Product Security Engineer
Core
Embed security into the software development lifecycle across multiple product teams by defining requirements, improving detection/prevention, and running threat modelling.
Role type
Product Security Engineer
Builds
Secure software products for data professionals across the DevOps lifecycle
Domain
Database management software, Cloud-native environments (AWS), C# ecosystem
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security governance, SAST/DAST tool tuning, Cloud and container security fundamentals, C#/.NET code review, Threat modelling, Secure-by-default standards
Preferred skills
OWASP ASVS familiarity, Java/Python knowledge, AI/LLM security guidance
Technologies
C#, .NET, React, Java, TypeScript, Python, AWS, Docker, SAST/DAST tooling
Responsibilities
Partner with engineering teams to define and operationalise security requirements across the SDLC; Audit application code for weaknesses and vulnerabilities; Own or co-own application security governance practices; Drive SAST/DAST adoption and quality; Support adoption of threat modelling for new features; Provide product security guidance for cloud-native environments; Review and assist in the development of engineering policies aligned with security best practices; Contribute secure shared libraries or perform targeted security testing/pentesting; Work with product teams to support implementation of AI, including LLMs, SLMs, and MCP.
Seniority
Mid-level, hands-on IC