
Senior Product Security Engineer, Application Security
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in United States.
• Assist in safeguarding CrowdStrike and its clients from sophisticated threats by fortifying our applications.
• Collaborate with engineering teams as a security expert and advisor, influencing the design and functionalities of our products.
• Develop, maintain, and enhance threat models to guide security architecture reviews and minimize threat exposure.
• Examine application source code for security vulnerabilities and potential risks.
• Conduct security assessments on applications throughout the Secure Development LifeCycle.
• Partner with developers to help them recognize vulnerabilities, risks, design flaws, and to implement effective solutions.
• Create integrated tools and automation to simplify processes for you, your team, and our engineering partners.
• Lead response initiatives for our bug bounty program, investigate similar issues across the platform, and enhance the security of our applications.
• Over 10 years of experience in CyberSecurity, with a focus on identifying security vulnerabilities and collaborating with engineering teams to devise solutions.
• Profound understanding of software product development and deployment within Agile/DevOps environments.
• Familiarity with threat model frameworks, particularly STRIDE.
• Established experience in manual secure code reviews for applications developed in Go (Golang), Python, or JavaScript.
• Extensive knowledge of browser security implementations across various platforms (Chrome, Firefox, etc. for both desktop and mobile), with strong experience in TypeScript, React, Node.js, and Electron.
• Proven skills in hands-on review and testing of API endpoint security.
• Familiarity with secure configuration practices for cloud-native and containerized applications across multiple cloud environments (GCP, Azure, AWS).
• Experience with or maintenance of commercially available AppSec tools such as SAST, DAST, CSPM, DSPM, and ASPM suites.
• Strong understanding of common software vulnerabilities affecting cloud and web applications (beyond just the OWASP Top 10) and demonstrated experience in application penetration testing.
• Examples of cross-technical team collaboration, including asking technical questions, challenging assumptions, and providing context for decision-making.
• Demonstrated experience in developing and maintaining automation for application security tasks and defect identification.
• Proven ability to leverage AI technologies to improve decision-making, streamline workflows and processes, enhance efficiency, and drive business results.
• Competitive compensation and equity awards that lead the market.
• Comprehensive wellness programs addressing both physical and mental health.
• Generous vacation and holiday policies for adequate rest and rejuvenation.
• Paid parental and adoption leave provisions.
• Opportunities for professional development available to all employees, irrespective of their level or role.
• Employee Networks, community groups, and volunteer initiatives to foster connections.
• A vibrant office culture complemented by world-class amenities.
Henkel
Pepperl+Fuchs Group
Win Systems
Intel Corporation
Get handpicked remote jobs straight to your inbox weekly.