Назад
Company hidden
10 дней назад

Senior Product Security Engineer (Cloud Security)

150 000 - 175 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Cloud Security): Designing secure-by-default architectures and conducting hands-on penetration testing across web applications, APIs, mobile clients, and cloud infrastructure with an accent on threat modeling, secure design patterns, and adversarial validation. Focus on identifying exploitable architecture and logic flaws, solving complex authentication and trust-boundary problems, and translating findings into actionable remediation guidance.

Salary: $150,000–$175,000 base salary in the United States, plus potential performance bonus, benefits, and other incentive compensation.

Company

hirify.global, part of Playlist alongside Mindbody, provides a platform for fitness, wellness, and other real-world experiences.

What you will do

  • Lead threat modeling and security architecture reviews for new products, features, and major system changes.
  • Conduct manual penetration testing across web applications, APIs, mobile clients, and cloud infrastructure.
  • Define secure architecture patterns, reference designs, and security requirements for cloud-native systems.
  • Partner with engineering and platform teams on authentication, authorization, data protection, and service-to-service trust boundaries.
  • Review code and designs for exploitable logic flaws, insecure assumptions, and architectural weaknesses.
  • Translate findings into prioritized remediation guidance and validate fixes through retesting.

Requirements

  • 5+ years of experience across security domains, focused on security architecture, application security, and penetration testing.
  • 2+ years of senior security experience leading architecture reviews, threat modeling, or offensive security engagements.
  • Hands-on proficiency with penetration testing tools and techniques, including Burp Suite, BooBoo, and Kali Linux.
  • Experience with SAST, DAST, SCA, WAF, and CNAPP solutions in CI/CD pipelines.
  • Experience securing public cloud, containerized, and Kubernetes-based architectures.
  • Proficiency in Python, .NET, or TypeScript for exploit proof-of-concepts, security automation, or secure design prototypes.

Nice to have

  • Product security experience in a SaaS organization or security consulting practice.

Culture & Benefits

  • Collaborative product security work supporting fitness and wellness software products.
  • Opportunity to lead cross-functional security initiatives and communicate risk to technical and non-technical audiences.
  • Commitment to a diverse and inclusive workplace.
  • Benefits and potential performance-based incentive compensation are included in the overall package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →