TRM Labs, Inc. logo

Product Security Engineer

TRM Labs, Inc.
Posted this week

LOCATION

United States · Remote

EXPERIENCE

8+ Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

Vulnerability ManagementApplication SecuritySecure Coding PracticesThreat Modeling

Job description

Overview

Build mission-critical infrastructure and practices that support application security for TRM products as they are built and deployed. Work with engineering and engineering leadership on technical strategy, company-wide best practices and implementation.

What you'll do

  • Lead application security reviews and threat modeling, including secure code review, architectural design and testing.
  • Develop automated testing and mature the Secure SDLC.
  • Own and perform application security vulnerability management.
  • Coordinate penetration testing engagements.
  • Support software engineers and product teams by developing application security best practices.
  • Develop and maintain the bug bounty program.
  • Bootstrap platform security initiatives that help protect TRM data.
  • Foster security champions within engineering teams and coordinate secure code training to inspire a culture of security across the engineering organization.
  • Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business.
  • Embed security testing and reviews within the Product Shipping Framework and CI/CD pipelines.
  • Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews.
  • Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments.

What you'll need

  • Minimum 8 years of experience in software development and testing.
  • BS (or equivalent) in Computer Science, Computer Engineering or a related field.
  • Proficiency in software development languages: Python, NodeJS and React.
  • Strong understanding of encryption, authentication and authorization protocols.
  • Deep experience with common software flaws, including OWASP and CWE, testing methodologies and common security tooling for testing.
  • Professional experience with open source, commercial or native security solutions for cloud providers such as GCP and AWS.
  • Experience with modern secure software development lifecycles, threat modeling and best practices.
  • Experience conducting efficient and comprehensive code security reviews on a daily or weekly basis.
  • Experience triaging and remediating vulnerabilities in software packages or libraries.
  • Experience with software security tools such as GitHub Advanced Security or other SAST, DAST and SCA tools.
  • Experience with web application testing frameworks such as Burp Suite and OWASP ZAP.
  • Experience with threat modeling tools such as OWASP Threat Dragon.
  • Experience working in a previous agile-based software development role.
  • Experience red teaming or penetration testing applications and infrastructure.
  • Professional experience with cloud providers such as GCP and AWS, modern secure software development lifecycles and best practices.
  • Strong written and verbal communication skills.

Nice to have

  • Security certifications such as OSCP, CEH or GWAPT.
  • Familiarity with security frameworks such as NIST SP 800-171 and SSDF.

Details

  • Location: United States.
  • Team time zones include Eastern Standard Time (EST - GMT-4), Pacific Standard Time (PST - GMT-7) and Central European Summer Time (CET - GMT+2).

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Product Security Engineer