Search by job, company or skills

Product Security Engineer (Cloud, DevSecOps)

  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Founded in 2016, Katalon is the category leader in AI-augmented software testing, empowering hybrid testers—those blending manual, automation, and AI skills—to deliver exceptional digital experiences. Katalon enables software teams of any size to deliver world-class customer experiences faster, easier, and more efficiently.

Since its first launch, Katalon has experienced tremendous growth, serving more than 30,000 teams across 80+ countries, many of which are in the Fortune Global 500. Katalon has been named a G2 Leader in software testing for 11 consecutive quarters and a Great Place to Work for three consecutive years.

About The Role

We're looking for a hands-on Product Security Engineer to join Katalon's Security team. You'll work closely with our Product Security Lead, owning the operational security layer cloud infrastructure security tooling, monitoring, and incident response and progressively taking on Application Security, DevSecOps, and AI Security as your scope matures.

This is a mid-level role. We expect real working experience and a problem-solving mindset, not just certifications or theoretical knowledge.

How This Role Grows

Your immediate ownership is cloud security and security operations—bringing our operational security to a place where it runs reliably, with strong detection coverage and clear playbooks.

As you build mastery in these areas, your scope will naturally expand into Application Security, DevSecOps, and AI Security—areas the team is actively investing in and where your contributions will have direct product impact.

The stronger you become on the operations side, the more opportunities you'll have to move toward higher-complexity security work. There is no artificial boundary between these responsibilities; this is one continuous role that evolves with you.

What You'll Own

Cloud & Infrastructure Security

  • Maintain and strengthen cloud security configurations across AWS, Azure, and GCP environments.
  • Drive security hardening for Kubernetes, API gateways, databases, servers, and cloud workloads.

Security Monitoring & Incident Response

  • Monitor security alerts from SIEM, EDR, infrastructure logs, and SaaS platforms.
  • Investigate and respond to suspicious activities, phishing attempts, malware, and account compromise incidents from detection through resolution.

Detection Engineering

  • Perform log analysis to triage alerts and determine root causes.
  • Develop and continuously improve detection rules and incident response playbooks to increase coverage while reducing false positives.

Vulnerability Management

  • Conduct vulnerability scanning and assessment across infrastructure, cloud workloads, containers, and third-party integrations.
  • Prioritize findings based on real-world exploitability and partner with DevOps and IT teams to drive remediation.

Identity & Access Control

  • Monitor IAM permissions, SSO, MFA, and privileged access management.
  • Proactively enforce the principle of least privilege across cloud and SaaS environments.

Governance & Collaboration

  • Support audit evidence collection for ISO 27001, SOC 2, and ISO 42001.
  • Maintain clear documentation for incidents, vulnerabilities, and access reviews.
  • Communicate security risks effectively to both technical and non-technical stakeholders.

As Your Scope Expands

Application Security & DevSecOps

  • Perform secure code reviews, API security assessments, and threat modeling for new product features.
  • Integrate security tooling—including SAST, DAST, SCA, and secret scanning—into CI/CD pipelines alongside DevOps and engineering teams.

Penetration Testing

  • Participate in and progressively take ownership of penetration testing activities across the Katalon product suite.

AI & LLM Security

  • Assess AI-specific security risks, including Prompt Injection, Insecure Output Handling, and Data Poisoning.
  • Help secure Katalon's AI Agents by applying best practices and frameworks such as the OWASP Top 10 for LLMs.

Job Requirements

  • 3–5 years of hands-on experience in Security Operations, Cloud Security, or a related field.
  • Strong experience with enterprise SIEM/logging platforms and EDR solutions, with the ability to independently analyze logs, triage alerts, and build detections.
  • Practical knowledge of cloud security (AWS, Azure, or GCP), IAM, SSO, MFA, and server hardening.
  • Ability to write automation scripts using Python, Bash, PowerShell, or similar languages.
  • Strong documentation and communication skills, with experience collaborating across IT, DevOps, and engineering teams.
  • A genuine desire to grow into Application Security, Penetration Testing, and AI Security.

Nice to Have

  • Familiarity with AI Security concepts, LLM guardrails, and securing AI Agents.
  • Understanding of Secure SDLC, the OWASP Top 10, and web/API security fundamentals.
  • Experience with DevSecOps, CI/CD pipelines, and security tooling integration.
  • Hands-on exposure to Kubernetes or container security.
  • Experience supporting ISO 27001, SOC 2, or other compliance audits.
  • Certifications such as AWS Security Specialty, BTL1, CySA+, CEH, OSCP, or BSCP are considered a plus, but are not required.

You'll Thrive Here If You Can

  • Investigate a security alert independently and clearly explain what happened and why it matters.
  • Read and correlate logs from cloud, endpoint, server, and SaaS platforms without requiring step-by-step guidance.
  • Partner with engineering and DevOps teams to drive vulnerability remediation through completion—not just create tickets.
  • Review IAM configurations and proactively identify over-privileged access.
  • Demonstrate genuine curiosity about how systems are compromised—and how to build resilient systems that aren't.

Job Benefit

At Katalon, we bring together self-starting, open-minded, and talented people while actively promoting a transparent and growth-enabling working environment. But don't just take our word for it. Take a better look below!

  • Total Remuneration: Satisfying your financial goals through competitive compensation and periodic performance bonuses.
  • Well-being & Work-life Balance: Staying healthy through comprehensive health plans, flexible work arrangements, and generous paid leaves.
  • Statutory Compliance: Labor compliance with local regulations that ensure employee security.
  • Work Facilities & Accommodation: Top-notch equipment, supportive allowances, and A-class facilities.
  • Diversity, Equity, Engagement, & Inclusion: Becoming part of a global team that celebrates differences, equal opportunity, and meaningful employee recognition.
  • Growth & Rewards: Thriving professionally through employee enablement, a culture of trust, and rewarding performance.

Katalon is proud to be an equal-opportunity employer. We care about our people and celebrate our differences. We want to work with talented, collaborative, and innovative people. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other characteristics protected by law.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151641903

Similar Jobs

India, Remote

Skills:

GcpDatadogPrometheusAzureTerraformGrafanaJenkinsAnsibleGitHub ActionsAI-OpsGCP Operations SuiteAzure Monitor

Beware of Scammers

We don’t charge money for job offers