
Senior Product Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Portugal, +1 more country.
• Establish product security throughout the engineering organization.
• Develop the product security practice and report directly to the Head of Information Security.
• Integrate security into the software development lifecycle, from architecture and design to build, deployment, and remediation.
• Implement security gates, secure release practices, and guardrails within engineering workflows.
• Select and manage application security tools.
• Leverage AI and automation to enhance security coverage without hindering product delivery.
• Lead threat modeling efforts for new products and significant changes.
• Offer secure-by-design insights for products related to card issuing, embedded finance, banking-as-a-service, and other payment solutions.
• Define secure-by-default application architecture patterns for authentication, authorization, API design, and service-to-service trust.
• Assess traditional tools against AI-assisted alternatives.
• Take ownership of CI/CD pipeline and software supply-chain security controls.
• Implement and refine container image scanning, dependency management, software bills of materials, infrastructure-as-code checks, and deployment-manifest security checks.
• Introduce AI agents and LLM-assisted workflows as the standard application-security delivery method.
• Facilitate the remediation of application-layer findings with engineering teams, including penetration test, scanner, and disclosure report findings.
• A minimum of 5 years of experience in Product Security or Application Security within payments, fintech, banking, e-money, or a similar fintech product setting.
• Extensive practical experience in embedding security within the software development lifecycle.
• Proficiency in reading code and contributing to design discussions with senior engineers.
• Demonstrated experience with threat modeling, secure-by-design reviews, and collaboration with engineers during architecture and delivery phases.
• Practical experience with SAST, SCA, secrets detection, and DAST.
• Hands-on experience securing cloud-native applications on AWS or other leading cloud platforms.
• Strong proficiency in AI and practical experience with agentic workflows and loops, RAG, MCP, etc.
• Comprehensive understanding of cloud-first environments and modern development methodologies.
• Experience in securing CI/CD pipelines and enhancing software supply-chain security.
• Ability to collaborate directly with engineering teams and influence secure delivery practices.
• Strong ownership mentality and ability to define, implement, enhance, and promote security practices across multiple teams.
• Excellent written and verbal English skills.
• Annual Learning Budget for professional development (eligible after probation).
• Company celebrations that unite colleagues from all offices.
• Opportunities to engage in international company events and initiatives.
• Global collaboration with colleagues from various regions.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.