Staff Product Security Engineer
Core
Senior Product Security Engineer focused on continuous vulnerability discovery, prevention, and offensive security testing for a cloud platform serving design engineers.
Role type
Senior IC product security engineer (offensive security & threat modeling)
Builds
Security regression test suites, threat models, and secure-by-design practices for cloud-native SaaS platforms
Domain
Cloud-native SaaS / Electronics design collaboration platform
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security testing, API security, Threat modeling, OWASP Top 10 knowledge, Manual penetration testing, Security regression testing, CI/CD security integration, Business logic vulnerability identification, Authentication/authorization/session management, Multi-tenant architecture understanding, Cloud-native systems expertise
Preferred skills
SaaS/multi-tenant platform experience, Bug bounty program participation, Red teaming, Security automation frameworks, AWS experience, Identity systems/federation (SSO/MFA), Software engineering background
Technologies
DAST, SAST, CI/CD pipelines, AWS, SSO, MFA
Responsibilities
Design and maintain security regression test suites covering critical application flows; Lead structured threat modeling sessions for existing components and new features; Perform manual and automated offensive security testing simulating real attacker behavior; Continuously assess the platform against OWASP Top 10 categories; Review new features and changes for security risks and ensure threat modeling coverage; Partner with engineering teams to reproduce issues, prioritize fixes, and validate remediation
Seniority
Senior, hands-on IC
