Security Engineer – Product Security
Summary
Security Engineer designing and reviewing security controls for web, mobile, and cloud applications, integrating SAST/DAST/SCA into CI/CD pipelines, conducting threat modeling, and assessing APIs and containers across AWS, Azure, and GCP.
You will design and review security controls for web mobile and cloud applications. You will lead threat modeling, integrate security testing into CI/CD pipelines, assess APIs and containers, manage vulnerabilities, support monitoring and incident response, and create secure development guidance and training.
Responsibilities
- Support security design and architecture reviews
- Define product security requirements and roadmaps
- Conduct threat modeling workshops
- Review AWS Azure and GCP services
- Own the application security lifecycle
- Integrate SAST DAST SCA and secrets scanning into CI/CD pipelines
- Coordinate application security testing and remediation
- Establish secure coding standards and frameworks
- Assess REST and GraphQL API security
- Support vulnerability triage and remediation
- Ensure appropriate handling of sensitive data
- Evaluate and implement product security tools
- Develop security documentation playbooks and training
- Advise on secure use of AI-assisted development tools
Requirements
- Bachelor’s degree in Computer Science Cybersecurity Engineering or a related field or equivalent practical experience
- 3+ years of experience in security engineering application security or product-aligned security roles
- Knowledge of web mobile and API vulnerabilities including OWASP Top 10
- Experience securing applications and services in a major cloud provider
- Knowledge of SAST DAST SCA secret scanning WAF and CI/CD integration
- Familiarity with Terraform review GitHub Actions security and secrets management
- Familiarity with container security Kubernetes RBAC network policies and runtime protection
- Familiarity with securing AI and ML platforms and agentic workflows
- Experience collaborating with software engineering teams in agile environments
- Knowledge of identity authentication and authorization technologies including OAuth OIDC and SSO
- Excellent communication and stakeholder management skills