Remote Jobs RockRemote Jobs Rock

Product Security Engineer

๐Ÿ“… Jul 6
Product SecurityApplication SecurityThreat ModelingSecurity Testing

๐Ÿ“œ Description

  • Design and conduct threat modeling sessions for new features and architectures
  • Identify attack vectors and security vulnerabilities early in development
  • Perform security testing of web and mobile applications, including penetration testing
  • Implement Static and Dynamic Application Security Testing in CI/CD pipelines
  • Develop automated security testing frameworks and tools

๐Ÿ› ๏ธ Requirements

  • 5+ years of experience in product security, application security, or related cybersecurity roles
  • Strong background in threat modeling and secure design review.
  • Extensive experience with web application security testing and mobile application security for iOS and Android platforms
  • Hands-on experience with DevSecOps practices and security tool integration
  • Proficiency with SAST, DAST, Cloud Security tools
  • Experience with security automation and scripting (Python, Bash)
  • Background in security analytics and data analysis for security insights
  • Experience with container security (Docker, Kubernetes)
  • Knowledge of infrastructure as code security (Terraform, CloudFormation)
  • Familiarity with security frameworks (NIST, ISO 27001, SOC 2)
Full job description

About the Role

We are seeking an experienced Product Security Engineer to join our team and help build security into every aspect of our product development lifecycle. In this role, you'll work closely with engineering, product, and DevOps teams to identify, assess, and mitigate security risks while enabling rapid and secure product delivery.

Key Responsibilities

Threat Modeling & Risk Assessment

  • Design and conduct comprehensive threat modeling sessions for new features and system architectures

  • Identify potential attack vectors and security vulnerabilities early in the development process

  • Collaborate with product and engineering teams to prioritize security requirements based on risk assessment

  • Develop and maintain threat models for existing and new products

Security Testing & Validation

  • Perform security testing of web applications, mobile applications, and APIs

  • Conduct static and dynamic application security testing

  • Execute penetration testing and vulnerability assessments

  • Review code for security vulnerabilities and provide remediation guidance

  • Validate security controls and defensive measures

DevSecOps Integration

  • Implement and maintain Static Application Security Testing (SAST) tools in CI/CD pipelines

  • Deploy and optimize Dynamic Application Security Testing (DAST) solutions

  • Establish cloud security best practices and tooling for AWS environments

  • Build security gates and quality checks into development workflows

  • Collaborate with DevOps teams to secure infrastructure as code

Security Automation & Tooling

  • Develop automated security testing frameworks and scripts

  • Build tools and integrations to streamline security processes

  • Automate vulnerability scanning and reporting workflows

  • Create self-service security tools for development teams

  • Implement security orchestration and response automation

Security Analytics & Monitoring

  • Design and implement security metrics and KPIs for product security

  • Analyze security testing results and trends to identify systemic issues

  • Build dashboards and reporting for security posture visibility

  • Conduct security data analysis to inform strategic decisions

  • Monitor and respond to security alerts and incidents

Cross-functional Collaboration

  • Partner with engineering teams to provide security guidance and support

  • Educate developers on secure coding practices and security requirements

  • Work with product managers to balance security and business requirements

  • Collaborate with infrastructure and platform teams on security architecture

Required Qualifications

  • 5+ years of experience in product security, application security, or related cybersecurity roles

  • Strong background in threat modeling and secure design review.

  • Extensive experience with web application security testing and mobile application security for iOS and Android platforms

  • Hands-on experience with DevSecOps practices and security tool integration

  • Proficiency with SAST, DAST, Cloud Security tools

  • Experience with security automation and scripting (Python, Bash)

  • Background in security analytics and data analysis for security insights

Preferred Qualifications

  • Experience with container security (Docker, Kubernetes)

  • Knowledge of infrastructure as code security (Terraform, CloudFormation)

  • Familiarity with security frameworks (NIST, ISO 27001, SOC 2)

  • Experience with bug bounty programs and responsible disclosure

  • Experience with compliance requirements (PCI DSS, GDPR)

Tipalti

Product Security Engineer

๐Ÿ•’ 14 days ago
Tipalti๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Financial Services

As a Product Security Engineer, you will enhance security across products and the software development lifecycle by collaborating with development teams to identify risks and implement solutions.

Application SecurityProduct SecurityThreat ModelingAPI Security
WRITER

Security engineer, application security (UK)

๐Ÿ•’ 8 days ago
WRITER๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Computer Software

As a Security Engineer focused on application security, you'll build and enhance security foundations for AI systems, ensuring robust protection while enabling developer agility.

Application SecurityThreat ModelingSASTDAST
Bloomreach

Product Security Engineer

๐Ÿ•’ 8 days ago
Bloomreach๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Internet

As a Product Security Engineer, you will focus on threat modeling, security assessments, and vulnerability management to enhance the security of Bloomreach's platform.

๐Ÿ“ ๐Ÿ‡ธ๐Ÿ‡ฐ Slovakia - Remote๐Ÿ’ฐ โ‚ฌ28.1k - โ‚ฌ35.1k / year๐Ÿ’ผ Full-Time๐ŸŽน Mid-level๐Ÿ“ Cybersecurity Engineer๐Ÿ“ข ๐Ÿ‡ฌ๐Ÿ‡ง English Required
CybersecurityApplication SecurityProduct SecurityThreat Modeling
Modern Health

Product Security Engineer

๐Ÿ•’ 11 days ago
Modern Health๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Mental Health

As a Product Security Engineer, you will enhance user privacy and security by analyzing vulnerabilities, integrating security practices, and collaborating with engineering teams to ensure secure software development.

Security EngineeringVulnerability ManagementSecure Coding StandardsThreat Modeling
Notion

Security Engineer, Detection and Response

๐Ÿ•’ 2 days ago
Notion๐Ÿ‘ฅ 10,000+ employees๐Ÿข Software Development๐Ÿค B2B

As a Detection Engineer, you'll build and operate systems to detect and respond to attacks in Notion's cloud-native environment, ensuring high-signal detections and effective incident response.

Detection EngineeringSecurity OperationsIncident ResponseThreat Hunting

Trusted by Remote Workers