Search by job, company or skills

Product Security Engineer

  • Posted 7 days ago
  • Be among the first 10 applicants

Job Description

Job information:

Level: Mid - Senior

Location: 5th Floor, Victory Tower, 318-320 Nguyen Oanh, Go Vap Ward, HCMC

About the Role

We are looking for a Product Security Engineer with an offensive security mindset to proactively identify, validate, and help eliminate security risks across our products and cloud infrastructure.

You will operate as an internal security researcher, continuously assessing the security posture of our web applications, APIs, cloud infrastructure (AWS), source code, and software development lifecycle to identify vulnerabilities before attackers do.

Beyond vulnerability research, you will continuously improve the security posture of our products through proactive security reviews, attack simulations, runtime monitoring, security automation, and close collaboration with engineering teams.

Key Responsibilities

1. Product Security Ownership

Own the security posture of assigned products throughout the entire Software Development Lifecycle (SDLC).

Responsibilities include:

• Act as the security champion for assigned products.

• Continuously assess security risks throughout the product lifecycle.

• Work closely with Engineering, DevOps and Product teams to improve product security.

• Ensure security is considered from design through production.

2. Product Security Assessment

Perform security assessments across:

• Web Applications

• REST / GraphQL APIs

• Backend Services

• Mobile APIs (where applicable)

• AWS Cloud Infrastructure

• Kubernetes & Docker

• Internal Services

• Authentication & Authorization

• CI/CD Pipelines

• Third-party Integrations

Conduct:

• Manual Security Assessments

• Penetration Testing

• Architecture Security Reviews

• Secure Design Reviews

• Threat Modeling

3. Offensive Security & Vulnerability Research

Proactively discover, validate and assess security vulnerabilities, including:

Web & API Security

• Broken Access Control

• IDOR

• Authentication & Authorization Bypass

• Business Logic Flaws

• Privilege Escalation

• SQL / NoSQL Injection

• Command Injection

• SSRF

• XSS

• CSRF

• XXE

• Path Traversal

• File Upload Vulnerabilities

• Insecure Deserialization

• Open Redirect

• Rate Limit Bypass

• API Abuse

• Session Management Weaknesses

Cloud & Infrastructure Security

• IAM Misconfigurations

• Excessive Privileges

• Cross-account Access Risks

• IAM Trust Relationship Issues

• Public S3 Buckets

• Exposed Secrets

• KMS & Secrets Manager Misconfigurations

• Security Group Misconfigurations

• Open Management Ports

• Kubernetes RBAC & IRSA Misconfigurations

• Container Escape Risks

• TLS/SSL Weaknesses

• DNS Misconfigurations

• Sensitive Information Disclosure

Dependency & Supply Chain Security

• CVE Assessment

• Dependency Vulnerability Analysis

• Open Source Component Risks

• Outdated Packages

• Software Supply Chain Security

4. Source Code Security Assessment

Perform manual and AI-assisted source code security reviews.

Responsibilities include:

• Identify insecure coding practices.

• Review authentication and authorization logic.

• Review cryptography implementation.

• Review session management.

• Identify business logic vulnerabilities.

• Validate security fixes before release.

• Work with development teams to eliminate security weaknesses early.

5. Security Monitoring & Threat Detection

Continuously monitor production environments to identify abnormal behaviors and potential attacks.

Monitor and investigate:

• Abnormal Traffic Patterns

• DDoS / DoS Attempts

• Brute-force Attacks

• Credential Stuffing

• Automated Bot Activities

• API Abuse

• Rate Limit Bypass Attempts

• Reconnaissance Activities

• Vulnerability Scanning

• Exploitation Attempts

• Suspicious Requests

• WAF Events

• AWS GuardDuty Findings

• AWS CloudTrail Events

• Suspicious IAM Activities

• Privilege Escalation Attempts

• Sudden Error Rate Increases

• Unusual CPU, Memory, Network or Application Workloads that may indicate attacks or compromise

Recommend and implement improvements to:

• Detection Rules

• Alerting

• Monitoring

• Security Controls

• Mitigation Strategies

6. Security Validation

• Develop Proof-of-Concepts (PoCs)

• Validate exploitability

• Assess business impact

• Prioritize vulnerabilities using CVSS

• Eliminate false positives

• Recommend remediation strategies

• Verify fixes after remediation

7. Secure SDLC

Drive security integration throughout the Software Development Lifecycle.

Responsibilities include:

• Security Code Reviews

• Threat Modeling

• Security Requirements Definition

• Secure Design Reviews

• Security Architecture Reviews

• Security Sign-off before Production Release

• Security Gates in CI/CD Pipelines

• Security Acceptance Criteria

• Promote Security-by-Design and Secure-by-Default principles

8. Proactive Security Review for New Features

Review every new feature before production release to identify security risks as early as possible.

Responsibilities include:

• Reviewing new APIs, features and architectural changes.

• Identifying new attack surfaces.

• Performing security impact analysis.

• Providing remediation recommendations before implementation.

• Working closely with engineering teams to build secure-by-default solutions.

9. Threat Simulation & Attack Validation

Conduct periodic offensive security exercises to validate the effectiveness of security controls and detection capabilities.

Responsibilities include:

• Simulating realistic attack scenarios.

• Conducting adversary emulation.

• Validating security controls.

• Evaluating detection and alerting capabilities.

• Identifying monitoring and logging gaps.

• Improving product resilience against real-world attacks.

10. Security Automation & AI-assisted Security

Improve security efficiency through automation and AI.

Responsibilities include:

• Automate vulnerability scanning.

• Automate secret detection.

• Automate security validation.

• Automate regression security testing.

• Develop internal security tools.

• Utilize AI-assisted tools for source code analysis, vulnerability research, attack path discovery and Proof-of-Concept generation.

11. Threat Intelligence

Continuously research emerging threats relevant to company products.

Responsibilities include:

• Track newly published CVEs.

• Monitor emerging attack techniques.

• Research exploitation trends.

• Evaluate applicability to company products.

• Recommend mitigation strategies before exploitation occurs.

12. Security Reporting

Produce and maintain:

• Vulnerability Reports

• Security Assessment Reports

• Security Advisories

• Risk Assessments

• Proof-of-Concept Documentation

• Remediation Tracking

• Executive Security Summaries

Qualifications

Technical Knowledge

Strong understanding of:

• Linux

• Networking

• HTTP/HTTPS

• DNS

• TLS/SSL

• OAuth2 / OpenID Connect

• JWT

• AWS Security

• Kubernetes Security

Strong familiarity with:

• OWASP Top 10

• OWASP API Security Top 10

• MITRE ATT&CK

• CVSS

• CWE

• Secure SDLC

Technical Skills

Experience with one or more of:

• Burp Suite

• Nuclei

• Nmap

• ffuf

• Amass

• Subfinder

• ProjectDiscovery Tools

• Trivy

• Semgrep

• Gitleaks

• TruffleHog

• Snyk / Dependabot

Additional skills:

• Source code review (preferably .NET / C#)

• Python, Bash or PowerShell scripting

• Security automation

• Log analysis

• Digital forensics

• AI-assisted security tooling

Preferred Qualifications

• Experience in Bug Bounty or Responsible Disclosure programs.

• Experience discovering High or Critical vulnerabilities.

• Experience with DevSecOps, SAST, DAST, IaC Security, Container Security or Application Security.

• Experience securing AWS-based SaaS platforms.

• Security certifications such as OSCP, PNPT, eJPT, CRTO, CISSP or equivalent.

Success Metrics (KPIs)

• Reduction of security risks across products.

• Number of High/Critical vulnerabilities identified.

• Number of Business Logic vulnerabilities discovered.

• Security review coverage before production releases.

• Mean Time to Validate (MTTV).

• Mean Time to Remediate (MTTR).

• Security automation coverage.

• Threat detection effectiveness.

• Reduction in false positives.

• Improvements in attack detection and product resilience demonstrated through threat simulation exercises.

Who You Are

You think like an attacker but work to protect products.

You are naturally curious and constantly ask:

• How could this feature be abused

• Can this protection be bypassed

• Is this traffic normal or an attack

• Can multiple low-risk issues be chained into a critical exploit

• What would an attacker try next

• How can we detect and prevent this earlier

You enjoy proactively discovering vulnerabilities, researching emerging threats, validating real-world attack scenarios, and building secure products before incidents happen.

BENEFITS

1. Compensation and benefit package

  • Attractive salary and benefits
  • Annual leave and 5 days of sick leave
  • 13th-month salary and Annual Performance Bonus
  • Premium healthcare packages
  • Allowance for project team activities
  • Extra benefits for long-term employees

2. Exciting career and development opportunities

  • Large-scale products and projects with high reputation clients with related industries which is beneficial for your career plan.
  • Clear roadmap for career advancement in both technical and leadership pathways
  • A solid talented team behind you – great people who are passionate and proud of their work.

3. Friendly and English-speaking working environment

  • Laptops provided.
  • Well-equipped & modern office with fully stocked pantry
  • Sponsored sports activities.
  • Friendly environment, great working location, extra leave days, working from home.
  • English working environment, Australian and global clients, onsite opportunities in Australia.
  • Flexible working hours - Monday - Friday. Hybrid working model, good work-life balance. 

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151550785

Similar Jobs

Ho Chi Minh, Vietnam

Skills:

.NETsecurity automation Digital ForensicsNetworkingDnsPowershell ScriptingHttpsTlsPythonOauth2Log AnalysisJwtNmapBashHttpSSLC SharpBurp SuiteLinuxSubfinderProjectDiscovery ToolsGitleaksKubernetes SecurityNucleiAWS SecurityTrivyOpenID ConnectAI-assisted security toolingSnykDependabotAmassTruffleHogSemgrepffuf

Beware of Scammers

We don’t charge money for job offers