About the role
Focuses on product and application security throughout the Secure Software Development Lifecycle (SDLC). Key areas include threat modeling using STRIDE, integrating security tools like SAST and SCA into CI/CD pipelines, managing Software Bill of Materials (SBOM), and performing risk assessments. The role also covers incident management, compliance with standards such as NIST 800-53, and security for embedded systems, including secure boot and firmware protection.
Responsibilities
- Design, implement, and maintain security controls for applications, systems, and embedded products.
- Support Secure SDLC practices, including Threat Modelling (using STRIDE), secure design reviews, and validation.
- Integrate SAST and SCA into CI/CD pipelines to strengthen code security.
- Perform risk assessments and remediate vulnerabilities in software, firmware, and system designs.
- Participate in incident management: detection, triage, root cause analysis, and remediation.
Full description
Product Security Engineer
What You Will Do
• Design, implement, and maintain security controls for applications, systems, and embedded products.
• Support Secure SDLC practices, including Threat Modelling (using STRIDE), secure design reviews, and validation.
• Define and enforce Security Requirements across development stages.
• Integrate SAST and SCA into CI/CD pipelines to strengthen code security.
• Maintain and review Bill of Materials (SBOM) for software components.
• Perform risk assessments and remediate vulnerabilities in software, firmware, and system designs.
• Participate in incident management: detection, triage, root cause analysis, and remediation.
• Ensure secure transition from design to production with compliance to standards (e.g., NIST 800-53).
• Collaborate with cross-functional Agile teams to embed security in the SDLC.
• Support audits, compliance assessments, and security documentation.
• Stay updated on emerging threats and best practices.
Required Qualifications
• Bachelor’s/Master’s in Computer Science, Information Security, or related field.
• 1–3 years of experience in product or application security.
• Knowledge of secure coding and OWASP Top 10.
• Understanding of authentication, authorization, and encryption.
Technical Competencies
• Hands-on with Secure SDLC, Threat Modelling, and STRIDE.
• Experience with SAST, SCA, and Bill of Materials (SBOM).
• Familiarity with NIST 800-53 and risk management practices.
• Understanding of incident response lifecycle.
• Knowledge of embedded security (secure boot, firmware protection) and system/network security.
Preferred
• Exposure to secure architecture, cloud security (Azure), and regulated industries.
• Knowledge of APIs, containers, IAM, and advanced embedded security.
Soft Skills
• Strong analytical and problem-solving skills.
• Effective communication and teamwork.
• Continuous learning mindset in cybersecurity.
