Staff Product Security Engineer

Stelle nicht auf LinkedIn

🕒 vor 3 Monaten

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Cherry

Cherry

201 - 500 Mitarbeiter

Gegründet 2019

🏥 Gesundheitswesen

🍽️ Lebensmittel & Getränke

🏨 Gastgewerbe

Healthcare • Food & Beverage • Hospitality

CHERRY ist ein weltweit führendes Unternehmen in der Entwicklung und Herstellung von hochwertigen Eingabegeräten und technologischen Lösungen, das sich auf Tastaturen, Mäuse und verwandtes Zubehör für sowohl Gaming als auch Büroanwendungen spezialisiert hat. Mit einem starken Schwerpunkt auf ergonomischem Design, mechanischer Schaltertechnologie und Hygiene bietet CHERRY auch maßgeschneiderte Lösungen für Branchen wie das Gesundheitswesen an, wo sie desinfizierbare Tastaturen und Terminals anbieten. Ihr Engagement für Innovation und Qualität hat CHERRY als vertrauenswürdigen Namen für sowohl Endverbraucher- als auch professionelle Produkte etabliert.

Beschreibung

• Partner with product and engineering teams to perform security design reviews and threat modeling for new and existing features across Cherry's platform. • Own and evolve Cherry's product security program — including secure coding standards, vulnerability management, and security testing processes. • Lead security reviews for authentication and authorization systems, ensuring robust access control patterns across our web and mobile products. • Assess and improve the security posture of Cherry's cloud infrastructure including network controls, IAM policies, secrets management, and container security. • Champion security best practices for payment processing, financial and health data handling, in alignment with PCI DSS and relevant compliance frameworks. • Conduct or coordinate penetration tests, red team exercises, and bug bounty triage; drive remediation of identified vulnerabilities. • Build and maintain security tooling integrated into the SDLC - SAST, DAST, dependency scanning, and runtime protection. • Respond to security incidents, perform root cause analysis, and implement lasting fixes to prevent recurrence. • Educate and mentor engineers on security principles, fostering a culture of security ownership across the organization. • Monitor the threat landscape for emerging risks relevant to FinTech and healthcare-adjacent payment products.

🎯 Anforderungen

• 5+ years of experience in product security, application security, or a related security engineering role. • Deep expertise in authentication and authorization — including OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC models, and session management. • Hands-on experience securing cloud environments (AWS preferred), including IAM, VPC, container orchestration (EKS/ECS), and infrastructure-as-code. • Strong understanding of secure software development practices — OWASP Top 10, threat modeling (STRIDE or similar), secure code review, and vulnerability remediation. • Experience integrating security tooling (SAST, DAST, SCA) into CI/CD pipelines. • Excellent communication skills — able to articulate security risk clearly to both technical and non-technical stakeholders. • Proven ability to work cross-functionally in a fast-paced, high-growth engineering environment. • Nice to Have: Penetration testing experience, familiarity with payment industry security, experience at a FinTech, healthcare technology, or other regulated-industry company.

🏖️ Vorteile

• Competitive Base + Bonus • Generous equity grant • Medical, vision, and dental benefits • Fully remote company • Flexible PTO

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 3 Monaten

Stedi

51 - 200

💼 Beratung

📦 Logistik

⚕️ Krankenversicherung

Head of Security managing security functions for a programmable healthcare clearinghouse startup. Overseeing incident readiness, regulatory obligations, and collaboration between teams.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Reddit, Inc.

501 - 1000

💼 Beratung

📣 Marketing

📱 Medien

Staff Product Security Engineer leading secure development frameworks and driving product security reviews at Reddit. Focused on integrating security into engineering workflows.

🇺🇸 Vereinigte Staaten – Remote

💵 $217.000 - $303.900 / Jahr

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Gainwell Technologies

10.000+ Mitarbeiter

💼 Beratung

📦 Logistik

⚕️ Krankenversicherung

Information Security Advisor ensuring secure computer systems and data protection. Leading audits, investigations, and compliance with security policies in a technology-driven environment.

🇺🇸 Vereinigte Staaten – Remote

💵 $101.300 - $144.700 / Jahr

💰 Grant im 2023-06

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Künstliche Intelligenz

Regional Sales Director to drive cybersecurity sales and strategy for CrowdStrike's Cloud Security solutions. Leading team to develop customer relationships and tackle modern cyber threats.

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cloud

Cyber Security

SFDC

Swift

🕒 vor 3 Monaten

Simbian

11 - 50

🤖 Künstliche Intelligenz

🔒 Cybersecurity

Experienced Product Manager for cybersecurity AI at Simbian. Owning product roadmap and driving innovation in security operations.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich