Product Security Engineer II
Jobgether · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
Accountabilities
- Contribute to application security initiatives by working closely with engineering, product, infrastructure, compliance, and security teams.
- Help identify vulnerabilities, improve security processes, and create tools and guidance that enable teams to build secure products efficiently.
- Partner with product and engineering teams to identify application security risks and provide practical recommendations for mitigation.
- Analyze application code, configurations, pull requests, logs, and technical documentation to identify potential security issues.
- Contribute code changes, scripts, automation, tests, security checks, and tooling improvements to enhance security workflows.
- Participate in Git-based development workflows, including code reviews, pull requests, issue tracking, and remediation discussions.
- Evaluate vulnerabilities from internal testing, bug bounty programs, penetration tests, and security tools while prioritizing risks based on business impact.
- Translate recurring security findings into scalable solutions such as secure coding guidelines, automation workflows, detection logic, and developer resources.
- Review system designs, data flows, authentication models, authorization controls, and potential abuse scenarios.
- Communicate security risks clearly to both technical and non-technical stakeholders, explaining impact, tradeoffs, and recommended actions.
- Build strong relationships across engineering, product, compliance, infrastructure, and security teams.
- Continue developing offensive security, defensive security, and software engineering skills through practical projects, research, certifications, and internal initiatives.
Requirements
- The ideal candidate is an early-career security professional with hands-on experience in software development, application security, or related technical fields.
- Strong curiosity, problem-solving abilities, and the ability to balance security requirements with product and business goals.
- 0-2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, security operations, or equivalent practical experience.
- Foundation programming experience with languages such as Python, JavaScript/TypeScript, Kotlin, or similar.
- Ability to read, understand, and reason about unfamiliar codebases.
- Experience using Git, GitHub, or similar version-control workflows, including branches, commits, pull requests, and code reviews.
- Hands-on experience building, testing, securing, or analyzing software through professional work, internships, personal projects, labs, CTFs, bug bounty programs, or coursework.
- Able to write maintainable scripts or small programs to automate workflows, analyze data, validate findings, or improve security processes.
- Understanding of common application security concepts, including OWASP Top 10 vulnerabilities, authentication and authorization issues, injection risks, insecure design, secrets management, dependency risks, and data protection.
- Interest in offensive security practices such as web/API testing, security certifications, exploit development fundamentals, or security research.
- Familiarity with vulnerability management concepts, including risk assessment, remediation tracking, false positives, and prioritization.
- Able to evaluate security risks based on likelihood, impact, and available mitigation options.
- Strong product and engineering mindset with the ability to understand technical constraints and business priorities.
- Excellent written and verbal communication skills with the ability to explain security concepts clearly.
- Collaborative mindset with curiosity, humility, and a commitment to continuous learning.
Benefits
- Full remote work opportunity.
- Comprehensive health coverage with premiums fully covered for employees and dependents.
- Flexible spending wallets for technology, food, lifestyle needs, and family-related expenses.
- Competitive vacation and holiday schedules to support work-life balance.
- Employee Stock Purchase Plan (ESPP) with discounted company shares.
- Monthly stipends supporting health, wellness, and technology expenses.
- Equity opportunities as part of a total compensation package.
- Inclusive and supportive workplace focused on employee growth and development.
- Opportunity to contribute to meaningful security initiatives that protect customers and strengthen product trust.