Skip to content
← Back to job listings

Senior Product Security Engineer

jobgether · US

RemoteImported listingcontract5 days ago

About The Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Product Security Engineer based in the United States.

This is a hands-on product security engineering role focused on embedding security throughout the software development <lifecycle.You> will identify risks early, assess modern applications and AI-enabled services, and work directly with engineering teams to build secure-by-design products.The role spans application security, threat modeling, penetration testing, secure code review, vulnerability management, AI security, and security <automation.You> will collaborate closely with Engineering, Product, Infrastructure, Cloud Security, and Compliance teams while helping maintain developer <velocity.You> will also improve security tooling and automation across CI/CD workflows, reducing manual effort and strengthening security <coverage.As> a senior technical contributor, you will help establish security standards, reusable patterns, and engineering guardrails across a modern cloud-native environment.This six-month, full-time contract is an opportunity to tackle challenging security problems across web, API, cloud, mobile, and AI technologies.

Accountabilities

  • Perform security design and architecture reviews for new products, features, applications, and services.
  • Conduct threat modeling across applications, APIs, microservices, and AI-enabled services to identify and mitigate security risks early.
  • Evaluate application security throughout the software development lifecycle and recommend practical improvements.
  • Partner directly with engineering teams to prioritize, remediate, and validate security vulnerabilities.
  • Review authentication, authorization, access control, OAuth, and OIDC implementations.
  • Conduct manual penetration testing across web applications, APIs, thick-client applications, and mobile applications.
  • Validate findings from third-party penetration tests and verify that identified vulnerabilities have been effectively remediated.
  • Perform secure code reviews and help engineering teams adopt stronger secure coding practices.
  • Define and improve Product Security standards, engineering guardrails, reusable security patterns, and reference architectures.
  • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
  • Partner with engineering teams to prioritize vulnerability remediation and monitor remediation SLAs and security metrics.
  • Assess AI-enabled products and LLM integrations for security risks, including prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Help establish secure AI engineering standards and contribute to the secure development of AI-enabled products.
  • Improve automated security testing throughout CI/CD pipelines and integrate security tools into developer workflows.
  • Develop scripts, automation, and internal tooling that reduce repetitive security work and improve engineering efficiency.
  • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams to align security priorities with business and product objectives.
  • Support customer security questionnaires and assist Sales Engineering with product security discussions when required.

Requirements

  • 5+ years of professional experience in Product Security, Application Security, or a closely related security engineering discipline.
  • Strong understanding of modern application architectures and experience securing web applications, APIs, microservices, and cloud-native applications.
  • Demonstrated experience performing threat modeling and application security assessments.
  • Hands-on experience conducting penetration testing and validating security vulnerabilities.
  • Strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.
  • Strong understanding of authentication, authorization, OAuth, OIDC, and secure software development lifecycle practices.
  • Experience with SAST, DAST, SCA, container security, and related application security tooling.
  • Proven ability to work directly with software engineering teams and translate security requirements into practical, developer-friendly solutions.
  • Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to technical and non-technical stakeholders.
  • Experience securing AI or LLM-powered applications is preferred.
  • Experience with Kubernetes and containerized environments is advantageous.
  • Familiarity with cloud security across AWS, Azure, or GCP is a plus.
  • Experience securing GitHub Actions or other CI/CD environments is desirable.
  • Familiarity with tools such as Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security is beneficial.
  • Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.
  • Strong analytical and problem-solving abilities, with a proactive approach to identifying risks and developing practical remediation strategies.
  • Ability to operate effectively in a fast-moving environment and balance security rigor with developer productivity.

Benefits

  • Six-month, full-time contract at 40 hours per week.
  • Competitive compensation.
  • 100% individual and dependent medical, dental, and vision coverage.
  • 401(k) with a 4% company match.
  • 20 days of paid time off.
  • Dedicated wellness week during the first week of July.
  • Paid family and medical leave.
  • Up to 16 weeks of paid leave for new parents.
  • Exciting opportunities to work on challenging security and technology initiatives.
  • Career growth and professional development opportunities.
  • Inclusive and collaborative environment that values diverse perspectives, backgrounds, and experiences.
  • Remote work opportunity within the United States.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing