We are looking for a Senior Product Security Engineer to own and evolve our Application and Cloud Security programs end-to-end. You'll embed security early in the development lifecycle, drive automation-first security practices across engineering, and partner closely with DevOps and product teams to keep our platform secure by design - from code to cloud.
What Youll Do
Responsibilities:
Own, maintain, and continuously improve the Secure Design Review process, ensuring security considerations are integrated early in the development lifecycle.
Develop, implement, and maintain our Application Security Program, including controls, standards, developer enablement, and automation - managing SAST and DAST tooling, integrations, alerting, and program-wide reporting.
Develop and maintain our Cloud Security Program, defining guardrails, policies, and automated controls for secure-by-default cloud deployments, including CSPM tooling, findings triage, and alignment with internal risk and compliance processes.
Monitor and enforce SDLC security controls, ensuring consistent application of secure development practices across all engineering teams.
Partner with DevOps to design, implement, and maintain a fully secured CI/CD pipeline, embedding security checks, guardrails, and automated gates throughout build, test, and deployment stages.
Collaborate closely with engineering teams to deliver actionable guidance, model threats, advise on architecture, and support secure implementations.
Identify gaps in product, application, and cloud security posture, and drive end-to-end remediation and vulnerability management campaigns.
Define and track KPIs, metrics, and reporting for application and cloud security health.
Drive automation-first approaches to product and cloud security, reducing friction and enabling fast, safe development, while promoting a culture of security and developer empowerment.
Requirements: 5+ years of experience in Engineering / Security Engineering, including 3+ years in an Application Security or Product Security focused role.
2+ years of experience managing enterprise-wide security projects, with strong project planning and organizational skills.
Proven experience leading AppSec-focused Security Review programs and CloudSec-focused Secure Design reviews.
Hands-on experience owning the migration or deployment of AppSec tooling (SAST, DAST, ASPM, or similar).
Strong proficiency with Kubernetes, Helm, and Terraform.
Strong proficiency with Python and TypeScript.
A builder's mindset - comfortable developing in-house solutions when faced with a capability gap.
This position is open to all candidates.