As a Product Security Engineer, you will focus on threat modeling, security assessments, and vulnerability management to enhance the security of Bloomreach's platform.
Product Security Engineer
📜 Description
- Review application architecture and new product features from a security perspective.
- Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
- Perform threat modeling and security design reviews.
- Support internal and external penetration testing activities.
- Build and improve Secure SDLC across engineering teams.
🛠️ Requirements
- 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
- Strong software engineering background.
- Experience securing backend systems, REST APIs, and microservices.
- Experience with cloud platforms (AWS, GCP, or Azure).
- Strong understanding of Kubernetes, Docker, networking, and infrastructure security.
- Experience with Secure SDLC and security automation.
- Hands-on experience with SAST, DAST, dependency scanning, and secrets management.
- Understanding of OWASP Top 10, common attack vectors, and secure coding practices.
- Ability to work closely with software engineers and influence technical decisions.
- Fluent English.
✨ Benefits
- Professional growth: support for courses, conferences, and English learning (up to 100% coverage).
- Work-life fit: remote or hybrid format with flexible hours across international teams.
- Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year
- Recognition programs: structured performance reviews and team awards.
- Team culture: retreats in international locations (for example, company apartments in Cyprus).
Full job description
As our platform continues to scale, security becomes a core product capability rather than a separate function. We're looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up.
This is a highly technical, hands-on role where you'll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle.
Responsibilities
Application Security
- Review application architecture and new product features from a security perspective.
- Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
- Perform threat modeling and security design reviews.
- Support internal and external penetration testing activities.
Secure Development
- Build and improve Secure SDLC across engineering teams.
- Integrate security tooling into CI/CD pipelines.
- Improve developer security practices and provide technical guidance.
- Help engineering teams remediate vulnerabilities.
Cloud & Infrastructure Security
- Improve the security posture of our cloud infrastructure.
- Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components.
- Implement security monitoring and hardening best practices.
- Work closely with Platform and DevOps teams.
Security Automation
- Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection.
- Automate security checks and developer workflows.
- Continuously improve security visibility across the engineering organization.
Requirements
- 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
- Strong software engineering background.
- Experience securing backend systems, REST APIs, and microservices.
- Experience with cloud platforms (AWS, GCP, or Azure).
- Strong understanding of Kubernetes, Docker, networking, and infrastructure security.
- Experience with Secure SDLC and security automation.
- Hands-on experience with SAST, DAST, dependency scanning, and secrets management.
- Understanding of OWASP Top 10, common attack vectors, and secure coding practices.
- Ability to work closely with software engineers and influence technical decisions.
- Fluent English.
Nice to have
- Mobile application security experience.
- Experience in fintech, crypto, payments, or blockchain.
- Offensive security or penetration testing experience.
- Security certifications are a plus but not required.
Benefits
- Professional growth: support for courses, conferences, and English learning (up to 100% coverage).
- Work-life fit: remote or hybrid format with flexible hours across international teams.
- Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year
- Recognition programs: structured performance reviews and team awards.
- Team culture: retreats in international locations (for example, company apartments in Cyprus).
Similar jobs
Search more Cybersecurity Engineer jobsAs a Product Security Engineer, you will enhance user privacy and security by analyzing vulnerabilities, integrating security practices, and collaborating with engineering teams to ensure secure software development.
As a Security Engineer, you will protect cloud infrastructure and applications by identifying and remediating vulnerabilities, enhancing security controls, and responding to incidents.
Security Engineer – Cloud & Infrastructure Security
As a Security Engineer, you will design and implement security controls to protect cloud infrastructure and applications while collaborating with various teams to enhance security measures.
As a Product Security Engineer, you will enhance security across products and the software development lifecycle by collaborating with development teams to identify risks and implement solutions.
