12 дней назад
Senior Product Security Engineer (Contract)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Product Security Engineer (Contract) (Application Security/AI): Embedding security into the product development lifecycle through architecture reviews, threat modeling, penetration testing, vulnerability remediation, and secure development practices with an accent on web, API, cloud-native, and AI-enabled applications. Focus on testing prompt injection, data leakage, insecure tool use, and authorization weaknesses while automating security controls across CI/CD.
Location: USA Remote
Company
is an AI-powered security and IT platform that unifies identity and access, endpoint security and management, and compliance automation.
What you will do
- Perform security architecture reviews, threat modeling, application security reviews, and secure code reviews.
- Conduct manual penetration testing for web, API, thick-client, and mobile applications.
- Partner with engineering teams to prioritize vulnerabilities, verify remediation, and improve secure coding practices.
- Define product security standards, engineering guardrails, reusable security patterns, and reference architectures.
- Assess AI-enabled products and LLM workflows for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
- Automate security testing and integrate security tooling into CI/CD and developer workflows.
Requirements
- USA-based remote work.
- 5+ years of experience in product security or application security.
- Experience securing web applications, APIs, microservices, and cloud-native applications.
- Experience with threat modeling, penetration testing, OWASP Top 10, OWASP API Top 10, authentication, authorization, OAuth/OIDC, and secure SDLC.
- Experience with SAST, DAST, SCA, container security, and direct collaboration with engineering teams.
Nice to have
- Experience securing AI and LLM applications.
- Experience with Kubernetes, containers, AWS, Azure, GCP, GitHub Actions, or CI/CD security.
- Experience with Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security.
- OSCP, GWAPT, GWEB, CSSLP, or CISSP certification.
Culture & Benefits
- Six-month contract at 40 hours per week.
- 100% individual and dependent medical, dental, and vision coverage.
- 401(k) with a 4% company match.
- 20 days of paid time off and a wellness week in July.
- Paid parental, family, and medical leave, plus opportunities for career growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →