Staff Product Security Engineer

Renesas Electronics

Poland

On-site

PLN 297,239 - 382,165

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Diversity & Inclusion Statement

Job summary

Renesas Electronics is seeking a Senior Product Security Engineer in Poland. This role involves enhancing product security through continuous vulnerability discovery, security regression testing, and offensive security activities. You will ensure that security measures integrate seamlessly into CI/CD pipelines while leading threat modeling sessions across various functionalities.

The ideal candidate should have over 5 years of experience in Application/Product Security, a bachelor's degree, and strong hands-on expertise in web application security testing and API security. This position offers a dynamic work environment focused on continuous improvement and collaboration with multiple teams.

Qualifications

  • 5+ years in Application / Product Security.
  • Deep understanding of OWASP Top 10.
  • Strong hands-on experience in web application and API security.

Responsibilities

  • Perform security regression testing and maintain test suites.
  • Lead threat modeling sessions and identify attack surfaces.
  • Conduct manual and automated security testing simulating real attacker behavior.

Skills

Web application security testing
API security
Threat modeling methodologies
Business logic vulnerability identification
Manual penetration testing

Education

Bachelor's Degree or equivalent experience

Tools

CI/CD security integration
Security automation frameworks

Job description

Job Description

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention. This role is responsible for building and executing security regression testing, driving threat modeling across existing and new functionality, conducting targeted offensive security activities (Red Team-style testing), and identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks.

Key Responsibilities
  • Security Regression Testing
    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10-Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with
      • Engineering teams
      • Architecture
      • SRE / Platform teams
    • Contribute to secure‑by‑design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through
      • Reusable patterns
      • Automation
      • Security guidance
Qualifications
Required Qualifications
  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands‑on experience in
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of
    • Authentication, authorization, and session management
    • Multi‑tenant architectures
    • Cloud‑native systems
Preferred Qualifications
  • Experience in SaaS / multi‑tenant platforms
  • Familiarity with
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of
    • AWS
    • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

Renesas Electronics is an equal opportunity and affirmative action employer, committed to supporting diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by law. For more information, please read our Diversity & Inclusion Statement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer: Threat Modeling & Red Team
Product Security Engineer: Threat Modeling & Red Team

Renesas Electronics • Poland

On-site
PLN 297,239 - 382,165
Diversity & Inclusion Statement
Staff Product Security Engineer
Staff Product Security Engineer

Renesas Electronics Corp. • Województwo śląskie

On-site
PLN 220,000 - 360,000
Staff Product Security Engineer
Staff Product Security Engineer

Altium • Wrocław

On-site
PLN 180,000 - 300,000
Competitive benefits package
Senior Application Security Engineer (Java)
Senior Application Security Engineer (Java)

SoftServe • Polska

On-site
PLN 180,000 - 240,000
Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Poland

On-site
PLN 254,022 - 381,033
Health care coverage
Generous time off
Continuous learning resources
+2
Embedded Penetration Tester
Embedded Penetration Tester

Spyro Soft • Wrocław

On-site
PLN 180,000 - 240,000
Senior Cloud Product Security Engineer — Threat Modeling & Red Team
Senior Cloud Product Security Engineer — Threat Modeling & Red Team

Renesas Electronics Corp. • Województwo śląskie

On-site
PLN 220,000 - 360,000
Product Security Engineer (m/f/d)
Product Security Engineer (m/f/d)

Aras Corporation • Poland

On-site
PLN 180,000 - 240,000
Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Gdańsk

Hybrid
PLN 180,000 - 360,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

On-site
PLN 190,000 - 270,000