runtimes.
- Hands-on experience with penetration testing coordination, threat modeling, and risk assessment.
- Demonstrated proficiency in Python and cloud-native programming or scripting languages to design and maintain security automation, policy enforcement, and continuous compliance controls using Infrastructure as Code.
- Familiarity with designing and enforcing least-privilege IAM and conducting access reviews.
- Ability to communicate security risks and recommendations clearly to engineering and leadership audiences.
Senior Product Security Engineer II
Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.
Senior Security Engineer, GRC
Senior GRC engineer owning customer security questionnaires, compliance automation, risk assessments, and policy management across SOC 2, ISO 27001, and HIPAA. Requires 8+ years experience, scripting skills, and strong customer-facing communication.
Senior Security Engineer
Senior Security Engineer building and scaling security platforms, AI/LLM security controls, detections-as-code, and automation across cloud and SaaS environments. Requires 5+ years hands-on security engineering experience and strong Python/cloud skills.
Senior Security Engineer - Data Security
Senior Security Engineer building and scaling data protection platforms, DLP, DSPM, and AI-driven automation across SaaS, cloud, and data warehouse environments. Requires 5+ years in security engineering and strong software engineering skills.