Senior Product Security Engineer (InfoSec)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Product Security Engineer (InfoSec): Securing products by embedding security into every stage of development with an accent on automation and AI-driven tooling. Focus on managing vulnerability processes, integrating security into CI/CD pipelines, and remediating complex vulnerabilities using SAST/DAST and AI-assisted techniques.
Location: Hybrid in Bulgaria
Company
provides high-performance data store and caching solutions used by thousands of companies worldwide to power fast applications.
What you will do
- Own and operate vulnerability management processes across products from discovery to reporting.
- Implement and manage AI-based security scanning tools to improve coverage and signal quality.
- Conduct product security assessments using SAST, DAST, and LLM-assisted code reviews.
- Partner with engineering teams to triage findings and drive remediation of vulnerabilities.
- Integrate security tools and workflows into CI/CD pipelines for continuous automated testing.
- Manage and triage findings from bug bounty platforms such as HackerOne.
Requirements
- 6+ years of experience in application security or product security.
- Strong experience operating vulnerability management programs and using Jira for issue tracking.
- Experience working with bug bounty platforms (HackerOne or Bugcrowd).
- Practical knowledge of security tools (SAST, DAST, dependency scanning) and OWASP Top 10.
- Experience with AI/ML-driven security tools or LLM-assisted code review workflows.
- Familiarity with Kubernetes, containers, and microservices architectures.
Culture & Benefits
- Competitive compensation package including salary and equity grants.
- Hybrid work options with home internet and phone monthly allowances.
- One-time home-office setup allowance.
- 25 days of vacation time.
- Comprehensive health, dental, and personal life insurance, including Critical Illness Cover.
- Office perks including lunch, snacks, and Multisport/CoolFit cards.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →