Senior Product Security Engineer
New
B
BeyondTrustCybersecurity SaaS
Remote CanadaFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering
- Required Skills
- CI/CD
Requirements
- Have 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering.
- Have hands-on experience building and operating security tooling in CI/CD pipelines.
- Have experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments.
- Have hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms.
- Understand CI/CD pipeline architecture and how to integrate security controls without disrupting developer velocity.
- Have experience building automation workflows, including scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration.
- Be familiar with container security scanning tools such as Wiz CLI, Trivy, or Snyk Container, and cloud security fundamentals.
- Understand common vulnerability classes well enough to tune tools, triage findings, and discuss severity and remediation with engineers.
- Work collaboratively across Security Testers, Architects, TPM, and engineering teams.
Responsibilities
- Build and maintain the product security tooling pipeline across the software development lifecycle.
- Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security, and Wiz CLI across repositories and CI/CD pipelines.
- Design and operate automated product security review workflows with human-in-the-loop checkpoints.
- Use Claude and LLM platforms to automate review triage, risk classification, and recommendation generation.
- Integrate security tooling into GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards.
- Tune rulesets, reduce false positives, and build feedback loops to improve findings.
- Build automation for code review triage, vulnerability detection, fix suggestions, policy enforcement, and review summaries.
- Support product incident investigations, impact scoping, emergency fixes, and root cause analysis.
- Partner with Security Testers, Architects, the TPM, and engineering teams on tooling, policies, findings, and troubleshooting.
View Full Description & ApplyYou'll be redirected to the employer's site