
Principal Product Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Florida.
• Ensure secure software development life cycle (SDLC) and DevSecOps practices.
• Integrate automated checks within our cloud (via GitHub Actions) and on-premises product pipelines using GitHub Advanced Security (SAST/SCA) and Wiz Code for application, dependency, and container scanning.
• Establish secure-by-default patterns, paved-road guardrails, and coding standards to support rapid and safe shipping by teams.
• Act as the application authority for our Zero Trust initiative, aligning with NIST SP 800-207 and the CISA Zero Trust Maturity Model (Applications & Workloads pillar).
• Conduct threat modeling and ensure secure design practices.
• Collaborate with product and engineering teams on security reviews for new features and payment integrations—conducting threat modeling (e.g., STRIDE) early in the design phase and translating outcomes into actionable, prioritized tasks.
• Oversee the end-to-end vulnerability management lifecycle for products and applications—managing a comprehensive program that encompasses code, dependency, container, penetration testing, and bug-bounty findings, from discovery to remediation.
• Prioritize based on real-world risks and drive remediation according to risk-based service level agreements (SLAs); while engineering addresses fixes, you manage the program and escalation processes to reduce remediation time.
• Provide program health reports using metrics actionable by leadership, ensuring compliance with obligations such as PCI DSS, GLI, ISO 27001, and SOC 2.
• Safeguard our applications and APIs from OWASP Top 10 threats and API abuse, collaborating on payment security across payment gateways, and partnering with our Principal Cloud & Network Security Engineer—who manages our Cloudflare edge defenses (WAF, Bot Management)—to enhance bot and abuse resilience.
• Take ownership of the application security for player-facing account processes—including registration, authentication, session management, and recovery—collaborating with our Principal Identity Engineer on customer identity and access management (CIAM) architecture, along with SecOps and Fraud on account takeover resilience.
• Coordinate penetration testing with external partners and ensure closure of findings.
• Enhance our existing coordinated-disclosure program into a comprehensive bug-bounty capability.
• 10+ years of experience in application or product security, or equivalent practical expertise.
• Extensive knowledge of the application security toolchain, including SAST, SCA, and secure code review.
• Strong understanding of the vulnerability management lifecycle: triage, prioritization, remediation tracking, and metrics.
• Hands-on experience with threat modeling and secure design collaboration with engineering teams.
• Familiarity with a modern programming language and an understanding of how contemporary applications are developed and deployed.
• Experience with CI/CD pipelines and cloud-native application security (predominantly on AWS).
• Excellent communication skills, translating findings into clear, prioritized requests.
• Proficient in AI, actively utilizing AI tools daily to enhance work efficiency and effectiveness; practical experience applying AI in security or engineering projects is essential.
• Competitive salary and benefits package.
• Flexible vacation policy.
• Hybrid/remote working options.
• Startup culture supported by a secure, global brand.
actago GmbH
Zscaler
Thomson Reuters
DSV - Global Transport and Logistics
Get handpicked remote jobs straight to your inbox weekly.