Product Security Engineer
Core
Securing codebases, CI/CD pipelines, and development practices to reduce risk without slowing down software delivery.
Role type
Product Security Engineer
Builds
Automation for vulnerability management and secure coding practices
Domain
Software Engineering / Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
SAST, SCA, secrets scanning, CI/CD pipeline integration, vulnerability triage, secure coding guidelines, automation scripting
Preferred skills
Ruby, Python, JavaScript, Go
Technologies
Semgrep, Dependabot, Trufflehog, GitHub Actions, ZAP
Responsibilities
Implement and maintain static application security testing (SAST) using Semgrep; Configure and improve software composition analysis (SCA) tooling; Manage secrets detection scanning and respond to findings; Integrate security scanning into CI/CD pipelines; Triage and prioritize vulnerability findings; Support dynamic application security testing (DAST) efforts; Contribute to Application Security Posture Management (ASPM) platform; Set up and configure automation scripts; Document secure coding guidelines and educate developers; Evaluate and recommend new security tools
Seniority
Mid-level, hands-on IC