Staff Product Security Engineer

Renesas Electronics

Portugal

Presencial

EUR 65 000 - 85 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Renesas Electronics is looking for a Senior Product Security Engineer in Portugal to enhance its Product Security capabilities. This role focuses on continuous vulnerability discovery and prevention through security regression testing and threat modeling.

The ideal candidate will have a strong background in application security with 5+ years of experience, a Bachelor’s degree, and deep knowledge of OWASP Top 10 risks. This position encourages collaboration across teams to support secure design practices.

Qualificações

  • 5+ years in Application/Product Security.
  • Deep understanding of OWASP Top 10.
  • Experience with manual penetration testing and security regression testing.

Responsabilidades

  • Design and maintain security regression test suites covering critical application flows.
  • Lead structured threat modeling sessions for existing system components and new features.
  • Perform manual and automated security testing simulating real attacker behavior.

Conhecimentos

Web application security testing
API security
Threat modeling methodologies
Business logic vulnerability identification

Formação académica

Bachelor's Degree or equivalent work experience

Ferramentas

Manual penetration testing
Security regression testing
CI/CD security integration

Descrição da oferta de emprego

Job Description

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention. This role is responsible for building and executing security regression testing, driving threat modeling across existing and new functionality, conducting targeted offensive security activities (Red Team-style testing), and identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks.

Key Responsibilities
  • Security Regression Testing
    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10-Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with
      • Engineering teams
      • Architecture
      • SRE / Platform teams
    • Contribute to secure‑by‑design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through
      • Reusable patterns
      • Automation
      • Security guidance
Qualifications
Required Qualifications
  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands‑on experience in
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of
    • Authentication, authorization, and session management
    • Multi‑tenant architectures
    • Cloud‑native systems
Preferred Qualifications
  • Experience in SaaS / multi‑tenant platforms
  • Familiarity with
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of
    • AWS
    • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

Renesas Electronics is an equal opportunity and affirmative action employer, committed to supporting diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by law. For more information, please read our Diversity & Inclusion Statement.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Staff Product Security Engineer
Staff Product Security Engineer

Renesas Electronics • Lisboa

Presencial
EUR 60 000 - 80 000
Flexible work environment
Diversity and inclusion initiatives
Career advancement opportunities
Senior Product Security Engineer: Threat Modeling & Red Team
Senior Product Security Engineer: Threat Modeling & Red Team

Renesas Electronics • Lisboa

Presencial
EUR 60 000 - 80 000
Flexible work environment
Diversity and inclusion initiatives
Career advancement opportunities
Product Security Engineer: Threat Modeling & Red Team
Product Security Engineer: Threat Modeling & Red Team

Renesas Electronics • Portugal

Presencial
EUR 65 000 - 85 000
Application Security Engineer
Application Security Engineer

LUZA Group • Porto

Híbrido
EUR 50 000 - 70 000
Remote work when possible
Equipment provided
Benefits plan
Senior DevSecOps & Product Security Engineer
Senior DevSecOps & Product Security Engineer

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
Application Security Engineer
Application Security Engineer

Jobtailor • Lisboa

Presencial
EUR 60 000 - 80 000
Devoteam Cyber Trust | Product Engineer – Security Platform
Devoteam Cyber Trust | Product Engineer – Security Platform

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 48 000 - 72 000
application security engineer for cloud software
application security engineer for cloud software

Enfint • Lisboa

Presencial
EUR 55 000 - 75 000
Security Analyst
Security Analyst

act digital EMEA - Alter Solutions • Lisboa

Presencial
EUR 50 000 - 70 000
Application Security Engineer
Application Security Engineer

Expleo • São Domingos de Benfica

Presencial
EUR 55 000 - 90 000