Senior Product Security Engineer

Tessera Labs

United States

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Tessera Labs is seeking a Senior Product Security Engineer to collaborate with developers and secure the product across its lifecycle. You will conduct design reviews, threat modeling, and hands-on testing to make the platform defensible while enabling engineers to ship securely.

You will lead security reviews, embed security into the SDLC, and contribute to SOC 2/ISO 27001 posture, with a strong emphasis on clear, actionable findings.

Qualifications

  • Proven track record securing products or applications.
  • Hands-on penetration testing experience against web apps and APIs.
  • Deep understanding of modern web apps, OAuth2/OpenID Connect, sessions, and OWASP Top 10.
  • Experience running security design reviews and threat modeling.
  • Solid understanding of the SDLC and embedding security into it.
  • Strong communication skills to explain risk to engineers.

Responsibilities

  • Partner with developers to secure the product across the SDLC, embedding security early.
  • Lead security design and architecture reviews, and run threat modeling on new features.
  • Perform hands-on penetration testing of web applications and APIs, translating findings into prioritized fixes.
  • Conduct secure code reviews and help define secure-coding standards and acceptance criteria.
  • Operate and tune SAST/DAST and dependency/supply-chain scanning and triage results.
  • Help engineers understand the rationale behind findings to prevent recurrence.

Skills

Penetration testing
Web app security
Threat modeling
Security design reviews
SDLC security
Communication skills
SAST/DAST tooling
OWASP Top 10

Tools

OWASP ZAP
Burp Suite
Semgrep
Trivy
Nuclei
Grype

Job description

Senior Product Security Engineer

Remote in Brazil or LATAM

The Role

We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands‑on penetration testing, and secure‑coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.

This role partners closely with product engineering and platform engineering teams.

What You'll Do
  • Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.

  • Lead security design and architecture reviews, and run threat modeling on new features and services.

  • Perform hands‑on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.

  • Conduct secure code reviews and help define secure‑coding standards and security acceptance criteria.

  • Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply‑chain scanning, and triage what they surface.

  • Help engineers understand the "why" behind findings so the same class of issue doesn't recur.

  • Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).

What You'll Need (Required)
  • A strong track record in product or application security — you've measurably made real products more secure.

  • Hands‑on penetration testing experience against web applications and APIs.

  • Deep understanding of how modern web applications work — single‑page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).

  • Experience running security design reviews and threat modeling.

  • Solid understanding of the SDLC and how to embed security into it.

  • Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.

Nice to Have
  • Familiarity with open‑source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).

  • A relevant offensive‑security certification (for example, Offensive Security Certified Professional, or OSCP).

  • Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.

  • Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.

  • Background in enterprise or regulated environments where deployment security is non‑negotiable.

What Success Looks Like (First 90 Days)
  • You've reviewed the product’s architecture and threat surface and identified the highest‑priority security risks.

  • A repeatable, lightweight process exists for security design reviews on new work.

  • Security findings have a clear triage‑to‑remediation path, and developers know how to engage you early.

Location and Work Model

Remote in Brazil or LATAM

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer (remote in Brazil)
Product Security Engineer (remote in Brazil)

knowbe4 • United States

Remote
USD 120,000 - 150,000
Company-wide bonuses tied to monthly销售
Employee referral bonuses
Adoption assistance
+3
Product Security Engineer
Product Security Engineer

GoMining • Georgia

On-site
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

On-site
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

Modernhealth • United States

Remote
USD 101,000 - 140,000
health and insurance coverage
flexible time off
family-support programs
+4
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

On-site
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7
Product Security Engineer
Product Security Engineer

Stellar IT Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 200,000
Remote Senior Product Security Engineer (Security-by-Design)
Remote Senior Product Security Engineer (Security-by-Design)

payabl. • United States

Remote
USD 127,000 - 173,000
Learning budget for professional dev
Company celebrations
Global collaboration events
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Product Security Engineer Remote - US
Product Security Engineer Remote - US

Secure State.IQ • United States

Remote
USD 120,000 - 180,000