Jobgether

Senior Product Security Engineer

Jobgether United States

Internet Marketplace Platforms · 11-50 employees

15 h ago
Remote security Senior (5-10 yrs) Contractor Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will perform security design reviews, threat modeling, and penetration testing to ensure products are secure-by-design. Additionally, you will collaborate with engineering teams to automate security workflows and remediate vulnerabilities across cloud-native and AI-enabled services.

What they look for

Product security Application security Threat modeling Penetration testing Secure code review Vulnerability management AI security Security automation CI/CD OAuth OIDC Cloud security SAST DAST SCA Kubernetes

Requirements

Candidates must have at least 5 years of professional experience in product or application security with strong knowledge of modern architectures and security standards. Proficiency in threat modeling, penetration testing, and securing CI/CD pipelines is essential for this role.

Benefits

Medical coverage Dental coverage Vision coverage 401(k) with 4% company match 20 days of paid time off Wellness week Paid family and medical leave Paid parental leave

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Product Security Engineer based in the United States.

This is a hands-on product security engineering role focused on embedding security throughout the software development lifecycle. You will identify risks early, assess modern applications and AI-enabled services, and work directly with engineering teams to build secure-by-design products. The role spans application security, threat modeling, penetration testing, secure code review, vulnerability management, AI security, and security automation. You will collaborate closely with Engineering, Product, Infrastructure, Cloud Security, and Compliance teams while helping maintain developer velocity. You will also improve security tooling and automation across CI/CD workflows, reducing manual effort and strengthening security coverage. As a senior technical contributor, you will help establish security standards, reusable patterns, and engineering guardrails across a modern cloud-native environment. This six-month, full-time contract is an opportunity to tackle challenging security problems across web, API, cloud, mobile, and AI technologies.

\n

Accountabilities

• Perform security design and architecture reviews for new products, features, applications, and services.

• Conduct threat modeling across applications, APIs, microservices, and AI-enabled services to identify and mitigate security risks early.

• Evaluate application security throughout the software development lifecycle and recommend practical improvements.

• Partner directly with engineering teams to prioritize, remediate, and validate security vulnerabilities.

• Review authentication, authorization, access control, OAuth, and OIDC implementations.

• Conduct manual penetration testing across web applications, APIs, thick-client applications, and mobile applications.

• Validate findings from third-party penetration tests and verify that identified vulnerabilities have been effectively remediated.

• Perform secure code reviews and help engineering teams adopt stronger secure coding practices.

• Define and improve Product Security standards, engineering guardrails, reusable security patterns, and reference architectures.

• Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.

• Partner with engineering teams to prioritize vulnerability remediation and monitor remediation SLAs and security metrics.

• Assess AI-enabled products and LLM integrations for security risks, including prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.

• Help establish secure AI engineering standards and contribute to the secure development of AI-enabled products.

• Improve automated security testing throughout CI/CD pipelines and integrate security tools into developer workflows.

• Develop scripts, automation, and internal tooling that reduce repetitive security work and improve engineering efficiency.

• Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams to align security priorities with business and product objectives.

• Support customer security questionnaires and assist Sales Engineering with product security discussions when required.

Requirements

• 5+ years of professional experience in Product Security, Application Security, or a closely related security engineering discipline.

• Strong understanding of modern application architectures and experience securing web applications, APIs, microservices, and cloud-native applications.

• Demonstrated experience performing threat modeling and application security assessments.

• Hands-on experience conducting penetration testing and validating security vulnerabilities.

• Strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.

• Strong understanding of authentication, authorization, OAuth, OIDC, and secure software development lifecycle practices.

• Experience with SAST, DAST, SCA, container security, and related application security tooling.

• Proven ability to work directly with software engineering teams and translate security requirements into practical, developer-friendly solutions.

• Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to technical and non-technical stakeholders.

• Experience securing AI or LLM-powered applications is preferred.

• Experience with Kubernetes and containerized environments is advantageous.

• Familiarity with cloud security across AWS, Azure, or GCP is a plus.

• Experience securing GitHub Actions or other CI/CD environments is desirable.

• Familiarity with tools such as Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security is beneficial.

• Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.

• Strong analytical and problem-solving abilities, with a proactive approach to identifying risks and developing practical remediation strategies.

• Ability to operate effectively in a fast-moving environment and balance security rigor with developer productivity.

Benefits

• Six-month, full-time contract at 40 hours per week.

• Competitive compensation.

• 100% individual and dependent medical, dental, and vision coverage.

• 401(k) with a 4% company match.

• 20 days of paid time off.

• Dedicated wellness week during the first week of July.

• Paid family and medical leave.

• Up to 16 weeks of paid leave for new parents.

• Exciting opportunities to work on challenging security and technology initiatives.

• Career growth and professional development opportunities.

• Inclusive and collaborative environment that values diverse perspectives, backgrounds, and experiences.

• Remote work opportunity within the United States.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles