
Product Security Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Lead engagements in threat modeling for features and services where the risk justifies it.
• Assist in the evolution of the threat-modeling practice from ad-hoc requests to a structured, repeatable process with defined engagement criteria.
• Take ownership of the daily triage of CNAPP findings: investigate, prioritize, direct to service owners, and ensure closure.
• Recognize patterns in findings that suggest the need for systemic improvements.
• Contribute to SDLC tools, SAST/SCA workflows, and bug bounty triage efforts.
• Collaborate with product engineering teams as a trusted security advisor.
• Leverage AI to expedite triage, summarize findings, draft threat models, scan code, and minimize repetitive tasks.
• Develop sustainable patterns for safe and effective AI implementation.
• Enhance security through documentation, office hours, and minor tooling enhancements.
• Report directly to the Director of Security and work alongside software engineers, product managers, and security engineers.
• 2 to 4 years of professional experience in a security-centric role; experience in AppSec, ProdSec, or cloud security is preferred.
• Proficient in reviewing and critiquing pull requests within a modern tech stack.
• Experience in participating in or leading threat modeling sessions.
• Familiarity with at least one structured approach to threat modeling: STRIDE, attack trees, or a similar methodology.
• Practical knowledge of cloud security posture management.
• Solid understanding of the OWASP Top 10, authentication and authorization methodologies, secrets management, and common cloud misconfigurations.
• Hands-on experience utilizing AI tools in security or engineering tasks, with concrete examples.
• Experience with developer tools, SaaS platforms, or feature management systems.
• Familiarity with bug bounty triage processes, particularly using HackerOne or Bugcrowd.
• Knowledge of programming languages such as Go, Python, or TypeScript.
• Contributions to internal security tools or open-source security initiatives.
• Restricted Stock Units (RSUs)
• Health insurance
• Vision insurance
• Dental insurance
• Mental health benefits
CrowdStrike
Triumph Enterprises, Inc.
Staffbase
Comcast
Get handpicked remote jobs straight to your inbox weekly.