Senior Product Security Engineer - Applications
1 Days Old
Senior Product Security Engineer - Applications The Product Security organization helps Optimum move faster, securely. We're a team of engineers who work to enable other teams to build products as quickly as possible while continuing to protect our customers. We support developers in shipping secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authentication, authorization, and safe data handling across the company.
As a Product Security Engineer focusing on application security, you'll be a trusted advisor, collaborating closely with engineering and product teams to ensure security is a cornerstone of every product. You will partner with leadership to shape product strategy, advocate for strong security controls, and influence future product iterations. By leveraging your deep industry knowledge, you'll lead the charge in implementing secure architecture and design principles, ensuring early detection and prevention of vulnerabilities. Your expertise in security assessments and software engineering will help identify and mitigate potential threats, while your mentorship and training efforts will foster a security-first culture.
Responsibilities include:
Collaborating with engineering and product teams to integrate security and secure-by-default guardrails into the product lifecycle, ensuring that security is a core consideration in all design and development decisions.
Conducting threat modeling and risk assessments from the early stages of the product development lifecycle to identify, assess, and prioritize security risks, enabling proactive mitigation strategies.
Performing rigorous security testing and reviews to uncover and address security weaknesses.
Leading initiatives automating security processes from the developer workstation to cloud, SaaS, and datacenter environments.
Contributing to incident response efforts, investigating root causes, and implementing corrective actions to minimize impact and prevent future occurrences.
Fostering a security-first culture by educating and empowering engineering and product teams through training, awareness campaigns, and mentorship, cultivating a strong security mindset.
Staying updated on the latest security threats, vulnerabilities, and technology trends, and proactively implementing improvements.
Qualifications include:
Bachelor's degree in Computer Science, Electrical Engineering, a related field, or equivalent professional experience. Master's degree is a plus.
5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
Demonstrable experience with product and application security concepts, including API, web, and mobile app security.
Excellent communication skills, both written and verbal, and the ability to communicate complex security concepts to technical and non-technical audiences, including senior leadership.
Proven ability to establish credibility and build trust with engineers and operational staff.
Expertise in conducting comprehensive threat modeling and risk assessments to identify and mitigate vulnerabilities.
Proficient in modern security frameworks, tools, and techniques. Familiarity with security standards and frameworks such as ISO, NIST, OWASP, etc.
Proficiency in secure SDLC practices, commercial and open-source security testing tools (SAST, DAST, SCA, fuzzing), container security (Docker, Kubernetes), and cloud security (GCP, AWS, Azure).
Practical experience securing CI/CD pipelines; Infrastructure-as-Code (IaC) tools like Terraform; GitHub and/or Gitlab; artifact management.
Strong understanding of both human and non-human identity management, enterprise and consumer authentication standards and use cases, and common protocols including OAuth and SAML.
Experience overseeing vulnerability and threat management at the platform and application levels.
Strong understanding of cryptography and key management use cases.
Proficiency in one or more modern programming languages like Golang, Python, Node, and Java.
Familiarity with penetration testing and red teaming is a plus.
Knowledge and experience in securing AI/ML based products is a plus.
Extensive experience securing Google Cloud Platform (GCP) workloads is a strong plus.
Site Reliability Engineering (SRE) experience is a strong plus.
Experience developing security-focused Terraform modules is a strong plus.
- Location:
- Plano, TX, United States
- Category:
- Computer And Mathematical Occupations