Staff Product Security Engineer

Auth21

Cambridge

On-site

GBP 90,000 - 120,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Altium Limited seeks a Senior Product Security Engineer to extend our security capability with a focus on continuous vulnerability discovery and prevention. The role aims to keep existing functionality secure and to uncover real vulnerabilities before customers do.

You will lead threat modeling, perform offensive testing, and ensure security is integrated throughout the CI/CD pipeline, driving secure-by-design practices across engineering teams.

Qualifications

  • 5+ years in Application or Product Security
  • Bachelor's degree or equivalent
  • Hands-on web app security testing and API security
  • Strong knowledge of OWASP Top 10
  • Experience with CI/CD security integration

Responsibilities

  • Design and maintain security regression test suites for critical flows.
  • Lead structured threat modeling sessions for existing and new features.
  • Perform manual and automated security testing simulating real attacker behavior.
  • Continuously assess the platform against OWASP Top 10 categories and go beyond tooling.
  • Review new features for security risks and ensure threat modeling and regression coverage.

Skills

Web app security testing
API security
Threat modeling
CI/CD security integration
Penetration testing
Authentication & sessions

Education

Bachelor's Degree or equivalent

Job description

Why A365 Software Engineering?

Build the cloud platform that’s transforming electronics design. Altium 365 for cloud lets design engineers communicate, collaborate and bring their ideas to market more efficiently than any platform in the industry.

Job Details
  • Full-time
  • Employment Type: Regular (PERM)
  • Remote Work Available: No
Job Description

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention.

The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.

Key Responsibilities
  • Security Regression Testing
    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for:
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into:
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to:
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10–Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are:
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck:
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with:
      • Engineering teams
      • Architecture
      • SRE / Platform teams
    • Contribute to secure-by-design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through:
      • Reusable patterns
      • Automation
      • Security guidance
Qualifications
Required Qualifications
  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in:
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
    • Authentication, authorization, and session management
    • Multi-tenant architectures
    • Cloud-native systems
Preferred Qualifications
  • Experience in SaaS / multi-tenant platforms
  • Familiarity with:
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of:
    • AWS
    • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)
Additional Information

Altium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software‑defined world with our industry‑first cloud‑based platform that unites every stakeholder and phase of electronics development.

From startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.

We believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer
Staff Product Security Engineer

Renesas Electronics • Cambridge

On-site
GBP 90,000 - 120,000
Senior Product Security Engineer - Cloud & App Security
Senior Product Security Engineer - Cloud & App Security

GCA Altium • Cambridge

On-site
GBP 80,000 - 110,000
Staff Product Security Engineer
Staff Product Security Engineer

GCA Altium • Cambridge

On-site
GBP 80,000 - 110,000
Senior Enterprise Account Strategist
Senior Enterprise Account Strategist

Altium • Cambridge

On-site
GBP 90,000 - 150,000
Private health insurance including.
Pension scheme with company match up
Remote working abroad program
+7
Product Security Engineer
Product Security Engineer

Action1 Corporation • United Kingdom

Hybrid
GBP 60,000 - 85,000
Fully remote work environment
Opportunity to work on a real security product
Close collaboration with teams
+1
Staff Strategic Account Manager
Staff Strategic Account Manager

Altium • Cambridge

On-site
GBP 90,000 - 150,000
Private health insurance including.
Pension scheme with company match up
Remote working abroad program
+7
Staff Strategic Account Manager
Staff Strategic Account Manager

Renesas Electronics Corporation • United Kingdom

Hybrid
GBP 90,000 - 125,000
Private health insurance including?d
Pension scheme with company match up 9
Remote working abroad program
+1
Senior Product Security Engineer
Senior Product Security Engineer

Camwebdir • United Kingdom

Hybrid
GBP 90,000 - 130,000
Staff Strategic Account Manager
Staff Strategic Account Manager

GCA Altium • Cambridge

On-site
GBP 90,000 - 130,000
Private health insurance
Pension scheme with company match up 9
Mental health and wellbeing support
+2
Senior Product Security Engineer
Senior Product Security Engineer

Arm Limited • Cambridge

Hybrid
GBP 60,000 - 80,000