Product Security Engineer

This hands-on security engineering role partners with engineering teams to build secure systems, improve application and cloud security, strengthen the development lifecycle, and guide vulnerability remediation.

Responsibilities

  • Review application architecture and new product features from a security perspective
  • Identify vulnerabilities across backend services, APIs, mobile applications, and web platforms
  • Perform threat modeling and security design reviews
  • Support internal and external penetration testing
  • Build and improve Secure SDLC practices
  • Integrate security tooling into CI/CD pipelines
  • Improve developer security practices and provide technical guidance
  • Help engineering teams remediate vulnerabilities
  • Improve cloud infrastructure security
  • Secure Kubernetes, IAM policies, secrets management, and infrastructure components
  • Implement security monitoring and hardening practices
  • Work closely with Platform and DevOps teams
  • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection
  • Automate security checks and developer workflows
  • Improve security visibility across the engineering organization

Requirements

  • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering
  • Strong software engineering background
  • Experience securing backend systems, REST APIs, and microservices
  • Experience with AWS, GCP, or Azure
  • Strong understanding of Kubernetes, Docker, networking, and infrastructure security
  • Experience with Secure SDLC and security automation
  • Hands-on experience with SAST, DAST, dependency scanning, and secrets management
  • Understanding of OWASP Top 10, common attack vectors, and secure coding practices
  • Ability to work closely with software engineers and influence technical decisions
  • Fluent English
  • Mobile application security experience
  • Experience in fintech, crypto, payments, or blockchain
  • Offensive security or penetration testing experience
  • Security certifications are a plus but not required

Benefits

  • Support for courses, conferences, and English learning with up to 100% coverage
  • Remote or hybrid work with flexible hours
  • Up to 20 vacation days, 8 company holidays, and 5 personal days per year
  • Structured performance reviews and team awards
  • Retreats in international locations

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available