Senior Product Security Engineer
jobgether · US
About The Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Product Security Engineer based in the United States.
This is a hands-on product security engineering role focused on embedding security throughout the software development <lifecycle.You> will identify risks early, assess modern applications and AI-enabled services, and work directly with engineering teams to build secure-by-design products.The role spans application security, threat modeling, penetration testing, secure code review, vulnerability management, AI security, and security <automation.You> will collaborate closely with Engineering, Product, Infrastructure, Cloud Security, and Compliance teams while helping maintain developer <velocity.You> will also improve security tooling and automation across CI/CD workflows, reducing manual effort and strengthening security <coverage.As> a senior technical contributor, you will help establish security standards, reusable patterns, and engineering guardrails across a modern cloud-native environment.This six-month, full-time contract is an opportunity to tackle challenging security problems across web, API, cloud, mobile, and AI technologies.
Accountabilities
- Perform security design and architecture reviews for new products, features, applications, and services.
- Conduct threat modeling across applications, APIs, microservices, and AI-enabled services to identify and mitigate security risks early.
- Evaluate application security throughout the software development lifecycle and recommend practical improvements.
- Partner directly with engineering teams to prioritize, remediate, and validate security vulnerabilities.
- Review authentication, authorization, access control, OAuth, and OIDC implementations.
- Conduct manual penetration testing across web applications, APIs, thick-client applications, and mobile applications.
- Validate findings from third-party penetration tests and verify that identified vulnerabilities have been effectively remediated.
- Perform secure code reviews and help engineering teams adopt stronger secure coding practices.
- Define and improve Product Security standards, engineering guardrails, reusable security patterns, and reference architectures.
- Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
- Partner with engineering teams to prioritize vulnerability remediation and monitor remediation SLAs and security metrics.
- Assess AI-enabled products and LLM integrations for security risks, including prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
- Help establish secure AI engineering standards and contribute to the secure development of AI-enabled products.
- Improve automated security testing throughout CI/CD pipelines and integrate security tools into developer workflows.
- Develop scripts, automation, and internal tooling that reduce repetitive security work and improve engineering efficiency.
- Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams to align security priorities with business and product objectives.
- Support customer security questionnaires and assist Sales Engineering with product security discussions when required.
Requirements
- 5+ years of professional experience in Product Security, Application Security, or a closely related security engineering discipline.
- Strong understanding of modern application architectures and experience securing web applications, APIs, microservices, and cloud-native applications.
- Demonstrated experience performing threat modeling and application security assessments.
- Hands-on experience conducting penetration testing and validating security vulnerabilities.
- Strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.
- Strong understanding of authentication, authorization, OAuth, OIDC, and secure software development lifecycle practices.
- Experience with SAST, DAST, SCA, container security, and related application security tooling.
- Proven ability to work directly with software engineering teams and translate security requirements into practical, developer-friendly solutions.
- Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to technical and non-technical stakeholders.
- Experience securing AI or LLM-powered applications is preferred.
- Experience with Kubernetes and containerized environments is advantageous.
- Familiarity with cloud security across AWS, Azure, or GCP is a plus.
- Experience securing GitHub Actions or other CI/CD environments is desirable.
- Familiarity with tools such as Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security is beneficial.
- Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.
- Strong analytical and problem-solving abilities, with a proactive approach to identifying risks and developing practical remediation strategies.
- Ability to operate effectively in a fast-moving environment and balance security rigor with developer productivity.
Benefits
- Six-month, full-time contract at 40 hours per week.
- Competitive compensation.
- 100% individual and dependent medical, dental, and vision coverage.
- 401(k) with a 4% company match.
- 20 days of paid time off.
- Dedicated wellness week during the first week of July.
- Paid family and medical leave.
- Up to 16 weeks of paid leave for new parents.
- Exciting opportunities to work on challenging security and technology initiatives.
- Career growth and professional development opportunities.
- Inclusive and collaborative environment that values diverse perspectives, backgrounds, and experiences.
- Remote work opportunity within the United States.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
