security engineer for HR technology

HireHi

United States

Remote

USD 150,000 - 210,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual training budget
Pension plan
Travel reimbursement
Wellness perks
4 weeks work-from-anywhere per year
MacBook and top-tier tooling

Job summary

Tellent provides a Talent Management Suite that helps organizations attract, hire, manage, and grow their people. Its platform combines Applicant Tracking, HRIS, and Performance Management solutions used by 7,000+ companies across 100+ countries.

The company builds scalable HR technology focused on employee experiences and protects sensitive candidate and employee information. We are looking for a senior security engineer to own the product security roadmap across Backend, Frontend, QA, DevOps,

Qualifications

  • Strong engineering foundation with hands-on application or product security experience across engineering and security roles.
  • Proven experience identifying vulnerabilities and explaining the full remediation process.
  • Understanding of access control, multi-tenancy, authentication/authorization, session management, and common web vulnerabilities.
  • Experience threat modelling real systems and translating findings into engineering work.
  • Knowledge of cloud security, containers, CI/CD, and infrastructure as code.
  • Excellent communication for discussing trade-offs with senior stakeholders.
  • Collaborative and low-ego approach to enable product teams.

Responsibilities

  • Perform deep manual security reviews and offensive testing across services, APIs, and clients.
  • Threat model high-risk product surfaces, including new AI functionality.
  • Own the technical strategy for application security tooling (Aikido).
  • Triage vulnerabilities from internal tooling, pentests, and researchers; verify fixes with teams.
  • Identify patterns and root causes; build systemic fixes and secure-by-default libraries.
  • Develop secure development standards for engineers’ day-to-day work.
  • Partner with Security on bug bounty, pentest remediation, and security training.
  • Act as senior technical partner for product security incidents and controls.
  • Shape and own the product security roadmap across Backend, Frontend, QA, DevOps, Product, and Security.
  • Provide a clear threat landscape view and prioritised risk assessments.
  • Embed secure-by-default standards into engineering workflows.

Skills

Vulnerability discovery
Access control & multi-tenancy
Authentication & authorization
Threat modelling
Security architecture
Production code reasoning
Cloud security
CI/CD & IaC
Security storytelling
Security tooling strategy
Security certifications (OSCP/CISSP/C\

Tools

Aikido

Job description

Tellent provides a Talent Management Suite that helps organizations attract, hire, manage, and grow their people. Its platform combines Applicant Tracking, HRIS, and Performance Management solutions used by 7,000+ companies across 100+ countries. The company builds scalable HR technology focused on employee experiences and protects sensitive candidate and employee information.

Задачи:
  • Perform deep manual security reviews and offensive testing across services, APIs, and clients, focusing on authorization, multi-tenancy, business logic, and other high-risk areas;
  • Threat model high-risk product surfaces, including new AI functionality, and help teams develop the skills to run this practice themselves;
  • Own the technical strategy for application security tooling, currently Aikido, with a focus on actionable signals, developer experience, and low false-positive rates;
  • Triage vulnerabilities from internal tooling, penetration tests, and external researchers, make defensible severity calls, and partner with teams to verify fixes;
  • Identify patterns and root causes across findings and build systemic fixes, secure-by-default libraries, and paved paths that prevent recurring vulnerabilities;
  • Develop secure development standards for engineers’ day-to-day work;
  • Partner with the Security team on the bug bounty programme, pentest remediation, security champions network, and training based on real findings;
  • Act as a senior technical partner for product security incidents and engineering controls required by security or privacy commitments;
  • Shape and own the product security roadmap across Backend, Frontend, QA, DevOps, Product, and Security;
  • Build a clear picture of the current threat landscape and deliver a prioritised assessment of key product security risks;
  • Establish threat models for the highest-risk surfaces and ship systemic improvements that remove classes of vulnerabilities;
  • Embed secure-by-default standards and paved paths into engineering workflows.
Требования:
  • Strong engineering foundation with deep hands-on application or product security experience across engineering and security roles;
  • Proven experience personally identifying vulnerabilities and explaining the full process from hypothesis and impact validation to remediation;
  • Strong understanding of access control, multi-tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse, and supply-chain risk;
  • Comfortable reading and writing production code and reasoning about unfamiliar systems and technologies;
  • Experience threat modelling real systems and translating findings into practical engineering work;
  • Working knowledge of cloud security, containers, CI/CD, and infrastructure as code;
  • Technology-agnostic mindset with the ability to work across different languages, stacks, and environments;
  • Excellent communication skills for explaining subtle vulnerabilities and discussing trade-offs with senior stakeholders;
  • Collaborative, low-ego approach focused on enabling product teams and building early engagement;
  • Nice to have: AI and LLM application security, privacy engineering, OAuth 2.0, OIDC, SAML, offensive security, company or platform integrations, building a product security practice from an early stage, OSCP, CISSP, CISM, or CSSLP certifications.
Условия:
  • Hybrid or remote working setup across the Netherlands, Germany, and Poland;
  • Opportunity to establish and shape product security within the Engineering organisation from the ground up;
  • Significant autonomy and direct collaboration with the VP of Engineering and engineering leadership;
  • Diverse, multicultural, and remote-friendly environment;
  • €1,500 Annual training budget and 2 dedicated learning days;
  • Dedicated tooling budget and opportunities to attend conferences and conduct security research;
  • Pension plan, travel reimbursement, and wellness perks;
  • 28 Paid holiday days plus 2 additional days to relax;
  • Work from anywhere for 4 weeks per year;
  • Apple MacBook and top-tier tooling;
  • €200 Home office budget;
  • Benefits may differ based on employment location.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

GoMining • Georgia

On-site
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

On-site
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Application Security Engineer - Senior
Application Security Engineer - Senior

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
security engineer for cloud platforms
security engineer for cloud platforms

HireHi • United States

Hybrid
USD 140,000 - 210,000
Удаленная работа/офис
Помощь с релокацией
Медицинское страхование
+5
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

On-site
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7
Application Security Engineer
Application Security Engineer

Softswiss • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Private health insurance
Sports benefits
Free English lessons (online)
+3
backend developer for an Applicant Tracking System
backend developer for an Applicant Tracking System

HireHi • United States

On-site
USD 120,000 - 180,000
Annual training budget
2 dedicated learning days
Pension plan
+7
security engineer in software development
security engineer in software development

HireHi • United States

Hybrid
USD 75,000 - 273,000
Top-of-the-market health insurance
Rich relocation package
Generous parental support
+2
product manager for XDR security solutions
product manager for XDR security solutions

HireHi • United States

Hybrid
USD 86,000 - 111,000
Health coverage
Flexible locations
Generous vacation
+4
GERMAN SPEAKING SECURITY ENGINEER
GERMAN SPEAKING SECURITY ENGINEER

LITIT • United States

Hybrid
USD 64,000 - 95,000
Remote work opportunities
Office in Vilnius
Flexible time off
+4