freehire launches on Product Hunt on 26 August.

Follow →

Product Security Engineer

Summary

Secure cloud apps, APIs, mobile apps, and Kubernetes infrastructure; perform threat modeling, penetration testing, and integrate security tooling into CI/CD pipelines.

You will secure applications, cloud infrastructure, APIs, mobile applications, and development workflows. You will review architectures, identify vulnerabilities, perform threat modeling, support penetration testing, build Secure SDLC practices, integrate security tooling into CI/CD pipelines, secure Kubernetes and cloud environments, automate security checks, and guide engineering teams in remediating vulnerabilities.

Responsibilities

  • Review application architecture and new product features from a security perspective
  • Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms
  • Perform threat modeling and security design reviews
  • Support internal and external penetration testing activities
  • Build and improve Secure SDLC across engineering teams
  • Integrate security tooling into CI/CD pipelines
  • Improve developer security practices and provide technical guidance
  • Help engineering teams remediate vulnerabilities
  • Improve the security posture of cloud infrastructure
  • Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components
  • Implement security monitoring and hardening best practices
  • Work closely with Platform and DevOps teams
  • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection
  • Automate security checks and developer workflows
  • Continuously improve security visibility across the engineering organization

Requirements

  • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering
  • Strong software engineering background
  • Experience securing backend systems, REST APIs, and microservices
  • Experience with AWS, GCP, or Azure
  • Strong understanding of Kubernetes, Docker, networking, and infrastructure security
  • Experience with Secure SDLC and security automation
  • Hands-on experience with SAST, DAST, dependency scanning, and secrets management
  • Understanding of OWASP Top 10, common attack vectors, and secure coding practices
  • Ability to work closely with software engineers and influence technical decisions
  • Fluent English
  • Mobile application security experience
  • Experience in fintech, crypto, payments, or blockchain
  • Offensive security or penetration testing experience
  • Security certifications are a plus but not required

Benefits

  • Support for courses, conferences, and English learning with up to 100% coverage
  • Remote or hybrid work with flexible hours
  • Up to 20 vacation days, 8 company holidays, and 5 personal days per year
  • Structured performance reviews and team awards
  • Retreats in international locations

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available