
Product Security Engineer
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Collaborate with Engineering and Product teams throughout the product development lifecycle.
• Evaluate new products and technologies.
• Lead security design reviews and threat modeling sessions.
• Examine application architecture, APIs, authentication methods, authorization processes, data flows, cloud services, and third-party integrations.
• Identify, validate, and prioritize security vulnerabilities.
• Work closely with engineers to develop practical remediation strategies.
• Manage and enhance SAST, DAST, dependency scanning, secret scanning, and other security tools.
• Optimize security tools and workflows to minimize false positives.
• Develop automation solutions for Product Security initiatives.
• Establish security standards, secure design patterns, coding guidelines, and documentation.
• Assist in leading product security incident response, containment, root cause analysis, and remediation efforts.
• Investigate emerging risks associated with cloud and AI-enabled products.
• Proven experience in product security, application security, software engineering, penetration testing, or a related field.
• Strong ability to analyze complex systems, data flows, and trust boundaries.
• Experience in threat modeling, architecture reviews, and application assessments.
• Capability to validate vulnerabilities and evaluate their exploitability.
• Familiarity with APIs, cloud services, containers, serverless technologies, and CI/CD pipelines.
• Experience with SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning.
• Proficient in reading and writing code.
• Ability to automate security tasks using Python, JavaScript, or a similar programming language.
• Experience in securing AI-enabled products, agents, large language model applications, or MCP integrations.
• Extensive expertise in identity, authentication, authorization, or multi-tenant application security.
• Knowledge of OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST frameworks.
• Excellent communication skills with both technical and non-technical teams.
• Aptitude for balancing security concerns, customer impact, engineering efforts, and business priorities.
• Flexible work hours.
• Flexible vacation policy.
• Generous 401K matching.
• Parental leave.
• Team-building events.
• Wellness budget.
• Learning reimbursement.
• Comprehensive benefits and perks.
• An ownership-focused, respectful, trust-based work environment.
• Fully remote work option available within the United States.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.