Product Security Engineer

Kforce Inc

Boston (MA)

On-site

USD 140,000 - 200,000

Full time

32 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Kforce Inc in Boston, MA seeks a Product Security Engineer to partner with software teams and embed security throughout the development lifecycle. The role emphasizes secure coding practices, threat modeling, and applying modern security controls across CI/CD pipelines.

Ideal candidates have 7+ years in product or application security, strong knowledge of secure SDLC, and hands-on security testing, vulnerability remediation, and code reviews.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 7+ years of experience in Application Security, Product Security, or a closely related security engineering role.
  • Strong understanding of secure SDLC practices and modern web application architecture.
  • Experience partnering directly with software development teams.
  • Hands-on experience with application security testing, vulnerability remediation, and security assessments.
  • Experience performing code reviews and providing secure development guidance.
  • Familiarity with cloud security and DevSecOps practices.
  • Knowledge of OWASP Top 10 and common web application vulnerabilities.
  • Experience securing CI/CD pipelines and integrating security into development workflows.
  • Strong communication skills with the ability to influence both technical and non-technical stakeholders.

Responsibilities

  • Partner with software engineers and technical leaders to promote secure coding practices and security-by-design principles.
  • Perform application security assessments and penetration testing activities.
  • Identify vulnerabilities and guide teams through remediation efforts.
  • Conduct code reviews and provide recommendations to improve application security.
  • Help design and implement security controls for internally developed and customer-facing applications.
  • Integrate security tooling and controls into CI/CD pipelines and development workflows.
  • Participate in threat modeling, security architecture reviews, and secure SDLC initiatives.
  • Develop and maintain security standards, policies, and best practices.
  • Support incident response activities related to application and product security.
  • Deliver security education and awareness programs for engineering teams.
  • Stay current on emerging threats, vulnerabilities, and security technologies.

Skills

Security mindset
Vulnerability assessment
Threat modeling
Secure SDLC
CI/CD security
OWASP Top 10
Cross-team collaboration
Code review guidance

Education

Bachelor's degree in Computer Science/IT/Cybersecurity

Tools

CI/CD tooling
Cloud security

Job description

Responsibilities

Kforce's client in Boston, MA is seeking a Product Security Engineer. Summary: We're partnering with a highly respected global organization that is investing heavily in modern application security, cloud technologies, and secure software development practices. This is an opportunity to join a collaborative, high-performing security team and play a key role in protecting business-critical applications while influencing how software is built across the organization. This role is ideal for someone who has a strong foundation in Application Security or Product Security and enjoys partnering directly with software engineering teams to embed security throughout the development lifecycle. What You'll Do:

  • Partner with software engineers and technical leaders to promote secure coding practices and security-by-design principles
  • Perform application security assessments and penetration testing activities
  • Identify vulnerabilities and guide teams through remediation efforts
  • Conduct code reviews and provide recommendations to improve application security
  • Help design and implement security controls for internally developed and customer-facing applications
  • Integrate security tooling and controls into CI/CD pipelines and development workflows
  • Participate in threat modeling, security architecture reviews, and secure SDLC initiatives
  • Develop and maintain security standards, policies, and best practices
  • Support incident response activities related to application and product security
  • Deliver security education and awareness programs for engineering teams
  • Stay current on emerging threats, vulnerabilities, and security technologies
Requirements
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field
  • 7+ years of experience in Application Security, Product Security, or a closely related security engineering role
  • Strong understanding of secure SDLC practices and modern web application architecture
  • Experience partnering directly with software development teams
  • Hands-on experience with application security testing, vulnerability remediation, and security assessments
  • Experience performing code reviews and providing secure development guidance
  • Familiarity with cloud security and DevSecOps practices
  • Knowledge of OWASP Top 10 and common web application vulnerabilities
  • Experience securing CI/CD pipelines and integrating security into development workflows
  • Strong communication skills with the ability to influence both technical and non-technical stakeholders
Preferred Experience
  • Prior software engineering or development background
  • Experience supporting cloud-native applications and modern distributed architectures
  • Familiarity with secure development practices across web applications, APIs, and microservices
  • Experience helping build, mature, or scale a Product Security or Application Security program
Why Consider This Opportunity?
  • High-impact role with visibility across engineering and technology teams
  • Opportunity to shape security strategy and influence software development practices
  • Exposure to modern cloud, DevSecOps, and application security initiatives
  • Collaborative, technology-driven environment
  • Strong compensation package including bonus opportunities
  • Long-term career growth and advancement potential

If you're passionate about secure software development and enjoy working closely with engineering teams to build security into the development process, we'd love to hear from you.

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.

This job is not eligible for bonuses, incentives or commissions.

Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Kforce Inc • New York (NY)

On-site
USD 140,000 - 190,000
Product Security Engineer: Shape Secure SDLC & Cloud
Product Security Engineer: Shape Secure SDLC & Cloud

Kforce Inc • Boston (MA)

On-site
USD 140,000 - 200,000
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

Hybrid
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
DevSecOps Architect
DevSecOps Architect

Kforce Inc • Fort Lauderdale (FL)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+1
Software Engineer
Software Engineer

Kforce Inc • Boston (MA)

On-site
USD 120,000 - 180,000
Medical/dental/vision insurance
HSA/FSA options
401(k) plan
+2
Product Security Engineer Remote - US
Product Security Engineer Remote - US

Secure State.IQ • United States

Remote
USD 120,000 - 180,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Boston (MA)

On-site
USD 140,000 - 200,000
Professional growth
Competitive USD-based compensation
Flextime
Product Security Engineer
Product Security Engineer

Hampton North • United States

Remote
USD 180,000 - 220,000
401(k)
Medical insurance
Vision insurance
+2