Product Security Engineer: Secure by Design

Celestica

Monterrey

Presencial

MXN 600.000 - 1.200.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Celestica is seeking a Product Security Engineer to bridge cybersecurity and software engineering. You will collaborate with DevOps and Engineering to bake security into the SDLC and shift left by identifying vulnerabilities during design and coding stages.

Responsibilities include threat modeling, vulnerability triage, and implementing security tooling. You will train developers, lead internal red-teaming, and respond to incidents with subject matter expertise.

Formación

  • Deep knowledge of OWASP Top 10 and cloud security.
  • Experience with Snyk, Checkmarx, Burp Suite, or GitHub Advanced Security.
  • Familiarity with Docker, Kubernetes, and CI/CD pipelines (Jenkins, GitLab CI).

Responsabilidades

  • Secure Design & Threat Modeling by reviewing features before coding; identify attack vectors and mitigations.
  • Vulnerability Management by triaging bugs from scanners, audits, or bug bounty.
  • Security Tooling: implement and manage SAST, DAST, and SCA to catch insecure dependencies.
  • Code Reviews: perform deep dives into critical codebases to spot logic flaws.
  • Incident Response: act as SME when a security flaw is exploited in production.
  • Internal Red Teaming: lead activities to bypass logic to alter data.
  • Developer Training: build Security Champions programs to teach secure coding.

Conocimientos

OWASP Top 10 knowledge
Cloud security

Herramientas

Snyk
Checkmarx
Burp Suite
GitHub Advanced Security
Docker
Kubernetes
Jenkins
GitLab CI

Descripción del empleo

A Software Product Security role (often called Product Security Engineer or ProdSec) is the bridge between traditional cybersecurity and software engineering. Unlike IT security, which focuses on protecting the company's internal network, Product Security focuses on ensuring the software the company sells or provides is resilient against attacks.

About the Role

The Product Security Engineer works directly with DevOps and Engineering teams to bake security into the Software Development Life Cycle (SDLC). The goal is to move security "left"—finding and fixing vulnerabilities during the design and coding phases rather than after the product has launched.

Responsibilities

  • Secure Design & Threat Modeling: Reviewing new features before a single line of code is written. You’ll identify potential attack vectors and suggest mitigations.
  • Vulnerability Management: Triaging bugs found via automated scanners, internal audits, or Bug Bounty programs.
  • Security Tooling: Implementing and managing tools like SAST (Static Analysis), DAST (Dynamic Analysis), and SCA (Software Composition Analysis) to catch insecure dependencies.
  • Code Reviews: Performing manual "deep dives" into critical codebases to spot logic flaws that automated tools might miss.
  • Incident Response: Acting as a subject matter expert when a security flaw is exploited in production.
  • Internal Red Teaming: Lead activities to find ways to bypass the logic to alter "Recipe" files or production data.
  • Developer Training: Creating "Security Champions" programs to teach engineers how to write defensive code.

Qualifications

  • Deep understanding of the OWASP Top 10 (SQLi, XSS, CSRF) and cloud security (AWS/Azure/GCP).
  • Experience with Snyk, Checkmarx, Burp Suite, or GitHub Advanced Security.
  • Familiarity with Docker, Kubernetes, and CI/CD pipelines (Jenkins, GitLab CI).

Required Skills

  • Deep understanding of the OWASP Top 10 (SQLi, XSS, CSRF) and cloud security (AWS/Azure/GCP).
  • Experience with Snyk, Checkmarx, Burp Suite, or GitHub Advanced Security.
  • Familiarity with Docker, Kubernetes, and CI/CD pipelines (Jenkins, GitLab CI).

Preferred Skills

  • Experience with Snyk, Checkmarx, Burp Suite, or GitHub Advanced Security.
  • Familiarity with Docker, Kubernetes, and CI/CD pipelines (Jenkins, GitLab CI).

Pay range and compensation package

This isn’t a "gatekeeper" role. To be successful, you have to be a collaborative problem-solver. Developers often see security as a hurdle; your job is to make the "secure way" the "easy way." If you enjoy breaking things to learn how to fix them, you’ll love ProdSec.

Equal Opportunity Statement

I’m looking for "Security Engineers" who can actually code and contribute to the repository, rather than just pointing out problems and leaving.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Software Product Security Engineer
Software Product Security Engineer

Celestica • Monterrey

Presencial
MXN 600.000 - 1.200.000
Senior Security Software Engineer – Open Source Platform
Senior Security Software Engineer – Open Source Platform

Canonical • Ciudad de México

A distancia
MXN 736.000 - 1.106.000
Application Cyber Secuirty Engineer
Application Cyber Secuirty Engineer

TSSI Recruit Ltd • Ciudad de México

Presencial
MXN 600.000 - 800.000
Senior Security Application Engineer - Automation & Detection
Senior Security Application Engineer - Automation & Detection

PVH (Tommy Hilfiger/Calvin Klein) • Región Centro

Presencial
MXN 2.099.000 - 3.150.000
Security Software Engineer
Security Software Engineer

Canonical • Ciudad de México

A distancia
MXN 736.000 - 1.106.000
Personal learning and development budget of USD 2,000 per year
Annual compensation review
Maternity and paternity leave
+1
Senior Security Developer
Senior Security Developer

Dematic • Guadalupe

Híbrido
MXN 1.203.000 - 1.719.000
Career Development
Competitive Compensation and Benefits
Pay Transparency
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

Presencial
MXN 700.000 - 1.100.000
Biweekly pay
IMSS
Christmas bonus
+6
Software Engineer - Go Specialist
Software Engineer - Go Specialist

Pavago • México

Presencial
USD 120.000 - 180.000
Senior Staff Engineer - DevOps Engineer
Senior Staff Engineer - DevOps Engineer

Nagarro • Región Centro

Presencial
MXN 1.000.000 - 1.500.000
Security Engineer
Security Engineer

Bright Machines, Inc. • Región Centro

Presencial
MXN 850.000 - 1.350.000