
Senior Product Security Engineer
Jobgether
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Product Security Engineer based in the United States.
This is a hands-on product security engineering role focused on embedding security throughout the software development lifecycle.
You will identify risks early, assess modern applications and AI-enabled services, and work directly with engineering teams to build secure-by-design products.
The role spans application security, threat modeling, penetration testing, secure code review, vulnerability management, AI security, and security automation.
You will collaborate closely with Engineering, Product, Infrastructure, Cloud Security, and Compliance teams while helping maintain developer velocity.
You will also improve security tooling and automation across CI/CD workflows, reducing manual effort and strengthening security coverage.
As a senior technical contributor, you will help establish security standards, reusable patterns, and engineering guardrails across a modern cloud-native environment.
This six-month, full-time contract is an opportunity to tackle challenging security problems across web, API, cloud, mobile, and AI technologies.
Accountabilities
Perform security design and architecture reviews for new products, features, applications, and services.
Conduct threat modeling across applications, APIs, microservices, and AI-enabled services to identify and mitigate security risks early.
Evaluate application security throughout the software development lifecycle and recommend practical improvements.
Partner directly with engineering teams to prioritize, remediate, and validate security vulnerabilities.
Review authentication, authorization, access control, OAuth, and OIDC implementations.
Conduct manual penetration testing across web applications, APIs, thick-client applications, and mobile applications.
Validate findings from third-party penetration tests and verify that identified vulnerabilities have been effectively remediated.
Perform secure code reviews and help engineering teams adopt stronger secure coding practices.
Define and improve Product Security standards, engineering guardrails, reusable security patterns, and reference architectures.
Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
Partner with engineering teams to prioritize vulnerability remediation and monitor remediation SLAs and security metrics.
Assess AI-enabled products and LLM integrations for security risks, including prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
Help establish secure AI engineering standards and contribute to the secure development of AI-enabled products.
Improve automated security testing throughout CI/CD pipelines and integrate security tools into developer workflows.
Develop scripts, automation, and internal tooling that reduce repetitive security work and improve engineering efficiency.
Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams to align security priorities with business and product objectives.
Support customer security questionnaires and assist Sales Engineering with product security discussions when required.
Requirements
5+ years of professional experience in Product Security, Application Security, or a closely related security engineering discipline.
Strong understanding of modern application architectures and experience securing web applications, APIs, microservices, and cloud-native applications.
Demonstrated experience performing threat modeling and application security assessments.
Hands-on experience conducting penetration testing and validating security vulnerabilities.
Strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.
Strong understanding of authentication, authorization, OAuth, OIDC, and secure software development lifecycle practices.
Experience with SAST, DAST, SCA, container security, and related application security tooling.
Proven ability to work directly with software engineering teams and translate security requirements into practical, developer-friendly solutions.
Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to technical and non-technical stakeholders.
Experience securing AI or LLM-powered applications is preferred.
Experience with Kubernetes and containerized environments is advantageous.
Familiarity with cloud security across AWS, Azure, or GCP is a plus.
Experience securing GitHub Actions or other CI/CD environments is desirable.
Familiarity with tools such as Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security is beneficial.
Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.
Strong analytical and problem-solving abilities, with a proactive approach to identifying risks and developing practical remediation strategies.
Ability to operate effectively in a fast-moving environment and balance security rigor with developer productivity.
Benefits
Six-month, full-time contract at 40 hours per week.
Competitive compensation.
100% individual and dependent medical, dental, and vision coverage.
401(k) with a 4% company match.
20 days of paid time off.
Dedicated wellness week during the first week of July.
Paid family and medical leave.
Up to 16 weeks of paid leave for new parents.
Exciting opportunities to work on challenging security and technology initiatives.
Career growth and professional development opportunities.
Inclusive and collaborative environment that values diverse perspectives, backgrounds, and experiences.
Remote work opportunity within the United States.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1