Senior Product Security Engineer
Skills
About the Role
You will embed security into the design, development, and operation of products and platforms. You will lead security architecture reviews, define security requirements and roadmaps, conduct threat modeling, and assess cloud-based applications. You will mature the secure development lifecycle, integrate automated security testing into CI/CD pipelines, lead application and API security assessments, manage vulnerabilities, and support monitoring and incident response. You will also select security tools, create documentation and training, and provide guidance on securely using AI-assisted development tools.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience
- 5+ years of experience in security engineering, application security, or product-aligned security roles
- Understanding of web, mobile, and API vulnerabilities, including OWASP Top 10
- Experience securing applications and services in a major cloud provider, with AWS preferred
- Experience with application security tooling and CI/CD integration
- Familiarity with Terraform review, GitHub Actions security, and secrets management
- Familiarity with container security, including image hardening, Kubernetes RBAC, network policies, and runtime protection
- Familiarity with securing AI/ML platforms and agentic workflows
- Experience collaborating with software engineering teams in agile environments
- Knowledge of identity, authentication, and authorization technologies including OAuth, OIDC, and SSO
- Communication and stakeholder management skills
Responsibilities
- Lead security design and architecture reviews for web, mobile, and cloud-based applications
- Define product security requirements, risk tolerances, and security roadmaps with product and engineering leadership
- Conduct threat modeling workshops and drive mitigations into product design
- Review security for products and services deployed across AWS, Azure, and GCP
- Own and mature the application and product security lifecycle
- Drive automated security checks in CI/CD pipelines
- Lead application security testing and prioritize remediation findings with development teams
- Establish secure coding standards, patterns, and reusable frameworks
- Lead API security assessments and review API gateway configurations
- Integrate product logs, alerts, and events into monitoring and incident response workflows
- Own vulnerability triage and management for product and application findings
- Ensure sensitive data is handled according to security requirements
- Evaluate and implement product security tools and services
- Develop security documentation, playbooks, and training
- Provide best practices for secure use of AI-assisted development tools
Benefits
- Competitive programs to support well-being
