← All jobs

Product Security Engineer

TeamBees Corp
Employment
Full Time
Experience
1-4 years

About the role

Focuses on product and application security throughout the Secure Software Development Lifecycle (SDLC). Key areas include threat modeling using STRIDE, integrating security tools like SAST and SCA into CI/CD pipelines, managing Software Bill of Materials (SBOM), and performing risk assessments. The role also covers incident management, compliance with standards such as NIST 800-53, and security for embedded systems, including secure boot and firmware protection.

Responsibilities

  • Design, implement, and maintain security controls for applications, systems, and embedded products.
  • Support Secure SDLC practices, including Threat Modelling (using STRIDE), secure design reviews, and validation.
  • Integrate SAST and SCA into CI/CD pipelines to strengthen code security.
  • Perform risk assessments and remediate vulnerabilities in software, firmware, and system designs.
  • Participate in incident management: detection, triage, root cause analysis, and remediation.

Full description

Product Security Engineer What You Will Do •     Design, implement, and maintain security controls for applications, systems, and embedded products. •     Support Secure SDLC practices, including Threat Modelling (using STRIDE), secure design reviews, and validation. •     Define and enforce Security Requirements across development stages. •     Integrate SAST and SCA into CI/CD pipelines to strengthen code security. •     Maintain and review Bill of Materials (SBOM) for software components. •     Perform risk assessments and remediate vulnerabilities in software, firmware, and system designs. •     Participate in incident management: detection, triage, root cause analysis, and remediation. •     Ensure secure transition from design to production with compliance to standards (e.g., NIST 800-53). •     Collaborate with cross-functional Agile teams to embed security in the SDLC. •     Support audits, compliance assessments, and security documentation. •     Stay updated on emerging threats and best practices. Required Qualifications •     Bachelor’s/Master’s in Computer Science, Information Security, or related field. •     1–3 years of experience in product or application security. •     Knowledge of secure coding and OWASP Top 10. •     Understanding of authentication, authorization, and encryption. Technical Competencies •     Hands-on with Secure SDLC, Threat Modelling, and STRIDE. •     Experience with SAST, SCA, and Bill of Materials (SBOM). •     Familiarity with NIST 800-53 and risk management practices. •     Understanding of incident response lifecycle. •     Knowledge of embedded security (secure boot, firmware protection) and system/network security. Preferred •     Exposure to secure architecture, cloud security (Azure), and regulated industries. •     Knowledge of APIs, containers, IAM, and advanced embedded security. Soft Skills •     Strong analytical and problem-solving skills. •     Effective communication and teamwork. •     Continuous learning mindset in cybersecurity.
Not ready for a demo? Run a real role through a free pilot first.
Self-serve signup, no sales call, no charges during the pilot.
Start Free Pilot