Staff Product Security Engineer

Emploi pas sur LinkedIn

🕒 il y a 3 mois

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Cherry

Cherry

201 - 500 employés

Fondée en 2019

🏥 Santé

🍽️ Alimentation et boissons

🏨 Hôtellerie

Healthcare • Food & Beverage • Hospitality

CHERRY est un leader mondial dans le développement et la fabrication de dispositifs d'entrée de haute qualité et de solutions technologiques, spécialisé dans les claviers, souris et accessoires connexes pour les environnements de jeu et de bureau. Avec un accent prononcé sur la conception ergonomique, la technologie de commutation mécanique, et l'hygiène, CHERRY fournit également des solutions sur mesure pour des secteurs comme le médical, où ils offrent des claviers et terminaux désinfectables. Leur engagement envers l'innovation et la qualité a établi CHERRY comme une référence fiable pour les produits destinés aussi bien aux consommateurs qu'aux professionnels.

Description

• Partner with product and engineering teams to perform security design reviews and threat modeling for new and existing features across Cherry's platform. • Own and evolve Cherry's product security program — including secure coding standards, vulnerability management, and security testing processes. • Lead security reviews for authentication and authorization systems, ensuring robust access control patterns across our web and mobile products. • Assess and improve the security posture of Cherry's cloud infrastructure including network controls, IAM policies, secrets management, and container security. • Champion security best practices for payment processing, financial and health data handling, in alignment with PCI DSS and relevant compliance frameworks. • Conduct or coordinate penetration tests, red team exercises, and bug bounty triage; drive remediation of identified vulnerabilities. • Build and maintain security tooling integrated into the SDLC - SAST, DAST, dependency scanning, and runtime protection. • Respond to security incidents, perform root cause analysis, and implement lasting fixes to prevent recurrence. • Educate and mentor engineers on security principles, fostering a culture of security ownership across the organization. • Monitor the threat landscape for emerging risks relevant to FinTech and healthcare-adjacent payment products.

🎯 Exigences

• 5+ years of experience in product security, application security, or a related security engineering role. • Deep expertise in authentication and authorization — including OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC models, and session management. • Hands-on experience securing cloud environments (AWS preferred), including IAM, VPC, container orchestration (EKS/ECS), and infrastructure-as-code. • Strong understanding of secure software development practices — OWASP Top 10, threat modeling (STRIDE or similar), secure code review, and vulnerability remediation. • Experience integrating security tooling (SAST, DAST, SCA) into CI/CD pipelines. • Excellent communication skills — able to articulate security risk clearly to both technical and non-technical stakeholders. • Proven ability to work cross-functionally in a fast-paced, high-growth engineering environment. • Nice to Have: Penetration testing experience, familiarity with payment industry security, experience at a FinTech, healthcare technology, or other regulated-industry company.

🏖️ Avantages

• Competitive Base + Bonus • Generous equity grant • Medical, vision, and dental benefits • Fully remote company • Flexible PTO

Postuler Maintenant

Emplois Similaires

🕒 il y a 3 mois

Stedi

51 - 200

💼 Conseil

📦 Logistique

⚕️ Assurance santé

Head of Security managing security functions for a programmable healthcare clearinghouse startup. Overseeing incident readiness, regulatory obligations, and collaboration between teams.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 3 mois

Reddit, Inc.

501 - 1000

💼 Conseil

📣 Marketing

📱 Médias

Staff Product Security Engineer leading secure development frameworks and driving product security reviews at Reddit. Focused on integrating security into engineering workflows.

🇺🇸 États-Unis – Télétravail

💵 $217 000 - $303 900 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 3 mois

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Intelligence artificielle

Regional Sales Director to drive cybersecurity sales and strategy for CrowdStrike's Cloud Security solutions. Leading team to develop customer relationships and tackle modern cyber threats.

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

SFDC

Swift

🕒 il y a 3 mois

Cybersecurity Policy SME at MBL Technologies developing and implementing federal security policies and guidance. Collaborating with stakeholders and advising on compliance and policy interpretation.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 4 mois

AlphaSense

1001 - 5000

💼 Conseil

🏥 Santé

📣 Marketing

Staff Product Security Engineer leading secure design and implementation of AI-driven products at AlphaSense. Embedding security throughout the product lifecycle and collaborating with multiple teams.

🇺🇸 États-Unis – Télétravail

💵 $184 000 - $252 000 / an

💰 Debt Financing en 2022-06

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis