Product Security Engineer
Overview
In this role you will safeguard business-critical applications by embedding security into the development lifecycle. You’ll partner with software engineers and leadership to advance secure coding and security-by-design practices while shaping security strategy across a global organization. You’ll tackle assessments, remediation guidance, and threat modeling, contributing to secure SDLC initiatives and cloud/DevSecOps efforts. This is a collaborative, high-impact position that drives secure software at scale.
Compensation / Benefitsbonus opportunitiesstrong compensation packagelong-term career growth and advancement potential
ResponsibilitiesPartner with engineers and tech leaders to promote secure coding and security-by-design principlesConduct application security assessments and penetration testingIdentify vulnerabilities and guide remediation effortsPerform code reviews and provide secure development recommendationsDesign and implement security controls for internal and customer-facing appsIntegrate security tooling into CI/CD pipelines and workflowsParticipate in threat modeling, security architecture reviews, and secure SDLC initiativesDevelop and maintain security standards, policies, and best practicesSupport incident response related to application and product securityDeliver security education and awareness programs for engineering teamsStay current on emerging threats, vulnerabilities, and security technologies
Key requirementsBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field7+ years of experience in Application Security, Product Security, or a related security engineering roleStrong understanding of secure SDLC practices and modern web application architectureExperience partnering directly with software development teamsHands-on experience with application security testing, vulnerability remediation, and security assessmentsExperience performing code reviews and providing secure development guidanceFamiliarity with cloud security and DevSecOps practicesKnowledge of OWASP Top 10 and common web application vulnerabilitiesExperience securing CI/CD pipelines and integrating security into development workflowsStrong communication skills with the ability to influence both technical and non-technical stakeholdersStrong communication and influencing skillsCollaborative mindsetAbility to translate technical concepts for non-technical stakeholdersApplication security testingVulnerability remediation and security assessmentsCode reviews for secure development