Senior Security Engineer - Product Security

TaxSlayer

Georgia

Hybrid

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Work Options
Generous Time Off
Health & Wellness Coverage
Education assistance
Company paid parking
Unlimited coffee

Job summary

TaxSlayer is seeking a Senior Security Engineer focused on product security. You will partner with software teams to embed security throughout the SDLC, perform threat modeling and security testing, and lead incident response initiatives.

The role emphasizes hands-on security reviews, bug bounty coordination, and ongoing risk management. The position offers a hybrid/remote arrangement with potential for fully remote for eligible states.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
  • Minimum 5 years of experience in application security/product security/security engineering
  • Experience partnering with software development teams to integrate security into the lifecycle
  • Experience identifying and validating vulnerabilities in web apps, APIs, and cloud environments

Responsibilities

  • Serve as the primary security point of contact for assigned development teams during sprint planning and design reviews
  • Review product features, designs, APIs, authentication mechanisms, and third-party integrations to identify and mitigate security risks
  • Partner with engineering teams to embed security controls early in the SDLC and promote secure coding practices
  • Conduct secure code reviews, threat modeling, architectural risk assessments, and security testing for apps and releases
  • Perform hands-on penetration testing and coordinate third-party testing as appropriate
  • Manage and optimize SAST, DAST, and CI/CD security tooling and processes
  • Track vulnerabilities through remediation and collaborate with engineering teams to address findings
  • Oversee bug bounty program administration, researcher engagement, submission triage, validation, and remediation coordination
  • Monitor bug bounty metrics and recommend process improvements
  • Support governance, risk and compliance activities including audits (PCI DSS, SOC 2, IRS security requirements)
  • Contribute to enterprise risk management and maintain product security risk documentation
  • Assist with security incident response activities including investigation, root cause analysis, remediation tracking
  • Mentor engineering teams on secure coding, threat modeling, and product security best practices
  • Other duties as assigned

Skills

Secure SDLC
Threat modeling STRIDE
Threat modeling PASTA
OWASP Top 10
CWESANS Top 25
SAST
DAST
Penetration testing
CI/CD security tooling
Cloud security

Education

Bachelor's degree in Cybersecurity/CS/IT

Tools

SAST tooling
DAST tooling
Cloud security tools
Threat modeling tools

Job description

Work Location & Schedule

Senior Security Engineer Product Security Augusta Ga


This is a hybrid position based in our Augusta GA office Team members are expected to work on site two days per week in our Augusta office and remotely three days per week This schedule supports collaboration while offering flexibility and work life balance For the right candidate this position may also be considered as a fully remote opportunity for individuals residing in Georgia South Carolina North Carolina Florida or Tennessee only


Who we are

At TaxSlayer were more than just a tax software development company; were empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease


As a leading innovator in tax prep software TaxSlayer LLC has been revolutionizing the way people file their taxes since 1965


Our user friendly platform offers an intuitive interface that guides customers through the tax filing process step by step ensuring accuracy and maximum refunds


TaxSlayer is headquartered in Augusta GA with a satellite office in Charlotte NC


TaxSlayer proudly employs nearly 200 individuals year round plus 300 additional in season support agents


Our employees are among the brightest most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season


About the Role

The Senior Security Engineer Product Security serves as the primary security partner to software development teams helping ensure security is embedded throughout the software development lifecycle


Core Responsibilities


  • Serve as the primary security point of contact for assigned Development teams participating in sprint planning architecture discussions and design reviews

  • Review product features system designs APIs authentication mechanisms and third party integrations to identify and mitigate security risks

  • Partner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practices

  • Conduct secure code reviews threat modeling activities architecture risk assessments and security testing for applications and product releases

  • Perform hands on penetration testing and coordinate third party testing efforts when appropriate

  • Manage and optimize SAST DAST and CICD security tooling and processes

  • Track identified vulnerabilities through remediation and collaborate with engineering teams to address findings

  • Own day to day administration of the companys bug bounty program including researcher engagement submission triage validation and remediation coordination

  • Monitor and report bug bounty program performance metrics and recommend process improvements

  • Support governance risk and compliance initiatives including audits and assessments related to PCI DSS SOC 2 IRS security requirements and other applicable regulations

  • Contribute to enterprise risk management activities and maintain product level security risk documentation

  • Assist with security incident response activities including investigation root cause analysis and remediation tracking

  • Mentor engineering teams on secure coding practices threat modeling and product security best practices

  • Other duties as assigned


How your Success is measured


  • Reduction in application and product security vulnerabilities identified in production environments

  • Timely completion of security reviews threat models and vulnerability remediation activities

  • Effective integration of security controls within the software development lifecycle

  • Successful management and continuous improvement of the bug bounty program including response and remediation timelines

  • Positive audit and compliance assessment outcomes related to product security controls

  • Increased adoption of secure coding practices and security standards across development teams

  • Clear communication of technical risks and effective collaboration with engineering and business stakeholders


Education & Experience

Bachelors degree in Cybersecurity Computer Science Information Technology or a related field or equivalent combination of education and experience


Minimum of 5 years of experience in application security product security security engineering or a related field


Experience partnering closely with software development teams to integrate security into the development lifecycle


Experience identifying and validating vulnerabilities in web applications APIs and cloud based environments


Skills & Competencies

Strong knowledge of secure software development lifecycle SDLC practices


Experience with threat modeling methodologies such as STRIDE PASTA or similar frameworks


Knowledge of common vulnerability frameworks including OWASP Top 10 and CWESANS Top 25


Experience with SAST DAST penetration testing code review and CICD security tools


Strong understanding of web application API and cloud security principles


Ability to assess and communicate technical security risks to technical and non technical audiences


Strong problem solving collaboration and relationship building skills


Ability to balance security requirements with business objectives and product delivery schedules


Preferred certifications include OSCP OSWE GWAPT CSSLP or comparable credentialsExperience with bug bounty or vulnerability disclosure programs is strongly preferred

Physical & Work Environment Requirements

This is a hybrid or remote roleWork is performed in a standard office environment with minimal physical demandsMust be able to work at a computer for extended periodsOccasional travel may be required for meetings training or business needs


What We Offer

At TaxSlayer we know that our greatest strength lies in the talented individuals who drive our innovation and success Thats why were proud to offer a competitive comprehensive and flexible benefits package designed to support your well being growth and work life balance



  • Flexible Work Options

  • Generous Time Off

  • Health & Wellness Coverage

  • Financial Benefits

  • Additional Perks

  • Education assistance to support your professional development

  • Company paid parking company store and unlimited free coffee


Legal Disclaimers

TaxSlayer is an equal opportunity employer and complies with all applicable laws regarding discrimination Employment is based on qualifications merit and business need This job description is not intended to be all inclusive and may be subject to change to meet business needs


Please note As a federal contractor we are responsible to ensure our employees meet any obligations set forth by the US government We will inform you of any applicable requirements as they arise

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • Augusta (GA)

On-site
USD 120,000 - 160,000
Flexible Work Options
Generous Time Off
Health & Wellness Coverage
+2
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • Town of Florida (NY)

On-site
USD 140,000 - 180,000
Flexible Work Options
Generous Time Off
Health & Wellness Coverage
+6
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • Virginia (MN)

Hybrid
USD 110,000 - 150,000
Flexible Work Options
401k match
Health Insurance
+3
Senior Security Engineer
Senior Security Engineer

RHODES FINANCIAL SERVICES LLC • Augusta (GA)

Hybrid
USD 120,000 - 170,000
401(k) with 150% match on up to 3%
Health, dental, vision insurance
Flexible work options
+1
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • Tennessee

Hybrid
USD 120,000 - 170,000
Flexible Work Options
Remote and Hybrid opportunities
PTO and holidays
+1
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • North Augusta (GA)

On-site
USD 140,000 - 180,000
Remote options
Hybrid work
PTO
+8
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • North Carolina

Hybrid
USD 120,000 - 150,000
Flexible work options
Wellness program
401(k) with match
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

TaxSlayer • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Flexible Work Options
Remote and Hybrid Work
PTO and holidays
+6
Software Developer
Software Developer

TaxSlayer, LLC • Augusta (GA)

Hybrid
USD 85,000 - 115,000
Remote and hybrid work options
Competitive benefits package
Education assistance
+2
Software Developer
Software Developer

TaxSlayer • Lexington (SC)

Hybrid
USD 100,000 - 130,000
Health insurance
Wellness program
401(k) with match
+4