Product Security Engineer
This hands-on security engineering role partners with engineering teams to build secure systems, improve application and cloud security, strengthen the development lifecycle, and guide vulnerability remediation.
Responsibilities
- Review application architecture and new product features from a security perspective
- Identify vulnerabilities across backend services, APIs, mobile applications, and web platforms
- Perform threat modeling and security design reviews
- Support internal and external penetration testing
- Build and improve Secure SDLC practices
- Integrate security tooling into CI/CD pipelines
- Improve developer security practices and provide technical guidance
- Help engineering teams remediate vulnerabilities
- Improve cloud infrastructure security
- Secure Kubernetes, IAM policies, secrets management, and infrastructure components
- Implement security monitoring and hardening practices
- Work closely with Platform and DevOps teams
- Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection
- Automate security checks and developer workflows
- Improve security visibility across the engineering organization
Requirements
- 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering
- Strong software engineering background
- Experience securing backend systems, REST APIs, and microservices
- Experience with AWS, GCP, or Azure
- Strong understanding of Kubernetes, Docker, networking, and infrastructure security
- Experience with Secure SDLC and security automation
- Hands-on experience with SAST, DAST, dependency scanning, and secrets management
- Understanding of OWASP Top 10, common attack vectors, and secure coding practices
- Ability to work closely with software engineers and influence technical decisions
- Fluent English
- Mobile application security experience
- Experience in fintech, crypto, payments, or blockchain
- Offensive security or penetration testing experience
- Security certifications are a plus but not required
Benefits
- Support for courses, conferences, and English learning with up to 100% coverage
- Remote or hybrid work with flexible hours
- Up to 20 vacation days, 8 company holidays, and 5 personal days per year
- Structured performance reviews and team awards
- Retreats in international locations