- We’re looking for a Principal Product Security Engineer to shape how we design, build, and ship secure software at Tellent
- This is a new, hands‑on role sitting directly within Engineering. At least 30% of your time will be spent actively looking for vulnerabilities in our own products. The rest will focus on making sure the next vulnerability doesn’t get written in the first place - through threat modelling, secure‑by‑default patterns, and close collaboration with our engineering teams
- Your goal won’t simply be to find and fix individual vulnerabilities. You’ll help us understand their root causes and eliminate whole classes of security issues across our products
- You’ll work alongside our engineering leads and closely with our existing Security and GRC team. They own corporate security policy, certification, risk and incident response; you’ll focus on product security, close to our engineers, architecture and code
- This isn’t a gatekeeper role. Your impact will come from partnering with teams, building trust, and creating solutions that make the secure way the easiest way to build
- As our first dedicated Principal Product Security Engineer, you’ll also have significant influence over how the function develops. We’ll bring the context and priorities; you’ll help turn them into a product security roadmap and own the technical direction from there
- First 3 months: You’ll get to know our architecture, products and engineering teams while building a clear picture of our current threat landscape. Through hands‑on review and offensive testing, you’ll deliver a credible, prioritised assessment of our most important product security risks
- Within 6 months: You’ll have threat models in place for our highest‑risk surfaces, including our AI features, with the most serious gaps either addressed or credibly planned. You’ll have shipped at least one systemic improvement that removes a class of vulnerability rather than fixing a single instance
- After 1 year: Secure‑by‑default standards and paved paths will be increasingly embedded into how our teams build. Engineers will involve you during design rather than only before launch, and we’ll be catching more serious security issues internally before they reach us from outside
- Perform deep manual security reviews and offensive testing across our services, APIs and clients, with particular attention to authorization, multi‑tenancy, business logic and other high‑risk areas
- Threat model our highest‑risk product surfaces, including new AI functionality, and help teams develop the skills to eventually run this practice themselves
- Own the technical strategy for our application security tooling, currently Aikido, focusing on actionable signal, developer experience and low false‑positive rates
- Triage vulnerabilities from internal tooling, penetration tests and external researchers, make severity calls you can defend, and partner with teams to verify that fixes work
- Identify patterns and root causes across findings and build systemic fixes, secure‑by‑default libraries and paved paths that prevent vulnerabilities from recurring
- Develop secure development standards that engineers can use in their day‑to‑day work
- Partner with our Security team on our bug bounty programe, pentest remediation, security champions network and training based on real findings
- Act as a senior technical partner for product security incidents and when security or privacy commitments require engineering controls
- Shape and own our product security roadmap, working across Backend, Frontend, QA, DevOps, Product and Security
Benefits
- Hybrid work: You decide if and when you want to come to one of our offices.
- Flexible hours: Our employees can choose which working hours are the best for them
- Training budget: Up to €1500 per year for your personal development. You will keep your skills sharp
- Well‑being support: Direct, free, and easy access to professional mental health support (provided by OpenUp)
- Equipment: We offer everyone a MacBook, a screen and Apple accessories
- Fitness subscription: We offer everyone a sports card that is acceptable in many fitness facilities.
- Work from anywhere: Take your laptop and work from anywhere (for up to 4 weeks/year)
Strong understanding of areas such as access control and multi-tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse and supply-chain riskA collaborative, low-ego approach. You see product security as an enabling function and build relationships that make teams want to involve you earlyHands-on engineering skills. You’re comfortable reading and writing production code and reasoning about unfamiliar systems and technologiesA technology-agnostic mindset. You’re comfortable moving between different languages, stacks and environments depending on the problem you’re solvingExcellent communication skills. You can explain a subtle vulnerability to the engineer who wrote the code and discuss the resulting trade-offs with senior stakeholdersStrong examples of vulnerabilities you’ve personally identified and can walk us through, from forming the hypothesis and proving the impact to getting the issue fixedWorking knowledge of cloud security, containers, CI/CD and infrastructure as codeExperience threat modelling real systems and translating findings into practical engineering workThe profile that will likely thrive in this role is someone with a strong engineering foundation who moved deeper into security and is still comfortable working directly with codeDeep hands-on application or product security experience, ideally built across both engineering and security rolesFamiliarity with technologies already used across Tellent is helpful, but we don’t expect you to arrive knowing our entire stack. We’d rather hire a strong, adaptable security engineer who can learn our systems than someone tied to one particular technologyCertifications such as OSCP, CISSP, CISM or CSSLP are welcome, but not required. Practical experience matters more to us than certificationsExperience with AI and LLM application security, including prompt injection, excessive agency and data leakage through model context or RAG, would be particularly valuable. Experience with privacy engineering, identity systems such as OAuth 2.0, OIDC and SAML, offensive security, company or platform integrations, or building a product security practice from an early stage would also be a plus