Remote job
Product Security Engineer
Job details
About this role
Role overview This position sits within a product security organization supporting a large personalization platform that serves enterprise brands across retail, financial services, hospitality, and gaming. The engineer serves as the dedicated security lead for an assigned product domain, partnering closely with engineering, DevOps, and compliance teams to embed security throughout the software development lifecycle.
Responsibilities - Champion Secure Software Development Lifecycle (SSDLC) adoption across engineering squads and help integrate security checkpoints into existing workflows. - Review application designs, system architectures, and infrastructure components to surface risks and recommend mitigations. - Lead or contribute to threat modeling sessions using approaches such as STRIDE, producing practical recommendations that engineering teams can act on. - Conduct security assessments, penetration testing, and validation exercises across web applications and supporting environments. - Triage, validate, and assign vulnerabilities surfaced by automated tooling and manual testing, then drive remediation with stakeholders. - Act as a security point of contact for the assigned domain, escalating complex or high-risk issues to senior security staff as needed.
Requirements - Two or more years of hands-on experience in application security, product security, or a closely related discipline. - Practical exposure to security assessments and penetration testing of web applications. - Familiarity with threat modeling methodologies such as STRIDE and the ability to identify common threat categories. - Working knowledge of vulnerability management, including validation, risk-based prioritization, and remediation tracking. - Understanding of modern application architectures, APIs, authentication and authorization mechanisms, and common web security risks. - Familiarity with OWASP materials (Top 10, Testing Guide) and tools such as Burp Suite, OWASP ZAP, Nmap, and SAST/SCA platforms.
Nice to have - Exposure to AI and large language model technologies, with curiosity about their unique security risks. - Strong communication skills for translating technical findings into actionable guidance for non-security audiences.
Benefits and work setup - Virtual-first work model with collaboration hubs across multiple continents. - Company-wide events, volunteering days, and an annual professional development budget. - Equity participation, performance bonuses, parental leave, wellness resources, and additional quarterly days off.