Senior Product Security Engineer

Gofractional

Northern (KY)

Hybrid

USD 83,000 - 165,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
401K
Paid parental leave
Equity
Wellness Week
Career growth
Paid Family Leave
PTO 20 days

Job summary

Gofractional is seeking a Senior Product Security Engineer to identify security risks early, partner with development teams, and drive secure-by-design practices across the SDLC.

You will perform threat modeling, security testing, code reviews, and vulnerability management for web, API, AI-enabled services, and cloud-native apps, collaborating with cross-functional teams across Engineering, Cloud Security, Infrastructure, Compliance, and Product Management.

Qualifications

  • 5+ years in Product Security or Application Security.
  • Strong understanding of modern application architectures.
  • Experience securing Web apps, APIs, microservices and cloud-native apps.
  • Experience performing threat modeling.
  • Experience conducting penetration testing.
  • Solid knowledge of OWASP Top 10 and OAuth/OIDC.
  • Experience with SAST, DAST, SCA and container security.
  • Ability to work directly with engineering teams and communicate clearly.

Responsibilities

  • Perform security design and architecture reviews for new products and features.
  • Conduct threat modeling for applications, APIs, and AI-enabled services.
  • Review application security posture throughout the SDLC.
  • Partner with engineering teams to prioritize and remediate vulnerabilities.
  • Review authentication, authorization, and access control implementations.
  • Perform manual web, API, thick-client, and mobile app penetration testing.
  • Validate findings from third-party penetration tests.
  • Develop reusable security patterns and reference architectures.

Skills

Threat modeling
Penetration testing
Secure SDLC
Security testing
Cloud security
Software security
Cross-functional collaboration
Communication

Tools

Snyk
Burp Suite Pro
Semgrep
Wiz
GitHub Advanced Security

Job description

Senior Product Security Engineer (Contract)

Position Details

  • Location: USA Remote
  • Type: Full-Time Contract
  • Duration: 6 months (40 hours/week)
  • Department: G&A – Security and Trust
The Opportunity

Hands-on engineering role responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure-by-design products. This role will work closely with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to ensure security is integrated throughout the SDLC while enabling developer velocity.

What You'll Do
Application Security
  • Perform security design and architecture reviews for new products and features.
  • Conduct threat modeling for applications, APIs, and AI-enabled services.
  • Review application security posture throughout the SDLC.
  • Partner with engineering teams to prioritize and remediate vulnerabilities.
  • Review authentication, authorization, and access control implementations.
Security Testing
  • Perform manual web, API, thick-client, and mobile application penetration testing.
  • Validate findings from third-party penetration tests.
  • Conduct secure code reviews.
  • Verify remediation of security vulnerabilities.
Secure Development
  • Drive adoption of secure coding practices.
  • Partner with developers to improve security throughout the SDLC.
  • Help define Product Security standards and engineering guardrails.
  • Develop reusable security patterns and reference architectures.
Vulnerability Management
  • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
  • Work with engineering teams to prioritize remediation.
  • Track remediation SLAs and security metrics.
AI Security
  • Assess AI-enabled products for security risks.
  • Review LLM integrations and AI workflows.
  • Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Help define secure AI engineering standards.
Security Automation
  • Improve automation of security testing throughout CI/CD.
  • Integrate security tooling into developer workflows.
  • Build scripts and tooling that reduce manual security work.
Cross-functional Partnership
  • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
  • Support customer security questionnaires related to product security.
  • Assist Sales Engineering with security discussions when needed.
Qualifications
  • 5+ years in Product Security or Application Security.
  • Strong understanding of modern application architectures.
  • Experience securing:
    • Web applications
    • APIs
    • Microservices
    • Cloud-native applications
  • Experience performing threat modeling.
  • Experience conducting penetration testing.
  • Strong understanding of:
    • OWASP Top 10
    • OWASP API Top 10
    • Authentication & Authorization
    • OAuth / OIDC
    • Secure SDLC
  • Experience with SAST, DAST, SCA, and container security.
  • Experience partnering directly with engineering teams.
  • Strong written and verbal communication skills.
Preferred
  • Experience securing AI/LLM applications.
  • Experience with Kubernetes and containers.
  • Familiarity with cloud security (AWS, Azure, or GCP).
  • Experience with GitHub Actions or CI/CD security.
  • Experience using:
    • Snyk
    • Burp Suite Pro
    • Semgrep
    • Wiz
    • GitHub Advanced Security
  • Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus
Benefits & Perks
  • Competitive salary
  • 100% individual and dependent medical + dental + vision coverage
  • 401(K) with 4% company match
  • 20 days PTO
  • Iru Wellness Week the first week in July
  • Equity for full-time employees
  • Up to 16 weeks of paid leave for new parents
  • Paid Family and Medical Leave
  • Exciting opportunities for career growth
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Product Security Engineer (Contract)
Senior Product Security Engineer (Contract)

Iru, Inc. • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Boston (MA)

On-site
USD 140,000 - 200,000
Professional growth
Competitive USD-based compensation
Flextime
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Houston (TX)

On-site
USD 140,000 - 180,000
Professional growth
Competitive compensation
Exciting projects
+1