
Product Security Engineer
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States, +1 more country.
• Collaborate with product and engineering teams to facilitate security architecture evaluations for product features and the GCP environment; lead threat modeling efforts and document risks, existing controls, and actionable recommendations.
• Organize and assist with penetration testing initiatives by aiding in vendor selection and scoping, establishing rules of engagement, coordinating testing activities, validating results, supporting severity assessments, and tracking remediation and retesting in partnership with engineering teams.
• Act as a GCP security subject matter expert for project teams, offering guidance on secure practices across networking (VPC, private access, perimeter controls), data protection (KMS, secrets), compute runtimes (GKE, Cloud Run, GCE), CI/CD (Cloud Build, Artifact Registry), and logging and monitoring.
• Aid in the implementation and ongoing enhancement of least-privilege IAM in GCP by providing advice on role design (custom vs. predefined), service account lifecycle management, workload identity, IAM Conditions, policy constraints at the organizational and folder level, and conducting periodic access reviews.
• Support the triage and routing of product security findings to the relevant engineering owners; assist in fine-tuning detection rules to minimize noise, aid in defining severity and SLA, and monitor remediation progress, including documenting justified exceptions.
• Contribute to security guardrails via policy and infrastructure-as-code (e.g., organizational policies, constraints, reusable Terraform modules, admission or policy controllers) and facilitate the integration of pre-merge security checks into CI/CD workflows.
• Create and sustain practical documentation and runbooks (e.g., design review checklists, IAM standards, exception processes) and conduct targeted enablement sessions for engineers and product managers.
• Provide insights into progress and risk through metrics and regular updates to security leadership; proactively identify blockers and propose options and trade-offs.
• Mentor and coach engineers and code owners on secure-by-default coding practices and architectural patterns.
• 5–7 years of experience in product security, cloud security engineering, or a related discipline.
• In-depth understanding of Google Cloud Platform (GCP) services and security best practices, including IAM, networking, data protection, and workload runtimes.
• Practical experience with coordinating penetration testing, threat modeling, and risk assessment activities.
• Proven proficiency in Python and cloud-native programming or scripting languages to design and maintain security automation, policy enforcement, and continuous compliance controls utilizing Infrastructure as Code.
• Knowledgeable in designing and enforcing least-privilege IAM and conducting access reviews.
• Strong ability to articulate security risks and recommendations effectively to engineering and leadership audiences.
• Meaningful equity so you share in Doppel’s success.
• Remote-first culture with built-in flexibility.
• Flexible PTO, comprehensive health benefits, parental leave, and more.
• A high-growth environment where your contributions have immediate impact and visibility.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.