Назад
Company hidden
5 дней назад

Staff Product Security Engineer (Web Application Security)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer (Web Application Security): Building and maintaining security regression coverage for a cloud-based electronics design platform with an accent on threat modeling, API security, and OWASP Top 10 vulnerability discovery. Focus on manual and automated offensive testing, identifying business-logic flaws, integrating security checks into CI/CD, and validating remediation across multi-tenant cloud systems.

Location: Wrocław, Poland; onsite, remote work is not available

Competitive salary and benefits package; exact compensation is provided during the hiring process.

Company

A global software company within the hirify.global Group, building Altium 365, a cloud platform for electronics design collaboration and product development.

What you will do

  • Build and maintain security regression test suites for authentication, access control, APIs, data flows, and other critical application paths.
  • Integrate security regression testing into CI/CD pipelines and define coverage targets for security-critical functionality.
  • Lead threat-modeling sessions for existing components, new features, and architectural changes; identify attack surfaces, abuse cases, and trust boundaries.
  • Conduct manual and automated offensive security testing, validate exploitability and business impact, and support remediation with engineering teams.
  • Continuously assess the platform against the OWASP Top 10, including context-specific vulnerabilities, logic flaws, and abuse paths.
  • Partner with engineering, architecture, and SRE/platform teams to scale secure-by-design practices through automation, reusable patterns, and security guidance.

Requirements

  • 5+ years of experience in application or product security.
  • Bachelor's degree or equivalent experience, including 12 years of professional experience.
  • Hands-on experience with web application security testing, API security, threat modeling, manual penetration testing, and security regression testing.
  • Deep understanding of the OWASP Top 10 and the ability to identify business-logic vulnerabilities.
  • Strong knowledge of authentication, authorization, session management, multi-tenant architectures, and cloud-native systems.
  • Ability to read and write code, integrate security into CI/CD, and collaborate with engineering teams on vulnerability remediation.

Nice to have

  • Experience with SaaS or multi-tenant platforms, bug bounty programs, red teaming, or security automation frameworks.
  • Knowledge of AWS and identity systems, including SSO and MFA.

Culture & Benefits

  • Regular employment with a competitive benefits package alongside the salary.
  • Opportunity to contribute to a global cloud software platform for electronics innovation.
  • Collaboration across engineering, architecture, and SRE/platform functions.
  • Work environment focused on innovation, global collaboration, and secure-by-design development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →