
Senior Product Security Engineer – Contract
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in United States.
• Integrate security into the product development lifecycle.
• Detect security risks early and collaborate with development teams on solutions.
• Conduct security design and architecture assessments for new products and features.
• Execute threat modeling for applications, APIs, and AI-driven services.
• Evaluate application security posture throughout the software development lifecycle (SDLC).
• Analyze authentication, authorization, and access control implementations.
• Carry out manual penetration testing for web, API, thick-client, and mobile applications.
• Confirm results from third-party penetration tests.
• Perform secure code assessments.
• Validate the remediation of identified security vulnerabilities.
• Promote the adoption of secure coding practices.
• Assist in defining Product Security standards and engineering guidelines.
• Create reusable security patterns and reference architectures.
• Manage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
• Monitor remediation SLAs and security performance metrics.
• Evaluate AI-enabled products for potential security risks.
• Review LLM integrations and AI workflows.
• Test AI applications for issues such as prompt injection, data leakage, insecure tool usage, model misuse, and authorization flaws.
• Contribute to the establishment of secure AI engineering standards.
• Enhance automation of security testing throughout CI/CD processes.
• Incorporate security tools into developer workflows.
• Develop scripts and tools that minimize manual security tasks.
• Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
• Assist with customer security questionnaires regarding product security.
• Support Sales Engineering with security discussions as necessary.
• Over 5 years of experience in Product Security or Application Security.
• Strong knowledge of contemporary application architectures.
• Proven experience in securing web applications, APIs, microservices, and cloud-native applications.
• Experience in conducting threat modeling.
• Proven experience in penetration testing.
• Deep understanding of the OWASP Top 10.
• Strong grasp of the OWASP API Top 10.
• Comprehensive understanding of authentication and authorization mechanisms.
• In-depth knowledge of OAuth / OIDC.
• Strong familiarity with Secure SDLC practices.
• Experience with SAST, DAST, SCA, and container security measures.
• Proven ability to collaborate directly with engineering teams.
• Excellent written and verbal communication skills.
• Experience in securing AI/LLM applications is preferred.
• Familiarity with Kubernetes and container technologies is preferred.
• Knowledge of cloud security (AWS, Azure, or GCP) is preferred.
• Experience with GitHub Actions or CI/CD security practices is preferred.
• Familiarity with tools like Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security is preferred.
• Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are advantageous.
• Competitive salary.
• Comprehensive medical, dental, and vision coverage for individuals and dependents at 100%.
• 401(K) plan with a 4% company match.
• 20 days of paid time off (PTO).
• Iru Wellness Week during the first week of July.
• Equity options for full-time employees.
• Up to 16 weeks of paid leave for new parents.
• Paid Family and Medical Leave.
• Exciting opportunities for professional growth.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.