Software Product Security EngineerOverview / Summary We are seeking a Software Product Security Engineer to work closely with development and security teams to identify, prioritize, and remediate software security risks. This role will help translate security risks into practical actions while supporting secure architecture, application security, cloud security, software development, and cybersecurity compliance activities.
The ideal candidate understands the developer perspective while bringing a strong cybersecurity and risk-management mindset. This role requires the ability to work through technical and business considerations and help development and business teams make appropriate security decisions.
Key Responsibilities - Guide development teams in triaging and remediating findings from SAST, DAST, SCA, and bug bounty/vulnerability reports.
- Serve as a liaison between engineering and security stakeholders, translating security risks into practical and prioritized actions.
- Consult on secure architecture, API security, IAM, logging, and secure coding practices across Azure, GCP, and AWS cloud platforms.
- Integrate and automate security testing within CI/CD pipelines in collaboration with platform and DevOps teams.
- Help development teams manage technical debt, upgrade paths, software supply chain risks, and SBOM-related risks.
- Communicate complex technical risks clearly to engineering and business stakeholders.
- Support cybersecurity compliance activities.
- Work with development and business teams to evaluate technical and security considerations and arrive at appropriate security decisions.
Required Qualifications - Bachelor's degree.
- 6+ years of experience in IT.
- 4+ years of development experience.
- Practical experience in two coding languages or advanced practical experience in one coding language.
- Experience with software development and the Software Development Lifecycle.
- Experience with cybersecurity and web applications/web technologies.
- Experience with scripting and troubleshooting/problem solving.
- Experience with TCP/IP and network protocols and standards.
- Experience with data integrity and data/analytics dashboards.
- Experience with application development and software development.
- Knowledge of cybersecurity, information security, and network security.
- Knowledge of IAM, JSON, Python, Java, JavaScript, or other listed development technologies is applicable based on experience.
- Strong analytical and problem-solving skills.
Preferred Qualifications - Master's degree.
- Certifications such as CISSP, CISA, or CISM.
- Experience with cloud computing and cloud infrastructure.
- Experience with Google Cloud Platform.
- Experience with risk management, risk assessment, and business risk management.
- Experience with solution/application architecture.
- Experience with penetration testing and tools such as Burp Suite.
- Experience with Spring Security, Spring Boot, J2EE, Apache Tomcat, React, JQuery, Salesforce, Pega, Dynatrace, or SharePoint.
- Knowledge of ISO 27001.
- Experience with disaster recovery, change control, configuration management, and tooling.
- Experience with Linux, network security, and application design.
#LI-Hybrid #LI-KK1