
Senior Product Security Engineer
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in Brazil.
• Collaborate with developers to ensure product security throughout the Software Development Life Cycle (SDLC)
• Oversee security design and architecture evaluations
• Conduct threat modeling for new features and services
• Execute hands-on penetration testing for web applications and APIs
• Transform findings into clear, prioritized, and actionable tasks
• Perform secure code assessments
• Assist in defining secure coding standards and security acceptance criteria
• Manage and optimize Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency/supply-chain scanning
• Evaluate security findings
• Aid engineers in understanding the implications of findings and strategies to prevent future occurrences
• Contribute security evidence and rigor to compliance programs such as SOC 2, ISO 27001, and others
• Assess the product’s architecture and threat landscape, identifying the most critical security risks within the first 90 days
• Develop a repeatable process for conducting security design reviews
• Establish a clear pathway for triaging and remediating security findings
• Proven experience in product or application security
• Practical penetration testing skills focused on web applications and APIs
• Comprehensive knowledge of modern web applications, including single-page applications, APIs, authentication and authorization mechanisms, session management, and prevalent attack vectors such as those listed in the OWASP Top 10
• Experience leading security design reviews and threat modeling exercises
• Strong grasp of the SDLC and integrating security within it
• Excellent communication abilities, capable of conveying risk to developers effectively
• Familiarity with tools such as OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy or Grype, and Nuclei (preferred)
• Relevant offensive-security certifications, such as OSCP (preferred)
• Experience in cloud security with platforms like AWS, Azure, or Google Cloud, and container/Kubernetes security (preferred)
• Background in supporting SOC 2, ISO 27001, or similar compliance initiatives (preferred)
• Experience in enterprise or regulated environments (preferred)
• Comprehensive health and wellness benefits
• Opportunities for professional development and training
• Flexible work hours and remote work options
• Supportive team culture and collaborative environment
• Competitive salary and performance-related bonuses
VAILEXA
EverCommerce
NatWest Group
Inviso
Get handpicked remote jobs straight to your inbox weekly.