Role Overview
We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention. The role is responsible for building and executing security regression testing, driving threat modeling across existing and new functionality, and conducting targeted offensive security activities.
What You Will Do
Key responsibilities include security regression testing, threat modeling, offensive security activities, and OWASP Top 10-driven vulnerability discovery. The goal is to ensure that existing functionality and new changes remain secure over time and that real vulnerabilities are discovered before customers do.
Why It Might Be a Fit
The ideal candidate will have 5+ years of experience in application/product security, a strong understanding of web application security testing, API security, and threat modeling methodologies, as well as experience with manual penetration testing, security regression testing, and CI/CD security integration.
Key Responsibilities
- Security Regression Testing
- Design and maintain security regression test suites covering critical application flows
- Ensure vulnerabilities, once fixed, are permanently prevented from recurring
- Integrate security regression into CI/CD pipelines
- Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
- Threat Modeling
- Lead structured threat modeling sessions for:
- Existing system components
- New features and architectural changes
- Identify attack surfaces, abuse cases, and trust boundaries
- Translate threats into:
- Test cases
- Security requirements
- Mitigation plans
- Ensure threat modeling becomes a continuous lifecycle activity
- Offensive Security / Red Team Activities
- Perform manual and automated security testing simulating real attacker behavior
- Focus on high-impact vulnerabilities, not theoretical findings
- Validate exploitability and business impact
- Partner with engineering teams to:
- Reproduce issues
- Prioritize fixes
- Validate remediation
- OWASP Top 10–Driven Vulnerability Discovery
- Continuously assess the platform against OWASP Top 10 categories
- Use deep product knowledge to find non-obvious, context-specific vulnerabilities
- Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
- Security Assurance for Product Changes
- Review new features and changes for security risks
- Ensure all changes are:
- Threat-modeled
- Covered by regression tests
- Act as a security gatekeeper without becoming a bottleneck:
- Enable teams with guidance and tooling
- Avoid heavy process overhead
- Collaboration & Enablement
- Work closely with:
- Engineering teams
- Architecture
- SRE / Platform teams
- Contribute to secure-by-design practices
- Support developers in understanding and fixing vulnerabilities
- Help scale security through:
- Reusable patterns
- Automation
- Security guidance
Qualifications
Required Qualifications
- 5+ years in Application / Product Security
- Bachelor's Degree or equivalent of 12 years of work experience
- Strong hands-on experience in:
- Web application security testing
- API security
- Threat modeling methodologies
- Deep understanding of OWASP Top 10
- Experience with:
- Manual penetration testing
- Security regression testing
- CI/CD security integration
- Ability to identify business logic vulnerabilities
- Strong understanding of:
- Authentication, authorization, and session management
- Multi-tenant architectures
- Cloud-native systems