
Product Security Engineer
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Cyprus, +4 more states.
• Evaluate application architecture and new product features with a focus on security.
• Detect security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
• Conduct threat modeling and security design evaluations.
• Assist with both internal and external penetration testing efforts.
• Develop and enhance the Secure SDLC within engineering teams.
• Incorporate security tools into CI/CD pipelines.
• Enhance developer security practices and offer technical advice.
• Aid engineering teams in addressing vulnerabilities.
• Strengthen the security framework of cloud infrastructure.
• Safeguard Kubernetes environments, IAM policies, secrets management, and infrastructure components.
• Execute security monitoring and implement hardening best practices.
• Collaborate closely with Platform and DevOps teams.
• Set up and manage SAST, DAST, dependency scanning, container scanning, and secret detection.
• Automate security checks and developer workflows.
• Continuously enhance security visibility throughout the engineering organization.
• Over 4 years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
• Solid background in software engineering.
• Proven experience in securing backend systems, REST APIs, and microservices.
• Familiarity with cloud platforms such as AWS, GCP, or Azure.
• Strong knowledge of Kubernetes, Docker, networking, and infrastructure security.
• Experience with Secure SDLC and automation in security processes.
• Practical experience with SAST, DAST, dependency scanning, and secrets management.
• Comprehensive understanding of OWASP Top 10, common attack vectors, and secure coding practices.
• Ability to collaborate effectively with software engineers and influence technical choices.
• Proficient in English.
• Nice to have: Experience in mobile application security.
• Nice to have: Background in fintech, crypto, payments, or blockchain.
• Nice to have: Experience in offensive security or penetration testing.
• Security certifications are advantageous but not mandatory.
• Professional development: funding for courses, conferences, and English language learning (up to 100% coverage).
• Work-life balance: remote or hybrid working arrangements with flexible hours across global teams.
• Paid time off: up to 20 vacation days + 8 company holidays + 5 personal days annually.
• Recognition programs: structured performance reviews and team awards.
• Team culture: retreats in international destinations (for example, company accommodations in Cyprus).
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.