
Product Security Engineer
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Participate early in the development of new products and features by conducting threat modeling and security design reviews.
• Evaluate application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations.
• Detect and confirm vulnerabilities, differentiate genuine risks from false positives, and prioritize remediation efforts.
• Collaborate with engineers to devise effective remediation strategies.
• Manage and enhance security tools throughout the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
• Optimize security tools and workflows to enhance the quality of findings.
• Develop automation to scale Product Security operations efficiently.
• Establish security standards, secure design patterns, coding guidelines, and documentation.
• Lead product security incident responses from investigation and containment to root cause analysis and long-term remediation.
• Collaborate with Engineering and Product teams to make informed security decisions.
• Evaluate emerging risks associated with cloud and AI-enabled products.
• Proven experience in product security, application security, software engineering, penetration testing, or a similar role.
• Proficient in analyzing complex systems, data flows, and trust boundaries.
• Skills in threat modeling, architecture reviews, and application security assessments.
• Ability to validate vulnerabilities and evaluate their exploitability.
• Familiarity with APIs, cloud services, containers, serverless technologies, and CI/CD pipelines.
• Experience with SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning.
• Capability to read and write code proficiently.
• Experience in automating security processes using Python, JavaScript, or a comparable language.
• Background in securing AI-enabled products, agents, large language model applications, or MCP integrations.
• Extensive experience with identity, authentication, authorization, or multi-tenant application security.
• Familiarity with applying OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST frameworks.
• Excellent communication skills with the ability to collaborate with both technical and non-technical teams.
• Flexible work hours.
• Flexible vacation policy.
• Generous 401K matching.
• Parental leave.
• Team-building events.
• Wellness budget.
• Learning reimbursement.
• Ownership-focused growth and development environment.
• Comprehensive benefits and perks.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.