Product Security Engineer

Insight Global

Westborough (MA)

On-site

USD 83,000 - 96,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Insight Global is seeking a Senior Product Security Engineer to identify security requirements, perform threat modeling, and architect secure AI-enabled products. The role focuses on security across software, cloud, and devices, with emphasis on integrating secure design into the product lifecycle.

You will collaborate with cross-functional teams, apply SSDLC and DevSecOps practices, conduct security testing, and contribute to risk assessments and compliance documentation.

Qualifications

  • Experience with embedded technology and software security.
  • Experience in using SSDLC within agile framework.
  • Expertise in threat modelling, security risk management, secure coding, secure system development, and DevSecOps
  • Knowledge of application security and code analysis tools such as Veracode, SonarQube, BlackDuck, Cyberspect, Nessus or similar.
  • Experience with security techniques, standards, and methods for authentication and authorization, applied cryptography, security vulnerabilities and remediation in Windows .NET and Azure environments.
  • Knowledge of government and industry standards, guidance’s and frameworks applicable to product software development such as NIST Cybersecurity Framework, OWASP, HIPAA, GDPR, SANS/CWE and/or CERT.
  • Solid technical background and understanding of all aspects of security research and development
  • Excellent analytical and troubleshooting skills.
  • Ability to work both independently and in a team environment.
  • Excellent communication skills, oral and written.
  • Able to work in a multi-discipline collaborative environment to include international colleagues and Olympus partners.
  • Bachelor's degree in Computer Science, information technology, cybersecurity, or related area required, or minimum of 5 years’ experience in a relevant industry.
  • Familiarity with Secure AI Lifecycle (SAILC) concepts and secure development practices for AI-enabled systems.
  • Strong Understanding of AI Security Tools

Responsibilities

  • Plan, test, and implement advanced software security controls and techniques in alignment with enterprise security architecture and secure design principles.
  • Conduct ongoing security testing, code reviews, and vulnerability assessments to strengthen the security posture of software applications and platforms.
  • Identify, assess, and mitigate AI-specific security risks, including prompt injection, adversarial machine learning attacks, model evasion, model extraction, training data poisoning, inference attacks, and unauthorized model manipulation.
  • Perform security architecture reviews and threat modeling activities for software, cloud-based solutions, connected devices, and AI/ML-enabled products.
  • Design and implement security solutions to address vulnerabilities and reduce product and application risk.
  • Develop, maintain, and contribute to product threat models, security risk assessments, and cybersecurity risk management activities throughout the product development lifecycle.
  • Serve as a Product Security and AI Security subject matter expert, guiding development teams on secure design, secure coding practices, and emerging security threats.
  • Promote security awareness across engineering teams and help drive adoption of security best practices and compliance requirements.
  • Collaborate with cross-functional teams to define and execute security testing strategies, including static code analysis, dynamic testing, fuzz testing, penetration testing, compliance validation, and vulnerability management.
  • Design, develop, evaluate, and maintain AI-powered security tools, automations, and intelligent agents that enhance security processes such as threat modeling, risk assessments, security testing, compliance documentation, and secure design reviews.
  • Provide technical guidance and consultation on secure software development, application security, cloud security, and AI security practices.
  • Ensure compliance with applicable regulatory requirements, industry standards, cybersecurity frameworks, and internal security policies.
  • Support secure product development activities by integrating security requirements into design, development, testing, and release processes.
  • Monitor emerging threats, vulnerabilities, technologies, regulations, and industry best practices, and recommend improvements to security programs and controls.
  • Contribute to continuous improvement initiatives that enhance product security, cybersecurity resilience, and AI governance practices across the organization.

Skills

Embedded security
SSDLC in Agile
Threat modelling
Security risk mgmt
Secure coding
DevSecOps
AI security tools
Analytical skills
Communication skills
Independent worker
Team collaboration
Secure AI lifecycle familiarity

Education

Bachelor's degree in CS/IT/cybersecurity
5 years relevant experience

Tools

Veracode
SonarQube
BlackDuck
Cyberspect
Nessus

Job description

Job Description

Our Client is developing software-based products that will require security engineering. The Senior Product Security Engineer within the team will identify security related requirements, assist with threat models, help architect secure solutions, analyze software designs and implementations from a security perspective, and develop and maintain compliant documentation associated with product security. This role requires technical expertise, knowledge of safety critical systems, and the ability to work in a team environment to ensure security and resilience of our current and developing digital products.

Responsibilities
  • Plan, test, and implement advanced software security controls and techniques in alignment with enterprise security architecture and secure design principles.
  • Conduct ongoing security testing, code reviews, and vulnerability assessments to strengthen the security posture of software applications and platforms.
  • Identify, assess, and mitigate AI-specific security risks, including prompt injection, adversarial machine learning attacks, model evasion, model extraction, training data poisoning, inference attacks, and unauthorized model manipulation.
  • Perform security architecture reviews and threat modeling activities for software, cloud-based solutions, connected devices, and AI/ML-enabled products.
  • Design and implement security solutions to address vulnerabilities and reduce product and application risk.
  • Develop, maintain, and contribute to product threat models, security risk assessments, and cybersecurity risk management activities throughout the product development lifecycle.
  • Serve as a Product Security and AI Security subject matter expert, guiding development teams on secure design, secure coding practices, and emerging security threats.
  • Promote security awareness across engineering teams and help drive adoption of security best practices and compliance requirements.
  • Collaborate with cross-functional teams to define and execute security testing strategies, including static code analysis, dynamic testing, fuzz testing, penetration testing, compliance validation, and vulnerability management.
  • Design, develop, evaluate, and maintain AI-powered security tools, automations, and intelligent agents that enhance security processes such as threat modeling, risk assessments, security testing, compliance documentation, and secure design reviews.
  • Provide technical guidance and consultation on secure software development, application security, cloud security, and AI security practices.
  • Ensure compliance with applicable regulatory requirements, industry standards, cybersecurity frameworks, and internal security policies.
  • Support secure product development activities by integrating security requirements into design, development, testing, and release processes.
  • Monitor emerging threats, vulnerabilities, technologies, regulations, and industry best practices, and recommend improvements to security programs and controls.
  • Contribute to continuous improvement initiatives that enhance product security, cybersecurity resilience, and AI governance practices across the organization.
Compensation

$60-70/hr

Exact compensation may vary based on several factors, including skills, experience, and education.

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
  • Experience with embedded technology and software security.
  • Experience in using Secure Software Development Lifecycle (SSDLC) within agile framework.
  • Expertise in threat modelling, security risk management, secure coding, secure system development, and DevSecOps
  • Knowledge of application security and code analysis tools such as Veracode, SonarQube, BlackDuck, Cyberspect, Nessus or similar.
  • Experience with security techniques, standards, and methods for authentication and authorization, applied cryptography, security vulnerabilities and remediation in Windows .NET and Azure environments.
  • Knowledge of government and industry standards, guidance’s and frameworks applicable to product software development such as NIST Cybersecurity Framework, OWASP, HIPAA, GDPR, SANS/CWE and/or CERT.
  • Solid technical background and understanding of all aspects of security research and development
  • Excellent analytical and troubleshooting skills.
  • Ability to work both independently and in a team environment.
  • Excellent communication skills, oral and written.
  • Able to work in a multi-discipline collaborative environment to include international colleagues and Olympus partners.
  • Bachelor's degree in Computer Science, information technology, cybersecurity, or related area required, or minimum of 5 years’ experience in a relevant industry.
  • Familiarity with Secure AI Lifecycle (SAILC) concepts and secure development practices for AI-enabled systems.
  • Strong Understanding of AI Security Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Product Security Engineer - Team Lead
Product Security Engineer - Team Lead

Meta • Bellevue (WA)

On-site
USD 180,000 - 260,000
AI Application Security Engineer
AI Application Security Engineer

Insight Global • Naperville (IL)

On-site
USD 120,000 - 160,000
Software Engineer, AI Product Security
Software Engineer, AI Product Security

Notion • New York (NY)

On-site
USD 150,000 - 190,000
Cash Compensation
Equity
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Software Engineer, AI Security
Software Engineer, AI Security

Hong Kong Next Generation Internet Society • San Francisco (CA)

On-site
USD 180,000 - 280,000
Equity
Cash Compensation
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Principal Security Engineer
Principal Security Engineer

Insight Global • Raleigh (NC)

Hybrid
USD 140,000 - 190,000