Senior Product Security Engineer

Posted 23 hours ago

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Collaborate with developers to ensure product security throughout the Software Development Life Cycle (SDLC)

• Oversee security design and architecture evaluations

• Conduct threat modeling for new features and services

• Execute hands-on penetration testing for web applications and APIs

• Transform findings into clear, prioritized, and actionable tasks

• Perform secure code assessments

• Assist in defining secure coding standards and security acceptance criteria

• Manage and optimize Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency/supply-chain scanning

• Evaluate security findings

• Aid engineers in understanding the implications of findings and strategies to prevent future occurrences

• Contribute security evidence and rigor to compliance programs such as SOC 2, ISO 27001, and others

• Assess the product’s architecture and threat landscape, identifying the most critical security risks within the first 90 days

• Develop a repeatable process for conducting security design reviews

• Establish a clear pathway for triaging and remediating security findings


⛳️ Requirements

• Proven experience in product or application security

• Practical penetration testing skills focused on web applications and APIs

• Comprehensive knowledge of modern web applications, including single-page applications, APIs, authentication and authorization mechanisms, session management, and prevalent attack vectors such as those listed in the OWASP Top 10

• Experience leading security design reviews and threat modeling exercises

• Strong grasp of the SDLC and integrating security within it

• Excellent communication abilities, capable of conveying risk to developers effectively

• Familiarity with tools such as OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy or Grype, and Nuclei (preferred)

• Relevant offensive-security certifications, such as OSCP (preferred)

• Experience in cloud security with platforms like AWS, Azure, or Google Cloud, and container/Kubernetes security (preferred)

• Background in supporting SOC 2, ISO 27001, or similar compliance initiatives (preferred)

• Experience in enterprise or regulated environments (preferred)


🏝️ Benefits

• Comprehensive health and wellness benefits

• Opportunities for professional development and training

• Flexible work hours and remote work options

• Supportive team culture and collaborative environment

• Competitive salary and performance-related bonuses

People also viewed

VAILEXA18 hours ago

Product Security and Regulatory Expert

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
EverCommerce18 hours ago

Senior Director, Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$225k – $275k/year
ApplyView job
NatWest Group18 hours ago

Security Intelligence Specialist

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Inviso19 hours ago

Security & Identity Engineer

PL flagPoland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Atlas Governance20 hours ago

Information Security Governance Intern

BR flagBrazil OnlyInternshipCybersecurity / Security Engineer
ApplyView job
Triumph Enterprises, Inc.20 hours ago

Cloud Security Architect / Engineer

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers