Senior Product Security Engineer – Architect

Jobtailor

Lausanne

Vor Ort

CHF 180.000 - 240.000

Vollzeit

Vor 6 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jobtailor is seeking a senior security-focused engineer to own product security for Taurus‑PROTECT, Taurus‑CAPITAL, Taurus‑EXPLORER and Taurus‑NETWORK. You will review architectures, perform threat modeling, lead penetration tests, and partner with engineering to ship fixes.

The role emphasizes security across CI/CD, Kubernetes, and cryptographic systems, with a strong background in cryptography (PKI, TLS) and HSM technologies to support audits and regulatory discussions.

Qualifikationen

  • 7+ years in application security, product security, offensive security, or security engineering.
  • Background in security‑critical environments — financial services, payments, identity, custody, embedded systems, or regulated platforms.
  • Fluent written and spoken English.
  • Strong security code review experience in at least two of: Go, C/C++, TypeScript, Python.
  • Threat modeling, secure design reviews, and penetration testing.
  • Ability to identify business logic flaws, authorization issues, cryptographic misuse, and complex attack paths.
  • Strong applied‑cryptography foundation: PKI, TLS, X.509; AES, RSA, ECDSA, EdDSA; key management and key ceremonies; secure key storage and signing workflows.
  • Experience with HSM technologies and PKCS#11 environments.
  • Strong Kubernetes and container security experience.
  • Familiarity with cloud IAM, workload identity, secrets management, and policy‑as‑code.
  • A builder’s mindset — implement security controls, not only review them.
  • Experience with one or more of: Thales / Luna HSM, AWS CloudHSM, Azure Managed HSM, Intel SGX, AMD SEV‑SNP, AWS Nitro Enclaves, Azure Confidential Computing.
  • Comfortable engaging security teams, auditors, regulators, enterprise clients, and prospect CISOs.
  • Able to explain complex security topics clearly and pragmatically.
  • Strong plus: blockchain and smart contract security.
  • Strong plus: MPC and threshold signature systems.
  • Strong plus: fuzzing and secure software testing.
  • Strong plus: security compliance and regulatory frameworks (FINMA, DORA, MiCA, ISO 27001, SOC 2, FIPS 140‑3).
  • Strong plus: public security research, CVEs, bug bounty experience, or open‑source security contributions.
  • Strong plus: experience supporting RFPs, security questionnaires, and customer due diligence.
  • Degree in Computer Science, Security, or equivalent practical experience.

Aufgaben

  • Own product security for Taurus‑PROTECT, Taurus‑CAPITAL, Taurus‑EXPLORER and Taurus‑NETWORK.
  • Contribute to financial services product security and security architecture for HSMs and confidential computing.
  • Perform security reviews of application code, cryptographic workflows, smart contracts, HSM integrations, and enclave‑based components.
  • Model threats of new features and review architectural designs before release.
  • Lead and review penetration tests, reproduce findings, and validate remediation plans.
  • Build and own automation enforcing security guardrails across CI/CD pipelines, software supply chains, Kubernetes environments, and deployment platforms.
  • Pair with product engineering teams to design and ship fixes.
  • Review authorization models, privilege management, identity integrations, and operational access controls.
  • Support incident response, vulnerability management, and security investigations.
  • Support client audits, RFPs, security workshops, and regulatory discussions.
  • Translate regulatory and compliance requirements into practical technical controls.
  • Monitor security news and trends, identify potential product impact, and ensure timely corrective actions.
  • Work as a hands‑on individual contributor and security partner to engineering teams.

Kenntnisse

Go
C/C++
TypeScript
Python
Threat modeling
Security code review
Kubernetes security
PKI/TLS

Ausbildung

Master's Degree in Computer Science
PhD in IT Security Engineering
PhD in Cryptography

Tools

HSM technologies
AWS CloudHSM
Azure Managed HSM
Kubernetes security tooling
Azure Confidential Computing

Jobbeschreibung

  • Own product security for all applicable digital asset products: Taurus-PROTECT, Taurus-CAPITAL, Taurus-EXPLORER and Taurus-NETWORK
  • Contribute to financial services product security
  • Contribute to security architecture for HSMs, confidential computing, MPC, and cryptographic systems
  • Perform security reviews of application code, cryptographic workflows, smart contracts, HSM integrations, and enclave-based components
  • Model threats of new features and review architectural designs before release
  • Lead and review penetration tests, reproduce findings, and validate remediation plans
  • Build and own automation enforcing security guardrails across CI/CD pipelines, software supply chains, Kubernetes environments, and deployment platforms
  • Pair with product engineering teams to design and ship fixes
  • Review authorization models, privilege management, identity integrations, and operational access controls
  • Support incident response, vulnerability management, and security investigations
  • Support client audits, RFPs, security workshops, and regulatory discussions
  • Translate regulatory and compliance requirements into practical technical controls
  • Monitor security news and trends, identify potential product impact, and ensure timely corrective actions
  • Work as a hands‑on individual contributor and security partner to engineering teams
Requirements
  • Master or PhD in computer sciences, IT security engineering or cryptography
  • 7+ years in application security, product security, offensive security, or security engineering
  • Background in security‑critical environments — financial services, payments, identity, custody, embedded systems, or regulated platforms
  • Fluent written and spoken English
  • Strong security code review experience in at least two of: Go, C/C++, TypeScript, Python
  • Threat modeling, secure design reviews, and penetration testing
  • Ability to identify business logic flaws, authorization issues, cryptographic misuse, and complex attack paths
  • Strong applied‑cryptography foundation: PKI, TLS, X.509; AES, RSA, ECDSA, EdDSA; key management and key ceremonies; secure key storage and signing workflows
  • Experience with HSM technologies and PKCS#11 environments
  • Strong Kubernetes and container security experience
  • Familiarity with cloud IAM, workload identity, secrets management, and policy‑as‑code
  • A builder’s mindset — implement security controls, not only review them
  • Experience with one or more of: Thales / Luna HSM, AWS CloudHSM, Azure Managed HSM, Intel SGX, AMD SEV‑SNP, AWS Nitro Enclaves, Azure Confidential Computing
  • Comfortable engaging security teams, auditors, regulators, enterprise clients, and prospect CISOs
  • Able to explain complex security topics clearly and pragmatically
  • Strong plus: blockchain and smart contract security
  • Strong plus: MPC and threshold signature systems
  • Strong plus: fuzzing and secure software testing
  • Strong plus: security compliance and regulatory frameworks (FINMA, DORA, MiCA, ISO 27001, SOC 2, FIPS 140-3)
  • Strong plus: public security research, CVEs, bug bounty experience, or open‑source security contributions
  • Strong plus: experience supporting RFPs, security questionnaires, and customer due diligence
  • Degree in Computer Science, Security, or equivalent practical experience
Core Competencies

Demonstrates expertise in product security, application security, and offensive security within financial services and regulated environments. Proficient in threat modeling, security code reviews, and implementing security controls across various technologies and platforms.

Highest‑signal resume keywords
  • Application Security
  • Threat Modeling
  • Security Code Review
  • Kubernetes Security
  • HSM Technologies
ATS Optimization Keywords
Hard Skills
  • Go
  • C/C++
  • TypeScript
  • Python
  • PKI
  • TLS
  • X.509
  • AES
  • RSA
  • ECDSA
Soft Skills
  • Clear Communication
  • Collaboration
  • Problem‑Solving
Certifications & Qualifications
  • Master's Degree in Computer Science
  • PhD in IT Security Engineering
  • PhD in Cryptography
Industry Keywords
  • Financial Services
  • Payments
  • Identity
  • Custody
  • Regulated Platforms
  • Security Compliance
  • Regulatory Frameworks
  • ISO 27001
  • SOC 2
  • FIPS 140-3
Tools & Technologies
  • HSM
  • AWS CloudHSM
  • Azure Managed HSM
  • Intel SGX
  • AWS Nitro Enclaves
  • Azure Confidential Computing
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Product Security Engineer / Architect [Lausanne]
Senior Product Security Engineer / Architect [Lausanne]

Taurus SA • Lausanne

Vor Ort
Confidential
Hybrid remote work
Flexible working hours
Fun team events
Cloud Security Consultant – Manager
Cloud Security Consultant – Manager

Jobtailor • Zürich

Vor Ort
CHF 120.000 - 180.000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Zug

Vor Ort
CHF 100.000 - 130.000
Flexible vacation
Mental Health Days
Tuition reimbursement
+1
Security engineer
Security engineer

UBP - Union Bancaire Privée • Genf

Vor Ort
CHF 110.000 - 140.000
Red Team Engineer – AI, Offensive Security
Red Team Engineer – AI, Offensive Security

Jobtailor • Zürich

Vor Ort
CHF 120.000 - 180.000
Security engineer
Security engineer

UNION BANCAIRE PRIVÉE, UBP SA • Genf

Vor Ort
CHF 120.000 - 180.000
Security engineer
Security engineer

Union Bancaire Privée • Genf

Hybrid
CHF 120.000 - 170.000
Senior Product Security Engineer / Architect [Lausanne]
Senior Product Security Engineer / Architect [Lausanne]

Embodied AI • Lausanne

Hybrid
CHF 140.000 - 190.000
Hybrid remote work
Flexible hours
Team events
Lead Product Security Architect – FinTech & Crypto
Lead Product Security Architect – FinTech & Crypto

Embodied AI • Lausanne

Hybrid
CHF 140.000 - 190.000
Hybrid remote work
Flexible hours
Team events
Senior Product Security Architect for FinTech & Crypto
Senior Product Security Architect for FinTech & Crypto

Taurus SA • Lausanne

Hybrid
Confidential
Hybrid remote work
Flexible working hours
Fun team events