Назад
Company hidden
5 дней назад

Senior Product Security Engineer

150 000 - 200 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Cloud/Application Security): Designing secure architectures and testing web applications, APIs, mobile clients, and cloud infrastructure with an accent on threat modeling, penetration testing, and secure-by-default systems. Focus on identifying exploitable design weaknesses, defining security patterns, and translating adversarial findings into actionable remediation.

Location: United States

Salary: $150,000–$200,000 base salary annually, plus potential performance bonus, benefits, and other incentive compensation.

Company

hirify.global builds a platform for intentional living that connects people with fitness, wellness, and other real-world experiences through brands such as Mindbody and ClassPass.

What you will do

  • Lead threat modeling and architecture security reviews for new products, features, and major system changes.
  • Perform hands-on penetration testing across web applications, APIs, mobile clients, and cloud infrastructure.
  • Define secure architecture patterns, reference designs, and security requirements for cloud-native engineering teams.
  • Partner with software engineering and platform teams on authentication, authorization, data protection, and service-to-service trust boundaries.
  • Review code and system designs, validate remediation through retesting, and communicate risks to technical and non-technical audiences.
  • Lead security and cross-functional initiatives while tracking emerging attack techniques and architectural practices.

Requirements

  • 5+ years of experience across security architecture, application security, and penetration testing.
  • 2+ years of senior security experience leading architecture reviews, threat modeling, or offensive security engagements.
  • Hands-on ability to independently plan and execute penetration tests using manual techniques and tools such as Burp Suite and Kali Linux.
  • Experience with SAST, DAST, SCA, WAF, and CNAPP solutions in CI/CD pipelines.
  • Strong knowledge of authentication, authorization, trust boundaries, data protection, and threat modeling methodologies such as STRIDE and attack trees.
  • Experience securing public cloud, containerized, and Kubernetes-based environments, plus proficiency in Python, .NET, or TypeScript.

Nice to have

  • Product security experience at a SaaS organization or in a security consulting practice.

Culture & Benefits

  • Opportunity to support software products serving fitness and wellness businesses.
  • Collaborative environment focused on security improvement and cross-functional partnership.
  • Compensation may include a performance bonus, benefits, and other applicable incentive plans.
  • Commitment to diversity and an inclusive workplace.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →