Senior Product Security Engineer
Core
Partner with developers to secure the product across the SDLC through design reviews, threat modeling, penetration testing, and secure-coding partnership.
Role type
Senior IC product security engineer
Builds
Defensible web applications and APIs
Domain
Software security / Web application security (via careerplan.io/jobs/3a6fe2e0-68da-4d37-922d-47bd1801128c-senior-product-security-engineer-at-tessera-labs)
Required skills
Penetration testing (web apps/APIs), SDLC security integration, Threat modeling, Secure code review, SAST/DAST/Supply-chain scanning triage, OAuth 2.0/OpenID Connect, OWASP Top 10
Preferred skills
Offensive Security Certified Professional (OSCP), Cloud security (AWS/Azure/GCP), Container/Kubernetes security, SOC 2/ISO 27001 compliance support
Technologies
OWASP ZAP, Burp Suite, Semgrep, Trivy, Grype, Nuclei
Responsibilities
Lead security design and architecture reviews; Perform hands-on penetration testing of web applications and APIs; Conduct secure code reviews and define secure-coding standards; Operate and tune SAST, DAST, and dependency scanning tools; Translate security findings into prioritized, fixable work; Contribute to compliance posture (SOC 2, ISO 27001)
Seniority
Senior, hands-on IC
