Job Openings
Product Security Engineer
About the job Product Security Engineer
Job Responsibilities:
- Develop, implement, and maintain product security standards, frameworks, and best practices across all product lines within the organization.
- Design and establish a comprehensive System Security Framework covering authentication, OTP lifecycle management, data protection, secrets management, encryption, key management, and access controls.
- Conduct security architecture reviews, threat modeling exercises, and risk assessments throughout the software development lifecycle.
- Define, implement, and manage a Secure Software Development Lifecycle (Secure SDLC), including security requirements, design reviews, testing, and release approval processes.
- Lead application security activities including secure code reviews, vulnerability assessments, penetration testing coordination, SAST, DAST, software composition analysis, and dependency management.
- Perform security assessments of cloud environments, primarily AWS, focusing on identity management, network security, data protection, and configuration hardening.
- Review and provide security sign-off recommendations for product releases, ensuring security requirements are met prior to deployment.
- Partner closely with engineering, product, and technology teams across multiple regions to identify, prioritize, and remediate security vulnerabilities.
- Manage vulnerability remediation activities, track security risks, and provide regular reporting to senior management and stakeholders.
- Coordinate with external security auditors, penetration testing providers, and compliance assessors.
- Develop and maintain security policies, standards, baselines, guidelines, and security awareness initiatives for engineering teams.
- Act as the primary product security subject matter expert and advocate security best practices across the organization.
Job Requirements:
- Bachelor's Degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related discipline.
-
Minimum 4–6 years of hands-on experience in Product Security, Application Security, Cybersecurity, or related security engineering roles.
-
Strong experience in threat modeling, secure architecture design reviews, and application security assessments.
-
Proven experience designing, implementing, or operating Secure SDLC processes within software development environments.
-
Hands-on experience with application security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and vulnerability management platforms.
-
Strong understanding of authentication mechanisms, authorization models, OTP implementations, encryption technologies, key management systems (KMS), secrets management, and secure coding practices.
-
Experience securing cloud environments, preferably AWS, including IAM, networking, storage security, monitoring, and configuration management.
-
Strong knowledge of OWASP Top 10, secure development practices, API security, mobile security, and software supply chain security.
- Ability to work independently as the primary security owner while effectively influencing cross-functional engineering teams.
-
Experience working within fintech, digital payments, cryptocurrency, blockchain, wallet security, or regulated environments is an added advantage.
-
Professional certifications such as OSCP, CISSP, GWAPT, AWS Security Specialty, CEH, or equivalent are preferred.
- Demonstrated stability in career progression with a proven track record of delivering security initiatives and driving measurable improvements.