Jobs · Florida

Senior Product Security Engineer

Iru · Miami, FL · 2 wk ago
Hybrid$100/hrFull-time

Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation—collapsing the stack and giving IT & security time and control back. Backed by top investors like General Catalyst, Tiger Global, and Felicis, Iru raised $100 million in July 2024 and serves customers including Cursor, Vercel, and Replit.

About the role

We're seeking a highly technical Senior Product Security Engineer to embed security into the product development lifecycle. This hands-on engineering role is responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure-by-design products. You’ll collaborate with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to integrate security throughout the SDLC while enabling developer velocity.

Responsibilities

  • Application Security
    • Perform security design and architecture reviews for new products and features.
    • Conduct threat modeling for applications, APIs, and AI-enabled services.
    • Review application security posture throughout the SDLC.
    • Partner with engineering teams to prioritize and remediate vulnerabilities.
    • Review authentication, authorization, and access control implementations.
  • Security Testing
    • Perform manual web, API, thick-client, and mobile application penetration testing.
    • Validate findings from third-party penetration tests.
    • Conduct secure code reviews.
    • Verify remediation of security vulnerabilities.
  • Secure Development
    • Drive adoption of secure coding practices.
    • Partner with developers to improve security throughout the SDLC.
    • Help define Product Security standards and engineering guardrails.
    • Develop reusable security patterns and reference architectures.
  • Vulnerability Management
    • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
    • Work with engineering teams to prioritize remediation.
    • Track remediation SLAs and security metrics.
  • AI Security
    • Assess AI-enabled products for security risks.
    • Review LLM integrations and AI workflows.
    • Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
    • Help define secure AI engineering standards.
  • Security Automation
    • Improve automation of security testing throughout CI/CD.
    • Integrate security tooling into developer workflows.
    • Build scripts and tooling that reduce manual security work.
  • Cross-functional Partnership
    • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
    • Support customer security questionnaires related to product security.
    • Assist Sales Engineering with security discussions when needed.

Qualifications

  • 5+ years in Product Security or Application Security.
  • Strong understanding of modern application architectures.
  • Experience securing:
    • Web applications
    • APIs
    • Microservices
    • Cloud-native applications
  • Experience performing threat modeling.
  • Experience conducting penetration testing.
  • Strong understanding of:
    • OWASP Top 10
    • OWASP API Top 10
    • Authentication & Authorization
    • OAuth / OIDC
    • Secure SDLC
  • Experience with SAST, DAST, SCA, and container security.
  • Experience partnering directly with engineering teams.
  • Strong written and verbal communication skills.

Preferred Skills

  • Experience securing AI/LLM applications.
  • Experience with Kubernetes and containers.
  • Familiarity with cloud security (AWS, Azure, or GCP).
  • Experience with GitHub Actions or CI/CD security.
  • Experience using:
    • Snyk
    • Burp Suite Pro
    • Semgrep
    • Wiz
    • GitHub Advanced Security
  • Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.

What Success Looks Like

Within your first 12 months, you'll:

  • Embed security into engineering workflows without slowing development.
  • Improve vulnerability remediation timelines.
  • Increase adoption of secure design reviews and threat modeling.
  • Expand automated security testing across products.
  • Help mature Iru's AI Security program.
  • Strengthen Product Security standards and developer enablement.
  • Build strong partnerships with engineering teams and become a trusted security advisor.

Benefits

  • Competitive salary
  • Hybrid work environment (3 days in office per week)
  • 100% individual and dependent medical + dental + vision coverage
  • 401(K) with a 4% company match
  • 20 days PTO
  • Iru Wellness Week the first week in July
  • Equity for full-time employees
  • In-office lunch stipend
  • Up to 16 weeks of paid leave for new parents
  • Paid Family and Medical Leave
  • Modern Health mental health benefits for individuals and dependents
  • Fertility benefits
  • Working Advantage employee discounts
  • Onsite fitness center
  • Free parking
  • Exciting opportunities for career growth

Similar jobs