Senior Product Security Engineer

Jobtailor

Illinois

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jobtailor seeks a security-focused software engineer to design, build, and operate automated scanners and guardrails across the SDLC. You will reduce risk across code, dependencies, secrets, and AI/LLM tooling, partnering with engineering and security teams.

You will analyze complex challenges, tune controls, write detection rules, and improve remediation guidance using telemetry. Strong scripting in Python/Go/Bash and cloud-native tech like GCP, Kubernetes, Terraform are valued.

Qualifications

  • 3+ years of relevant experience and a Bachelor’s degree or equivalent
  • 3–5 years of experience in software engineering, application or product security, DevSecOps, or cybersecurity
  • Experience developing, integrating, or operating security automation in CI/CD or developer workflows
  • Experience with SAST, SCA, secrets detection, or software supply chain security
  • Programming or scripting in Python, Go, and Bash
  • Ability to write, review, and troubleshoot code
  • Knowledge of secure software development, vulnerabilities, dependency risks, and remediation
  • Experience with SLSA, SBOMs, provenance, signing or verification
  • Experience creating or tuning rules for static analysis, secrets detection, or policy-as-code
  • Familiarity with AI/LLM development tools security
  • Experience with cloud-native technologies: GCP, Kubernetes, Terraform
  • Familiarity with Java and JavaScript
  • Telemetry and metrics to improve security tooling
  • Ability to work independently and collaborate with teams
  • Clear written and verbal communication of technical findings and tradeoffs

Responsibilities

  • Design, build, and operate automated security scanners and guardrails across the software development lifecycle
  • Identify and reduce risk across source code, open source dependencies, secrets, software supply chains, AI/LLM tools, edge/CDN environments, and developer workflows
  • Apply security best practices to enhance and optimize systems
  • Partner with engineering, platform, and security teams on security initiatives and cross-functional projects
  • Analyze and resolve complex security challenges using standard and alternative approaches
  • Build and operate scanning and guardrail capabilities across source control, CI/CD, package ecosystems, and developer platforms
  • Tune SAST, SCA, and supply chain controls; investigate gaps and false positives; improve remediation guidance
  • Write and review code, APIs, detection rules, and automation that enforce security policy
  • Troubleshoot integrations with developers, platform engineers, and security teams
  • Evaluate AI/LLM tools and help define appropriate security controls
  • Use metrics and feedback to improve reliability, coverage, performance, adoption, and remediation outcomes

Skills

Security automation in CI/CD
SAST and SCA experience
Python
Go
Bash
AI/LLM tools awareness
Cloud-native technologies
Java/JavaScript familiarity
Telemetry & metrics
Independent work

Education

Bachelor’s degree or equivalent

Tools

GCP
Kubernetes
Terraform
CI/CD tools
SBOMs / provenance

Job description

  • Design, build, and operate automated security scanners and developer guardrails across the software development lifecycle
  • Identify and reduce risk across source code, open source dependencies, secrets, software supply chains, AI/LLM tools, edge/CDN environments, and developer workflows
  • Apply security best practices to enhance and optimize systems
  • Partner with engineering, platform, and security teams on security initiatives and cross-functional projects
  • Analyze and resolve complex security challenges using standard and alternative approaches
  • Build and operate scanning and guardrail capabilities across source control, CI/CD, package ecosystems, and developer platforms
  • Tune SAST, SCA, and supply chain controls; investigate gaps and false positives; improve remediation guidance
  • Write and review code, APIs, detection rules, and automation that process findings and enforce security policy
  • Troubleshoot integrations with developers, platform engineers, and security teams
  • Evaluate AI/LLM tools and help define appropriate security controls
  • Use metrics and feedback to improve reliability, coverage, performance, adoption, and remediation outcomes
Requirements
  • 3+ years relevant experience and a Bachelor’s degree OR any equivalent combination of education and experience
  • 3–5 minimum years of relevant experience in software engineering, application or product security, DevSecOps, or cybersecurity
  • Experience developing, integrating, or operating security automation in CI/CD or developer workflows
  • Experience with one or more of SAST, SCA, secrets detection, or software supply chain security
  • Programming or scripting experience in multiple languages such as Python, Go, and Bash
  • Ability to write, review, and troubleshoot code
  • Working knowledge of secure software development, common application vulnerabilities, dependency and package ecosystem risks, and practical remediation approaches
  • Experience with SLSA, SBOMs, provenance, artifact signing or verification, package repositories, or dependency governance
  • Experience creating or tuning rules for static analysis, secrets detection, or policy-as-code systems
  • Familiarity with security considerations for AI/LLM development tools, AI-assisted coding, or model and tool supply chains
  • Experience with GCP, Kubernetes, Terraform, and other cloud-native technologies
  • Familiarity with Java and JavaScript and ability to troubleshoot code
  • Experience using telemetry and metrics to improve security tooling at scale
  • Ability to work independently and collaborate with software, platform, and security teams
  • Clear written and verbal communication of technical findings and tradeoffs
Core Competencies

Demonstrates expertise in security automation, risk reduction, and secure software development practices, with a strong focus on integrating security into CI/CD workflows and developer environments. Proficient in programming and scripting, with the ability to analyze and resolve complex security challenges while collaborating effectively with cross-functional teams.

Highest-signal resume keywords
  • Security Automation in CI/CD
  • SAST and SCA Experience
  • Programming in Python, Go, and Bash
  • Cloud-Native Technologies: GCP, Kubernetes, Terraform
  • Secure Software Development Practices
Hard Skills
  • Security Automation
  • SAST
  • SCA
  • Secrets Detection
  • Software Supply Chain Security
  • Programming in Python
  • Programming in Go
  • Programming in Bash
  • Static Analysis Rules Tuning
  • Telemetry and Metrics Analysis
Soft Skills
  • Clear Communication
  • Collaboration
  • Independent Work
Industry Keywords
  • DevSecOps
  • Application Security
  • Cybersecurity
  • Dependency Governance
  • SBOMs
Tools & Technologies
  • GCP
  • Kubernetes
  • Terraform
  • AI/LLM Tools
  • CI/CD Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal, Product Security
Principal, Product Security

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • United States

On-site
USD 150,000 - 190,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • United States

On-site
USD 150,000 - 190,000
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Manager – Product Cybersecurity
Senior Manager – Product Cybersecurity

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 230,000
Senior Staff Product Security Engineer – AI
Senior Staff Product Security Engineer – AI

Jobtailor • Illinois

On-site
USD 140,000 - 220,000
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Security Software Engineer – Security Operations
Senior Security Software Engineer – Security Operations

Jobtailor • Missouri

On-site
USD 140,000 - 190,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000