Principal Product Security Engineer

TELLENT

Poznań

Hybrid

PLN 523,000 - 784,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid/Remote work across NL, DE, PL
Annual training budget
2 dedicated learning days
Pension plan
Travel reimbursement
Wellness perks
28 paid holidays + 2 days off
Work from anywhere 4 weeks/year
MacBook and tooling budget
Home office budget €200

Job summary

Tellent is seeking a Principal Product Security Engineer to shape secure software design, build, and release processes. You will spend a portion actively hunting vulnerabilities while shaping threat models and secure‑by‑default patterns across engineering teams.

You’ll partner with Security, GRC and Engineering, driving a product security roadmap and owning the technical direction. This is a high‑impact role with significant influence on how security is embedded in development.

Qualifications

  • Deep hands‑on application or product security experience across engineering and security roles.
  • Experience threat modelling real systems and translating findings into practical engineering work.
  • Strong understanding of access control, multi‑tenancy, authN/authZ, and secure development patterns.

Responsibilities

  • Perform deep manual security reviews and offensive testing across services, APIs and clients.
  • Threat model highest‑risk product surfaces and help teams develop the skill to run this practice.
  • Own the technical strategy for application security tooling and improve developer experience.

Skills

Threat modelling
Offensive security
Application security
Cloud security
CI/CD
Programming in production code
Communication skills

Tools

Aikido

Job description

Note: The listed salary range is based on the salary range for the Netherlands. Salary ranges may vary by location.

About the role

We're looking for a Principal Product Security Engineer to shape how we design, build, and ship secure software at Tellent.

This is a new, hands‑on role sitting directly within Engineering. At least 30% of your time will be spent actively looking for vulnerabilities in our own products. The rest will focus on making sure the next vulnerability doesn’t get written in the first place - through threat modelling, secure‑by‑default patterns, and close collaboration with our engineering teams.

Your goal won’t simply be to find and fix individual vulnerabilities. You’ll help us understand their root causes and eliminate whole classes of security issues across our products.

You’ll work alongside our engineering leads and closely with our existing Security and GRC team. They own corporate security policy, certification, risk and incident response; you’ll focus on product security, close to our engineers, architecture and code.

This isn’t a gatekeeper role. Your impact will come from partnering with teams, building trust, and creating solutions that make the secure way the easiest way to build.

As our first dedicated Principal Product Security Engineer, you’ll also have significant influence over how the function develops. We’ll bring the context and priorities; you’ll help turn them into a product security roadmap and own the technical direction from there.

Your First Year at Tellent

First 3 months: You’ll get to know our architecture, products and engineering teams while building a clear picture of our current threat landscape. Through hands‑on review and offensive testing, you’ll deliver a credible, prioritised assessment of our most important product security risks.

Within 6 months: You’ll have threat models in place for our highest‑risk surfaces, including our AI features, with the most serious gaps either addressed or credibly planned. You’ll have shipped at least one systemic improvement that removes a class of vulnerability rather than fixing a single instance.

After 1 year: Secure‑by‑default standards and paved paths will be increasingly embedded into how our teams build. Engineers will involve you during design rather than only before launch, and we’ll be catching more serious security issues internally before they reach us from outside.

What You’ll Be Doing
  • Perform deep manual security reviews and offensive testing across our services, APIs and clients, with particular attention to authorization, multi‑tenancy, business logic and other high‑risk areas.

  • Threat model our highest‑risk product surfaces, including new AI functionality, and help teams develop the skills to eventually run this practice themselves.

  • Own the technical strategy for our application security tooling, currently Aikido, focusing on actionable signal, developer experience and low false‑positive rates.

  • Triage vulnerabilities from internal tooling, penetration tests and external researchers, make severity calls you can defend, and partner with teams to verify that fixes work.

  • Identify patterns and root causes across findings and build systemic fixes, secure‑by‑default libraries and paved paths that prevent vulnerabilities from recurring.

  • Develop secure development standards that engineers can use in their day‑to‑day work.

  • Partner with our Security team on our bug bounty programe, pentest remediation, security champions network and training based on real findings.

  • Act as a senior technical partner for product security incidents and when security or privacy commitments require engineering controls.

  • Shape and own our product security roadmap, working across Backend, Frontend, QA, DevOps, Product and Security.

What You’ll Bring

The profile that will likely thrive in this role is someone with a strong engineering foundation who moved deeper into security and is still comfortable working directly with code.

  • Deep hands‑on application or product security experience, ideally built across both engineering and security roles.

  • Strong examples of vulnerabilities you’ve personally identified and can walk us through, from forming the hypothesis and proving the impact to getting the issue fixed.

  • Strong understanding of areas such as access control and multi‑tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse and supply‑chain risk.

  • Hands‑on engineering skills. You’re comfortable reading and writing production code and reasoning about unfamiliar systems and technologies.

  • Experience threat modelling real systems and translating findings into practical engineering work.

  • Working knowledge of cloud security, containers, CI/CD and infrastructure as code.

  • A technology‑agnostic mindset. You’re comfortable moving between different languages, stacks and environments depending on the problem you’re solving.

  • Excellent communication skills. You can explain a subtle vulnerability to the engineer who wrote the code and discuss the resulting trade‑offs with senior stakeholders.

  • A collaborative, low‑ego approach. You see product security as an enabling function and build relationships that make teams want to involve you early.

Experience with AI and LLM application security, including prompt injection, excessive agency and data leakage through model context or RAG, would be particularly valuable. Experience with privacy engineering, identity systems such as OAuth 2.0, OIDC and SAML, offensive security, company or platform integrations, or building a product security practice from an early stage would also be a plus.

Certifications such as OSCP, CISSP, CISM or CSSLP are welcome, but not required. Practical experience matters more to us than certifications.

Familiarity with technologies already used across Tellent is helpful, but we don’t expect you to arrive knowing our entire stack. We’d rather hire a strong, adaptable security engineer who can learn our systems than someone tied to one particular technology.

What We Offer
  • Hybrid or remote working setup across the Netherlands, Germany and Poland.

  • The opportunity to establish and shape product security within our Engineering organisation from the ground up.

  • Significant autonomy and direct collaboration with our VP of Engineering and engineering leadership.

  • A diverse, multicultural and remote‑friendly environment.

  • €1,500 annual training budget + 2 dedicated learning days.

  • Dedicated tooling budget and opportunities to stay connected to the wider security community through conferences and research.

  • Pension plan, travel reimbursement and wellness perks.

  • 28 paid holiday days + 2 additional days to relax.

  • Work from anywhere for 4 weeks per year.

  • Apple MacBook and top‑tier tooling.

  • €200 home office budget.

Please note: Benefits may differ based on your employment location.

About Tellent

Tellent is a Talent Management Suite that helps organizations attract, hire, manage, and grow their people. Our platform combines Applicant Tracking, HRIS, and Performance Management solutions used by 7,000+ companies across 100+ countries.

With 250+ employees across Europe, we’re building intuitive and scalable HR technology that helps companies create better employee experiences.

The products we build handle some of the most sensitive information people share in their working lives — from candidate applications and employee records to performance data. Security and privacy therefore can’t simply be bolted on afterwards; they need to be part of how our products are designed and built. This becomes even more important as we introduce AI‑powered functionality across our products.

AI in our recruitment process

We use our internally developed AI tools to help streamline our recruitment process. However, technology never makes a decision. Every candidate is personally reviewed by our team. Your journey with us is guided by people, supported by tech. Curious about how it works? Read our AI Statement, check our Privacy Policy, or chat with us at hr@tellent.com.

If you require accommodations or support during the recruitment process, please let us know — we’re happy to help.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Backend Developer (Elixir)
Senior Backend Developer (Elixir)

TELLENT • Poznań

Hybrid
PLN 200,000 - 260,000
Annual training budget
2 learning days
Pension plan
+6
Security & Compliance Engineer
Security & Compliance Engineer

Nomagic • Warszawa

Hybrid
PLN 290,160 - 357,120
Equity for every employee
Relocation package
No late evening calls
+1
Security Engineering Lead
Security Engineering Lead

Attio • Poland

On-site
PLN 517,000 - 624,000
Equity
Apple hardware
Team off-site
+1
Head of Information Security
Head of Information Security

Constructor Tech • Warszawa

On-site
PLN 360,000 - 480,000
Choice of work equipment
English classes (iTalki – $130 monthly
Flexible schedule
+5
Director, Product Security
Director, Product Security

Gainsight • Wrocław

On-site
PLN 435,000 - 502,000
Premium private medical care
Multisport Cards
Flexible remote work options
+1
Staff Product Security Architect
Staff Product Security Architect

GitLab Inc. • Polska

Hybrid
USD 180,000 - 240,000
Head of Information Security
Head of Information Security

Constructor Labs • Polska

Hybrid
PLN 180,000 - 260,000
English classes
Newborn bonus
Patent remuneration
+3
Senior Platform Engineer – Developer Experience & AI Enablement
Senior Platform Engineer – Developer Experience & AI Enablement

TRANS.EU • Wrocław

Hybrid
PLN 260,000 - 380,000
Private medical care (Luxmed)
Multisport card
Holiday and gift vouchers
+1
Senior Director, Product Security
Senior Director, Product Security

Gainsight • Wrocław

On-site
PLN 346,000 - 379,000
Premium private medical care
Multisport Card
Flexible remote work options
+1
IT Automation Engineer
IT Automation Engineer

Project 44 • Kraków

On-site
PLN 153,000 - 229,000
In-office four days weekly