Search by job, company or skills

Product Security Engineer

  • Posted 10 hours ago
  • Be among the first 10 applicants

Job Description

Location: Victory Tower, 318-320 Nguyen Oanh, Go Vap Ward, HCMC

Experience: Middle

Type: Full-time / Hybrid

Silicon Stack is a fast-growing Australian digital development, consulting, and creative agency with a strong global presence. We are a trustworthy and credible technology partner, known for our can-do attitude and expertise in cutting-edge technology. Our company is a premium development partner in industries like Automotive, Agriculture, Retail, and Manufacturing, specializing in ERP and CRM solutions. With over 200 staff across offices in Australia, Vietnam, and India, we continue to expand steadily. Our passion is to transform our clients ideas into reality through innovation and quality-driven solutions.

Requirement:

1. Technical Knowledge

Strong understanding of:

  • Linux
  • Networking
  • HTTP/HTTPS
  • DNS
  • TLS/SSL
  • OAuth2 / OpenID Connect
  • JWT
  • AWS Security
  • Kubernetes Security

Strong familiarity with:

  • OWASP Top 10
  • OWASP API Security Top 10
  • MITRE ATT&CK
  • CVSS
  • CWE
  • Secure SDLC

2. Technical Skills: Experience with one or more of:

  • Burp Suite
  • Nuclei
  • Nmap
  • ffuf
  • Amass
  • Subfinder
  • ProjectDiscovery Tools
  • Trivy
  • Semgrep
  • Gitleaks
  • TruffleHog
  • Snyk / Dependabot

Additional skills:

  • Source code review (preferably .NET / C#)
  • Python, Bash or PowerShell scripting
  • Security automation
  • Log analysis
  • Digital forensics
  • AI-assisted security tooling

Preferred Qualifications

  • Experience in Bug Bounty or Responsible Disclosure programs.
  • Experience discovering High or Critical vulnerabilities.
  • Experience with DevSecOps, SAST, DAST, IaC Security, Container Security or Application Security.
  • Experience securing AWS-based SaaS platforms.
  • Security certifications such as OSCP, PNPT, eJPT, CRTO, CISSP or equivalent.

3. Success Metrics (KPIs)

  • Reduction of security risks across products.
  • Number of High/Critical vulnerabilities identified.
  • Number of Business Logic vulnerabilities discovered.
  • Security review coverage before production releases.
  • Mean Time to Validate (MTTV).
  • Mean Time to Remediate (MTTR).
  • Security automation coverage.
  • Threat detection effectiveness.
  • Reduction in false positives.
  • Improvements in attack detection and product resilience demonstrated through threat simulation exercises.

Responsibilities:

1. Product Security Ownership: Own the security posture of assigned products throughout the entire Software Development Lifecycle (SDLC).

  • Act as the security champion for assigned products.
  • Continuously assess security risks throughout the product lifecycle.
  • Work closely with Engineering, DevOps and Product teams to improve product security.
  • Ensure security is considered from design through production.

2. Product Security Assessment: Perform security assessments across:

  • Web Applications
  • REST / GraphQL APIs
  • Backend Services
  • Mobile APIs (where applicable)
  • AWS Cloud Infrastructure
  • Kubernetes & Docker
  • Internal Services
  • Authentication & Authorization
  • CI/CD Pipelines
  • Third-party Integrations

Conduct:

  • Manual Security Assessments
  • Penetration Testing
  • Architecture Security Reviews
  • Secure Design Reviews
  • Threat Modeling

3. Offensive Security & Vulnerability Research: Proactively discover, validate and assess security vulnerabilities, including:

  • Web & API Security
  • Broken Access Control
  • IDOR
  • Authentication & Authorization Bypass
  • Business Logic Flaws
  • Privilege Escalation
  • SQL / NoSQL Injection
  • Command Injection
  • SSRF
  • XSS
  • CSRF
  • XXE
  • Path Traversal
  • File Upload Vulnerabilities
  • Insecure Deserialization
  • Open Redirect
  • Rate Limit Bypass
  • API Abuse
  • Session Management Weaknesses
  • Cloud & Infrastructure Security
  • IAM Misconfigurations
  • Excessive Privileges
  • Cross-account Access Risks
  • IAM Trust Relationship Issues
  • Public S3 Buckets
  • Exposed Secrets
  • KMS & Secrets Manager Misconfigurations
  • Security Group Misconfigurations
  • Open Management Ports
  • Kubernetes RBAC & IRSA Misconfigurations
  • Container Escape Risks
  • TLS/SSL Weaknesses
  • DNS Misconfigurations
  • Sensitive Information Disclosure
  • Dependency & Supply Chain Security
  • CVE Assessment
  • Dependency Vulnerability Analysis
  • Open Source Component Risks
  • Outdated Packages
  • Software Supply Chain Security

4. Source Code Security Assessment: Perform manual and AI-assisted source code security reviews.

  • Identify insecure coding practices.
  • Review authentication and authorization logic.
  • Review cryptography implementation.
  • Review session management.
  • Identify business logic vulnerabilities.
  • Validate security fixes before release.
  • Work with development teams to eliminate security weaknesses early.

5. Security Monitoring & Threat Detection: Continuously monitor production environments to identify abnormal behaviors and potential attacks.

Monitor and investigate:

  • Abnormal Traffic Patterns
  • DDoS / DoS Attempts
  • Brute-force Attacks
  • Credential Stuffing
  • Automated Bot Activities
  • API Abuse
  • Rate Limit Bypass Attempts
  • Reconnaissance Activities
  • Vulnerability Scanning
  • Exploitation Attempts
  • Suspicious Requests
  • WAF Events
  • AWS GuardDuty Findings
  • AWS CloudTrail Events
  • Suspicious IAM Activities
  • Privilege Escalation Attempts
  • Sudden Error Rate Increases
  • Unusual CPU, Memory, Network or Application Workloads that may indicate attacks or compromise
  • Recommend and implement improvements to:
  • Detection Rules
  • Alerting
  • Monitoring
  • Security Controls
  • Mitigation Strategies

6. Security Validation

  • Develop Proof-of-Concepts (PoCs)
  • Validate exploitability
  • Assess business impact
  • Prioritize vulnerabilities using CVSS
  • Eliminate false positives
  • Recommend remediation strategies
  • Verify fixes after remediation

7. Secure SDLC: Drive security integration throughout the Software Development Lifecycle.

  • Security Code Reviews
  • Threat Modeling
  • Security Requirements Definition
  • Secure Design Reviews
  • Security Architecture Reviews
  • Security Sign-off before Production Release
  • Security Gates in CI/CD Pipelines
  • Security Acceptance Criteria
  • Promote Security-by-Design and Secure-by-Default principles

8. Proactive Security Review for New Features: Review every new feature before production release to identify security risks as early as possible.

  • Reviewing new APIs, features and architectural changes.
  • Identifying new attack surfaces.
  • Performing security impact analysis.
  • Providing remediation recommendations before implementation.
  • Working closely with engineering teams to build secure-by-default solutions.

9. Threat Simulation & Attack Validation

Conduct periodic offensive security exercises to validate the effectiveness of security controls and detection capabilities.

  • Simulating realistic attack scenarios.
  • Conducting adversary emulation.
  • Validating security controls.
  • Evaluating detection and alerting capabilities.
  • Identifying monitoring and logging gaps.
  • Improving product resilience against real-world attacks.

10. Security Automation & AI-assisted Security: Improve security efficiency through automation and AI.

  • Automate vulnerability scanning.
  • Automate secret detection.
  • Automate security validation.
  • Automate regression security testing.
  • Develop internal security tools.
  • Utilize AI-assisted tools for source code analysis, vulnerability research, attack path discovery and Proof-of-Concept generation.

11. Threat Intelligence: Continuously research emerging threats relevant to company products.

  • Track newly published CVEs.
  • Monitor emerging attack techniques.
  • Research exploitation trends.
  • Evaluate applicability to company products.
  • Recommend mitigation strategies before exploitation occurs.

12. Security Reporting: Produce and maintain:

  • Vulnerability Reports
  • Security Assessment Reports
  • Security Advisories
  • Risk Assessments
  • Proof-of-Concept Documentation
  • Remediation Tracking
  • Executive Security Summaries

Benefits:

1. Compensation and benefit package

  • Attractive salary and benefits
  • Annual leave and 5 days of sick leave
  • 13th-month salary and Annual Performance Bonus
  • Premium healthcare packages
  • Allowance for project team activities
  • Extra benefits for long-term employees

2. Exciting career and development opportunities

  • Large-scale products and projects with high reputation clients with related industries which is beneficial for your career plan.
  • Clear roadmap for career advancement in both technical and leadership pathways
  • A solid talented team behind you – great people who are passionate and proud of their work.

3. Friendly and English-speaking working environment

  • Laptops provided.
  • Well-equipped & modern office with fully stocked pantry
  • Sponsored sports activities.
  • Friendly environment, great working location, extra leave days, working from home.
  • English working environment, Australian and global clients, onsite opportunities in Australia.
  • Flexible working hours - Monday - Friday. Hybrid working model, good work-life balance.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 151818013

Similar Jobs

Ho Chi Minh, Vietnam

Skills:

PowerShellNmapBashBurp SuiteDockerKubernetesPythonAWSSubfinderProjectDiscovery ToolsSnykGitleaksNucleiDependabotAmassTruffleHogTrivySemgrepffuf

Beware of Scammers

We don’t charge money for job offers