Security Engineer
Core
Building secure, resilient, and scalable products by embedding security into the software development lifecycle.
Role type
Senior Product Security Engineer
Builds
Secure web, mobile, and backend applications; cloud-native microservices architectures
Domain
Software Engineering / Application Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security principles, secure software development practices, vulnerability management, security automation, Threat Modeling, authentication and authorization, encryption standards, access management, cloud security (AWS/Azure/GCP), container and Kubernetes security, API security, security tooling (SAST/DAST/SCA), programming/scripting (Python/Java/Go/JavaScript/Bash)
Preferred skills
DevSecOps practices, Infrastructure as Code security, penetration testing, red team assessments
Technologies
Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, SonarQube, Terraform, CloudFormation, Kubernetes, AWS, Azure, Google Cloud Platform
Responsibilities
Design and maintain product security strategies across the SDLC; integrate security best practices into application architecture and deployment; conduct security assessments, code reviews, and vulnerability analyses; identify and remediate security vulnerabilities; develop secure coding guidelines; implement security controls and authentication mechanisms; automate security testing in CI/CD pipelines; monitor security alerts and coordinate incident remediation; perform security reviews for APIs and cloud infrastructure; ensure compliance with security standards (OWASP, NIST, ISO 27001, SOC 2)
Seniority
Senior, hands-on IC