Ready for the next big challenge Grow your career, and join our experienced global team, transforming the world of M&A software. Be part of the team behind the teams behind the deals. Work with the best. Be the best.
Accountabilities
Position Summary
The Product Security Engineer is responsible for supporting the organization's Product Security program by partnering with software engineering teams to identify, assess, and remediate application security risks throughout the Software Development Lifecycle (SDLC). This role performs application security assessments, supports secure design and development practices, and helps integrate security into modern development and DevSecOps processes.
In addition to product security responsibilities, the engineer will receive cross-training and provide operational support to the Security Operations team, gaining experience in areas such as security monitoring, vulnerability management, and incident response. This role offers an excellent opportunity for a security professional to develop broad technical expertise while contributing to the protection of the organization's applications, infrastructure, and information assets.
Duties And Responsibilities
- Review and validate findings from Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and container security tools.
- Partner with software engineering teams to identify, prioritize, and remediate application security vulnerabilities.
- Participate in secure architecture reviews, design reviews, and threat modeling exercises throughout the Software Development Lifecycle (SDLC).
- Support penetration testing activities and assist with remediation tracking and validation.
- Integrate and promote security best practices within CI/CD pipelines and DevSecOps processes.
- Assist in developing and maintaining secure coding standards, application security guidance, and security documentation.
- Research emerging application security threats and recommend appropriate mitigations.
- Collaborate with Product Security, Engineering, DevOps, and Infrastructure teams to continuously improve the organization's application security posture.
- Assist with security monitoring, alert triage, and investigation of potential security events.
- Participate in incident response activities, including investigation, containment, recovery, and post-incident reviews.
- Support enterprise vulnerability management activities across applications and infrastructure.
- Assist with maintaining security tools, documentation, and operational procedures.
- Participate in security awareness initiatives, tabletop exercises, and continuous improvement efforts.
- Crosstrain with the Security Operations team to support operational security processes and technologies.
Qualifications
- Solid understanding of secure software development lifecycle (SSDLC) principles and secure coding practices.
- Working knowledge of common application security vulnerabilities, including the OWASP Top 10 and secure design principles.
- Familiarity with application security testing tools, including SAST, DAST, SCA, and vulnerability management platforms.
- Experience with one or more programming or scripting languages such as Java, C#, JavaScript, Python, Go, PowerShell, or Bash.
- Understanding of RESTful APIs, web application architectures, and modern software development methodologies.
- Familiarity with source code management systems (Git) and CI/CD pipelines.
- Knowledge of cloud platforms (AWS, Azure, or Google Cloud) and container technologies (Docker, Kubernetes) is preferred.
- Familiarity with security monitoring technologies such as SIEM, EDR, or SOAR platforms is preferred.
- Strong analytical, problem-solving, and troubleshooting skills.
- Excellent communication and interpersonal skills with the ability to collaborate effectively across technical teams.
- Ability to manage multiple priorities while maintaining attention to detail.
- Strong written and verbal English communication skills.
Education
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Software Engineering, or related technical discipline.
Relevant industry certifications such as CompTIA Security+, CSSLP, GWAPT, OSWE, or similar certifications are considered a plus.
Experience
- 2–5 years of experience in Application Security, Software Development, Information Security, Software Engineering, or related technical discipline.
Relevant industry certifications such as CompTIA Security+, CSSLP, GWAPT, OSWE, or similar certifications are considered a plus.