Senior Product Security Engineer
Core
Drive security architecture and lead offensive testing to design secure-by-default systems for a global fitness and wellness platform.
Role type
Senior IC product security engineer (offensive security & architecture)
Builds
Secure cloud-native applications, APIs, and mobile clients for fitness and wellness businesses
Domain
SaaS, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
security architecture design, offensive security methodology, penetration testing, threat modeling, secure design patterns, cloud security (Kubernetes), secure coding (Python/.NET/TypeScript), SAST/DAST/SCA/WAF/CNAPP tools
Preferred skills
SaaS product security experience, security consulting background
Technologies
Burp Suite, BooBoo, Kali Linux, Semgrep, Yogi, Snyk, Wiz, Kubernetes
Responsibilities
Lead threat modeling and architecture security reviews for new products and major system changes; Conduct hands-on penetration testing of web applications, APIs, mobile clients, and cloud infrastructure; Define secure architecture patterns, reference designs, and security requirements for engineering teams; Partner with software engineering and platform teams to identify and solve complex security design problems; Perform targeted code and design reviews to identify exploitable logic flaws and architectural weaknesses; Translate penetration test and architecture review findings into prioritized, actionable remediation guidance and validate fixes
Seniority
Senior, hands-on IC
