Apply

Product Security Engineer

Posted 11 days agoViewed

View full description

💎 Seniority level: Junior, 2+ years

📍 Location: United States

💸 Salary: 124800.0 - 234000.0 USD per year

🔍 Industry: Financial Services

🏢 Company: SoFi👥 1001-5000💰 $750,000,000 Post-IPO Debt 12 months ago🫂 Last layoff about 1 year agoFinancial ServicesWealth ManagementLife InsuranceFinTech

🗣️ Languages: English

⏳ Experience: 2+ years

🪄 Skills: AWSDockerCloud ComputingCybersecurityKubernetesCI/CDTerraformNetworking

Requirements:
  • Experience with programming languages and automation tooling
  • Foundational understanding of Docker and Kubernetes
  • Good understanding of AWS and Well-Architected Framework security
  • Experience with Terraform and CI/CD tools
Responsibilities:
  • Deploy product security tools like SAST, DAST, and IAST
  • Build secure integrations with internal and external tools
  • Keep security tools updated with regular patching
  • Conduct proof of concept to evaluate security solutions
  • Manage cloud security and WAF solutions
Apply

Related Jobs

Apply
🔥 Product Security Engineer
Posted about 1 month ago

📍 New York Area, San Francisco Area, Washington State, Los Angeles, CA, Washington, DC, Seattle, WA

💸 134100.0 - 225000.0 USD per year

🔍 Database management systems

🏢 Company: ClickHouse👥 101-250💰 Series B about 2 years agoDatabaseArtificial Intelligence (AI)Big DataAnalyticsSoftware

  • Experience supporting engineering and product implementation efforts through threat assessments and assurance activities.
  • Strong knowledge and experience with cloud service providers (AWS, GCP, Azure), Kubernetes, and related technologies.
  • Experience operating engineering security tools and processes including code analysis and fuzzing tools.
  • Significant development and automation experience, preferably with C++.
  • Security as code mindset to solve problems with automation and scale.
  • Collaborate with engineering and product on improving existing and building new product features focused on threat modeling, assurance, and secure implementation.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, and manage vulnerabilities reported through various channels.
  • Improve and develop security assurance activities such as pentests and bug bounty programs.
  • Drive implementation and usage of engineering security tools including static and dynamic code analysis.
  • Nurture relationships between engineering and security and implement process and technology improvements.
  • Handle information security events and incidents and develop processes and automation to scale security.

AWSGCPKubernetesC++Azure

Posted about 1 month ago
Apply
Apply
🔥 Sr. Product Security Engineer
Posted about 1 month ago

📍 United States, Canada

🧭 Full-Time

🔍 Information Security

🏢 Company: Gong.io

  • 5+ years of experience in Information Security
  • Understanding of software development fundamentals
  • Knowledge of OWASP Top 10 vulnerabilities
  • Experience developing web applications with Java, JavaScript, Python, TypeScript, React
  • Expertise in AWS, Azure, GCP, Docker, Kubernetes
  • Experience with version control systems and CI/CD tools
  • Familiarity with SAST, SCA, IAST tools
  • Strong analytical and problem-solving skills
  • Excellent communication and collaboration skills
  • Lead cross-functional team activities
  • Conduct and oversee regular security assessments
  • Develop and implement security controls
  • Architect and design secure software components
  • Implement cloud security measures
  • Utilize security tools to identify vulnerabilities
  • Mentor and guide developers
  • Stay updated with security trends
  • Collaborate with other security teams

AWSDockerLeadershipPythonCloud ComputingCybersecurityJavaJavascriptKubernetesTypeScriptReactCI/CDMentoring

Posted about 1 month ago
Apply
Apply

📍 USA

💸 150000.0 - 265000.0 USD per year

🔍 Product security

🏢 Company: Navan👥 1001-5000💰 $400,000,000 Debt Financing about 2 years ago🫂 Last layoff about 1 year agoFinancial ServicesPaymentsSoftwareBusiness Travel

  • Proven experience in threat modeling and architecture reviews.
  • Experience delivering critical org-wide product security initiatives.
  • Application, cloud, and mobile penetration testing experience.
  • 8-10 years of experience in Technical Product Security and SSDLC tooling.
  • Ability to provide pragmatic security advice for web and mobile applications.
  • Experience in Agile development and cloud environments such as AWS.
  • Familiarity with application security testing tools and Continuous Integration processes.
  • Knowledge of security protocols, threats, and secure SaaS architecture.
  • Act as the tech lead for high-priority product security initiatives.
  • Ensure timely delivery of impactful initiatives.
  • Advise strategy and roadmap for the Product Security Program.
  • Drive key initiatives like Supply Chain Security, Authentication, and Authorization improvements.
  • Review product designs for security defects and conduct threat modeling.
  • Work with engineers to recommend ideal security designs.
  • Develop security tools and processes for development teams.
  • Provide training and guidance to development teams during the SSDLC.
  • Bring visibility to product vulnerabilities for prioritization and remediation.

AWSDockerGitHibernateCSSJavascriptJenkinsKubernetesJava SpringAngularTerraform

Posted 2 months ago
Apply