Senior Product Security Engineer
New
J
JobgetherCybersecurity
USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- KubernetesAzureCI/CDTerraform
Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related technical discipline.
- Extensive experience designing and implementing secure cloud architectures for enterprise applications, cloud-native platforms, and distributed systems.
- Strong expertise with Microsoft Azure security services and cloud security architecture.
- Hands-on experience with leading CNAPP platforms such as Microsoft Defender for Cloud, Prisma Cloud, Wiz, Orca Security, or Lacework.
- Deep knowledge of Kubernetes, Azure Kubernetes Service (AKS), container security, workload protection, and image hardening.
- Experience securing Infrastructure-as-Code environments using Terraform, ARM templates, or Bicep.
- Strong background implementing DevSecOps practices, including CI/CD security integration, SAST, DAST, SCA, and policy-as-code.
- Excellent understanding of cloud governance, identity and access management, least-privilege principles, and Zero Trust security models.
- Strong analytical, problem-solving, communication, and stakeholder management skills.
- Azure Security certifications are considered an asset.
Responsibilities
- Design and lead secure architecture reviews for cloud-native, distributed, and IoT-enabled platforms, ensuring security is embedded throughout the product lifecycle.
- Define, implement, and maintain cloud security standards, guardrails, landing zones, and policy-as-code frameworks.
- Lead the implementation and optimization of Cloud-Native Application Protection Platform (CNAPP) capabilities, including CSPM, CWPP, CIEM, and identity risk analysis.
- Secure Azure Kubernetes Service (AKS), containerized workloads, Infrastructure-as-Code environments, APIs, and service-to-service communications.
- Integrate security controls into CI/CD pipelines by implementing shift-left security practices, including SAST, DAST, SCA, and container/IaC scanning.
- Develop reusable security patterns, architectural standards, and governance frameworks.
- Partner closely with engineering, DevOps, and product teams to promote secure development practices.
- Communicate security assessments, technical findings, and remediation recommendations to stakeholders.
- Drive enterprise-wide adoption of Zero Trust principles and improve cloud security posture.
View Full Description & ApplyYou'll be redirected to the employer's site