Overview
Product Security Engineer responsible for embedding security into the product development lifecycle and partnering with engineering teams to identify, test, analyze, and remediate security risks.
What you'll do
- Integrate security practices into the SDLC from design through release.
- Perform security reviews of architecture, source code, APIs, and software components.
- Conduct security testing including SAST, SCA, DAST/API testing, fuzz testing, and penetration testing.
- Assess vulnerabilities, triage and reproduce issues, prioritize remediation, and validate fixes.
- Develop security test cases and automation to improve security testing coverage.
- Support secure coding practices and security controls within CI/CD pipelines.
- Support threat modeling, security risk assessments, SBOM generation/maintenance, and vulnerability remediation processes.
What you'll need
- 5+ years of experience in software development, application security, or product security.
- Hands-on experience in at least one programming language (C/C++, Java, Python, or JavaScript).
- Good understanding of SDLC and testing methodologies.
- Ability to read and understand source code and work with developers on remediation.
- Experience with security testing tools such as SAST, SCA, DAST, vulnerability scanners, fuzzing, and penetration-testing tools.
- Understanding of common application/product security vulnerabilities (e.g., OWASP Top 10, CWE).
- Experience with Git, CI/CD pipelines, and DevSecOps practices.
Details
- Maintain product security evidence and documentation for regulatory compliance, including EU Cyber Resilience Act (CRA) requirements.
Read the full description and apply on the company’s own careers page.