Product Security Engineer

🕒 vor 4 Tagen

🇺🇸 Vereinigte Staaten – Remote

💵 $175.000 - $200.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Doppel

Doppel

201 - 500 Mitarbeiter

Gegründet 2022

🔒 Cybersecurity

🤖 Künstliche Intelligenz

☁️ SaaS

Cybersecurity • Artificial Intelligence • SaaS

Doppel ist eine KI-native Plattform zur Abwehr von Social Engineering, die Organisationen vor KI-gesteuerten Imitationen, Phishing, Deepfakes und Multi-Channel-Social-Engineering-Angriffen schützt. Die Plattform vereint den Schutz vor digitalen Risiken, das Management menschlicher Risiken (Simulation und Schulung zur Sicherheitsbewusstsein) und E-Mail-Sicherheit, um Angreifer-Infrastrukturen über Domänen, soziale Medien, Werbenetzwerke, Telekommunikation, Marktplätze und dunkle Kanäle zu erkennen, zu korrelieren (über einen Bedrohungsgraphen) und zu beheben. Doppel legt Wert auf agentische KI-Automatisierung für Erkennung, Schließung, Phishing-Triage und skalierbare SOC-Workflows und richtet sich an Unternehmenskunden aus Branchen wie Finanzdienstleistungen, Gesundheitswesen, Technologie, Einzelhandel und Fertigung.

Beschreibung

• Partner with product and engineering teams to support security architecture reviews for product features and the GCP environment; facilitate threat modeling and document risks, existing controls, and actionable recommendations. • Coordinate and support penetration testing engagements by assisting with vendor selection and scoping, establishing rules of engagement, coordinating testing activities, validating findings, supporting severity assessment, and tracking remediation and retesting in collaboration with engineering teams. • Serve as a GCP security subject matter expert for project teams, advising on secure patterns across networking (VPC, private access, perimeter controls), data protection (KMS, secrets), compute runtimes (GKE, Cloud Run, GCE), CI/CD (Cloud Build, Artifact Registry), and logging and monitoring. • Support the implementation and ongoing improvement of least-privilege IAM in GCP by advising on role design (custom vs. predefined), service account lifecycle management, workload identity, IAM Conditions, organization and folder policy constraints, and periodic access reviews. • Assist with triage and routing of product security findings to appropriate engineering owners; help tune detection rules to reduce noise, support severity and SLA definition, and track remediation progress, including documenting justified exceptions. • Contribute to security guardrails through policy and infrastructure-as-code (e.g., org policies, constraints, reusable Terraform modules, admission or policy controllers) and support integration of pre-merge security checks into CI/CD workflows. • Develop and maintain practical documentation and runbooks (e.g., design review checklists, IAM standards, exception processes) and deliver targeted enablement sessions for engineers and product managers. • Provide visibility into progress and risk through metrics and regular status updates to security leadership; proactively surface blockers and suggest options and tradeoffs. • Coach and mentor engineers and code owners on secure-by-default coding practices and architectural patterns.

🎯 Anforderungen

• 5–7 years of experience in product security, cloud security engineering, or a related field. • Strong knowledge of Google Cloud Platform (GCP) services and security best practices, including IAM, networking, data protection, and workload runtimes. • Hands-on experience with penetration testing coordination, threat modeling, and risk assessment. • Demonstrated proficiency in Python and cloud-native programming or scripting languages to design and maintain security automation, policy enforcement, and continuous compliance controls using Infrastructure as Code. • Familiarity with designing and enforcing least-privilege IAM and conducting access reviews. • Ability to communicate security risks and recommendations clearly to engineering and leadership audiences.

🏖️ Vorteile

• Meaningful equity so you share in Doppel’s success • Remote first culture with flexibility built in • Flexible PTO, comprehensive health benefits, parental leave, and more • A high growth environment where your work has immediate impact and visibility

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 4 Tagen

Bridgeway Benefit Technologies

201 - 500

☁️ SaaS

👥 HR Tech

Associate Security Engineer at Bridgeway Benefit Technologies assisting with scalable security solutions and collaborating with teams to enhance security posture. Focused on compliance and efficient security operations in a remote role.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟢 Junior

🟡 Mittelstufe

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

Team8

51 - 200

💼 Beratung

🏥 Gesundheitswesen

🏭 Fertigung

Forward Deployed AI Engineer deploying AI solutions for fraud prevention in financial institutions. Collaborating with clients to optimize their unique fraud operations and enhance technological transformation.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

Dataflow Security

51 - 200

🔒 Cybersecurity

🎖️ Verteidigung

Security Researcher specializing in server-side vulnerabilities for web applications. Conduct research and develop exploits while collaborating with experienced security researchers.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

Dataflow Security

51 - 200

🔒 Cybersecurity

🎖️ Verteidigung

iOS Security Researcher joining a team at Dataflow Security. Involves conducting vulnerability research, reverse engineering, and exploit development on iOS.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

Dataflow Security

51 - 200

🔒 Cybersecurity

🎖️ Verteidigung

Security Researcher for Dataflow Security conducting vulnerability research on Web Browsers. Collaborating with a team to develop insights, proof-of-concept code, and exploits to meet security standards.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich