Senior Product Security Engineer

New
J
JobgetherCybersecurity
USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
KubernetesAzureCI/CDTerraform

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or a related technical discipline.
  • Extensive experience designing and implementing secure cloud architectures for enterprise applications, cloud-native platforms, and distributed systems.
  • Strong expertise with Microsoft Azure security services and cloud security architecture.
  • Hands-on experience with leading CNAPP platforms such as Microsoft Defender for Cloud, Prisma Cloud, Wiz, Orca Security, or Lacework.
  • Deep knowledge of Kubernetes, Azure Kubernetes Service (AKS), container security, workload protection, and image hardening.
  • Experience securing Infrastructure-as-Code environments using Terraform, ARM templates, or Bicep.
  • Strong background implementing DevSecOps practices, including CI/CD security integration, SAST, DAST, SCA, and policy-as-code.
  • Excellent understanding of cloud governance, identity and access management, least-privilege principles, and Zero Trust security models.
  • Strong analytical, problem-solving, communication, and stakeholder management skills.
  • Azure Security certifications are considered an asset.

Responsibilities

  • Design and lead secure architecture reviews for cloud-native, distributed, and IoT-enabled platforms, ensuring security is embedded throughout the product lifecycle.
  • Define, implement, and maintain cloud security standards, guardrails, landing zones, and policy-as-code frameworks.
  • Lead the implementation and optimization of Cloud-Native Application Protection Platform (CNAPP) capabilities, including CSPM, CWPP, CIEM, and identity risk analysis.
  • Secure Azure Kubernetes Service (AKS), containerized workloads, Infrastructure-as-Code environments, APIs, and service-to-service communications.
  • Integrate security controls into CI/CD pipelines by implementing shift-left security practices, including SAST, DAST, SCA, and container/IaC scanning.
  • Develop reusable security patterns, architectural standards, and governance frameworks.
  • Partner closely with engineering, DevOps, and product teams to promote secure development practices.
  • Communicate security assessments, technical findings, and remediation recommendations to stakeholders.
  • Drive enterprise-wide adoption of Zero Trust principles and improve cloud security posture.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now