Назад
Company hidden
2 дня назад

Product Security Engineer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Mexico
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (Cybersecurity): Maintaining and maturing a product security program for cloud-based software with an accent on DevSecOps, application security testing, and vulnerability remediation. Focus on integrating SAST, DAST, SCA, and API security tooling into CI/CD pipelines, reviewing system designs, and securing development, testing, and hosting environments.

Location: Hybrid in Mexico City, with office attendance on Tuesday, Wednesday, and Thursday at the Reforma office

Company

hirify.global develops a cloud-native Identity Security Platform that secures human and machine identities through centralized authorization and AI-powered intelligence.

What you will do

  • Maintain and mature product security tooling, including SAST, DAST, SCA, and ASPM solutions.
  • Assess software vulnerabilities and guide developers and administrators through remediation.
  • Secure environments used to develop, test, and host hirify.global software and cloud-based services.
  • Execute and improve the company’s secure software development lifecycle program.
  • Perform security reviews of software system designs and configurations.
  • Support teams in analyzing and responding to product and service security questions and issues.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • At least 2 years of professional experience in a product security role.
  • Experience integrating security testing tools into CI/CD pipelines and using source code management systems such as ADO Repos, GitLab, or GitHub.
  • Experience with SAST, DAST, IAST, SCA, containers, authentication and authorization methods, including OAuth, SAML2, Kerberos, and x509 certificates.
  • Ability to script and automate with Python, JavaScript, PowerShell, or similar languages.
  • Strong verbal and written communication skills for explaining technical concepts.

Nice to have

  • Software engineering or development experience.
  • Experience with ASPM tools and AI-assisted software security testing.
  • Knowledge of NIST, BSIMM, OWASP Top 10, FedRAMP, or similar security frameworks and standards.
  • Understanding of cloud security for containers, serverless functions, network segmentation, and access management.
  • Cybersecurity certifications and proficiency with Azure and AWS.

Culture & Benefits

  • Meaningful work protecting human and machine identities for large organizations.
  • Collaborative, innovative environment focused on respect, integrity, ownership, and continuous adaptation.
  • Competitive salary and a bonus program.
  • Healthcare insurance, pension or retirement matching, life insurance, and an employee assistance program.
  • Paid time off and company holidays.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →