Product Security Engineer
Core
Build and improve automation to secure codebases, CI/CD pipelines, and development practices while balancing security with delivery speed.
Role type
Product Security Engineer (DevSecOps)
Builds
Automated security scanning and vulnerability management systems for code and infrastructure
Domain
Software Engineering / Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
SAST, SCA, secrets scanning, CI/CD pipeline integration, vulnerability triage, secure coding guidelines, code review
Preferred skills
Dynamic application security testing (DAST), Application Security Posture Management (ASPM), automation scripting, new security tool evaluation
Technologies
Semgrep, Dependabot, Trufflehog, GitHub Actions, ZAP
Responsibilities
Implement and maintain static application security testing (SAST) using Semgrep; Configure and improve software composition analysis (SCA) tooling; Manage secrets detection scanning and respond to findings; Integrate security scanning into CI/CD pipelines; Triage and prioritize vulnerability findings; Support dynamic application security testing (DAST) efforts; Contribute to Application Security Posture Management (ASPM) platform; Set up automation scripts for vulnerability management; Document secure coding guidelines and educate developers; Evaluate and recommend new security tools
Seniority
Mid-level, hands-on IC