Product Security Engineer II
New
J
JobgetherProduct Security
CanadaFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 0–2+ years
- Required Skills
- PythonGitJavascriptKotlinTypeScriptGitHub
Requirements
- 0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, or penetration testing.
- Foundational programming experience with languages such as Python, JavaScript/TypeScript, Kotlin, or similar.
- Ability to read, understand, and reason about unfamiliar codebases.
- Experience using Git, GitHub, or similar version-control workflows, including branches, commits, pull requests, and code reviews.
- Hands-on experience building, testing, securing, or analyzing software through professional work, internships, personal projects, or labs.
- Ability to write maintainable scripts or small programs to automate workflows and improve security processes.
- Understanding of common application security concepts, including OWASP Top 10 vulnerabilities, authentication, authorization, and injection risks.
- Interest in offensive security practices such as web/API testing, security certifications, or exploit development.
- Familiarity with vulnerability management concepts, including risk assessment and remediation tracking.
- Ability to evaluate security risks based on likelihood, impact, and available mitigation options.
Responsibilities
- Partner with product and engineering teams to identify application security risks and provide practical recommendations for mitigation.
- Analyze application code, configurations, pull requests, logs, and technical documentation to identify potential security issues.
- Contribute code changes, scripts, automation, tests, security checks, and tooling improvements to enhance security workflows.
- Participate in Git-based development workflows, including code reviews, pull requests, issue tracking, and remediation discussions.
- Evaluate vulnerabilities from internal testing, bug bounty programs, penetration tests, and security tools while prioritizing risks based on business impact.
- Support vulnerability management activities including triage, validation, severity assessment, remediation tracking, and reporting.
- Translate recurring security findings into scalable solutions such as secure coding guidelines, automation workflows, detection logic, and developer resources.
- Review system designs, data flows, authentication models, authorization controls, and potential abuse scenarios.
View Full Description & ApplyYou'll be redirected to the employer's site