Product Security Engineer
Core
Conduct security assessments, code reviews, and threat modeling to integrate security into the software development lifecycle and support compliance.
Role type
Product Security Engineer
Builds
Secure application and product design, security automation systems, and compliance-aligned product deployments
Domain
Cloud infrastructure, application security, and software development lifecycle
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability assessment and remediation, secure coding practices, threat modeling, risk management, security policy enforcement, incident response coordination, security automation development, penetration testing (web/mobile/traditional), cloud infrastructure security, container security, dependency scanning, source code analysis (Ruby, PHP, Go, JavaScript, Python), networking knowledge, understanding of MVC/JWT/GraphQL, SAST/DAST/container scanning tool usage
Preferred skills
AI integration in security testing workflows, experience with Claude Code, advanced security certifications (OSWE, OSCP, CISSP, GPEN, CEH, CCSP)
Technologies
AWS, Terraform, Python, Burp Suite, Ruby, PHP, Go, JavaScript, GraphQL, JWT, MITRE ATT&CK, CWE Top 25, OWASP Top 10
Responsibilities
Conduct security assessments and code reviews, develop and maintain product threat models, integrate security into SDLC, identify and coordinate vulnerability remediation, implement security tools and automation, participate in incident response, provide secure coding training, ensure regulatory compliance, collaborate with engineering and product teams, develop security policies
Seniority
Mid-level, hands-on IC
