Posted on: 26/09/2026
Role Overview :
We are looking for a Senior Product Security Engineer to secure enterprise applications and AI-powered products across multiple engineering teams and repositories.
This role requires strong hands-on security expertise, the ability to operate at scale, and the ability to quickly identify, prioritize, and drive remediation of security risks across multiple products.
Key Responsibilities :
- Own security assessments across multiple enterprise applications, products, repositories, and engineering teams.
- Perform hands-on Web, API, cloud, and Kubernetes security testing, including vulnerability discovery, exploitation, validation, and reporting.
- Identify vulnerabilities through manual testing, source-code review, threat modeling, and security tooling.
- Assess authentication, authorization, business logic, APIs, attack surfaces, cloud configurations, IAM, containers, and Kubernetes environments.
- Identify and prioritize vulnerabilities based on exploitability, business impact, and risk.
- Work directly with engineering teams to drive remediation, retesting, and closure of security findings.
- Integrate security into the SDLC and CI/CD pipelines through SAST, DAST, SCA, secrets detection, and security gates.
- Establish repeatable and scalable security practices that can be applied across multiple products and teams.
- Rapidly assess new applications and prioritize the highest-risk security gaps in fast-moving development environments.
- Communicate technical vulnerabilities, business impact, and remediation requirements clearly to both engineering and business stakeholders.
Qualifications:
- Hands-on experience in Product Security, Application Security, or Security Engineering.
- Proven experience securing multiple enterprise applications/products across multiple repositories and engineering teams.
- Strong hands-on expertise in Web and API Security, OWASP Top 10, and vulnerability assessment.
- Demonstrated ability to discover and validate real-world vulnerabilities, beyond relying only on automated scanners.
- Strong experience with Burp Suite/ZAP, source-code security review, and root-cause analysis.
- Experience securing cloud environments, Kubernetes/GKE, IAM, containers, and CI/CD pipelines.
- Experience implementing or operating SAST, DAST, and SCA within the SDLC.
- Proven ability to prioritize and remediate security risks across multiple applications simultaneously.
- Experience working directly with engineering teams to drive vulnerabilities from discovery through remediation and retesting.
- Demonstrated ability to operate with speed, ownership, and strong execution in large-scale engineering environments.
- Strong communication skills with the ability to translate technical security issues into business risk and actionable remediation.
Nice to Have :
- GCP/GKE experience
- AI/GenAI application security
- OSCP, OSWE, GIAC, CREST, or equivalent
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1674981