
Senior Product Security Engineer
Posted Sep 28

Posted Sep 28
This is a fully remote position, open to applicants in Canada.
• Develop and maintain the product security tooling pipeline throughout the software development lifecycle.
• Implement and fine-tune Claude Code Security, Codex Security, GitHub Advanced Security, and Wiz CLI across repositories and CI/CD pipelines.
• Set up policies and consistently enhance security tooling for precise, actionable feedback.
• Design and manage automated product security review workflows with human-in-the-loop checkpoints.
• Utilize Claude and LLM platforms for review triage, risk classification, recommendation generation, vulnerability detection, fix suggestions, policy enforcement, and summarization.
• Integrate security tooling into GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards.
• Minimize false positives and establish feedback loops to enhance findings.
• Assist with product incident response, investigation, impact assessment, emergency fixes, root cause analysis, and post-incident improvements.
• Collaborate with Security Testers, Architects, the TPM, and engineering teams.
• Offer security tooling configuration, troubleshooting, and support to engineering teams.
• Over 4 years of experience in Application Security, Product Security, DevSecOps, or Security Engineering with practical experience in building and operating security tooling within CI/CD pipelines.
• Proficient in implementing and optimizing SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (such as GitHub Advanced Security, CodeQL, Dependabot, or similar).
• Practical experience with AI-driven security tools like Claude Code Security, Codex Security, or comparable LLM-based code analysis platforms.
• Strong comprehension of CI/CD pipeline architecture and the integration of security controls.
• Experience with scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration.
• Familiarity with container security scanning tools and foundational cloud security principles.
• Understanding of common vulnerability categories, finding triage, severity assessment, and remediation techniques.
• Excellent collaboration and communication abilities.
• Automation-focused mindset.
• A culture that promotes flexibility, trust, and continuous learning.
• Opportunities for recognition and ongoing learning growth.
• A workplace culture that emphasizes diversity and inclusion.
• Support and care for employees.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.