← İşler

Product Security Engineer

Bütçe: $17.0 - $25.0 HOURLY / FULL_TIME ⭐ 0.00 (0) Poland

security-engineering, python, secure-sdlc

Preferred qualifications

  • Experience: Expert
Key Responsibilities: Security Engineering & Automation Automate Everything: Develop custom automation to manage security processes and implement "Secure-by-Design" processes in the CI/CD pipeline using Python. Container Security: Identify, design, and implement controls to safeguard our containerized production environments. Tooling Management: Deploy and manage product security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). Threat Modeling: Review technical designs for new features, leading threat models to prioritize risks and educate developer teams on secure coding practices. Customer Trust & Vulnerability Management Threat Assessment & Security Analysis: Conduct and automate end-to-end vulnerability, threat, and exploitability assessments for actionable fixes and mitigations in DataRobot products. Incident Response: Perform initial technical investigation for customer reports and security incidents, coordinating with Engineering and IT Security to validate and track fixes. Customer Engagement: Work directly with Sales & Support teams to resolve concerns regarding security exposure and architecture. Customer-Centric Communication: Balance business needs with security rigor. You must be able to stand firm on security policies while maintaining strong professional relationships through clear, diplomatic, and solutions-oriented communication. Knowledge, Skills, and Abilities: Technical Proficiency: Fluent in writing code using Python to build security automation. Must have a deep understanding of Linux containers (internals, security isolation). Experienced in Git-based collaboration and automating software delivery through CI/CD integration (Jenkins, Harness, or GitHub Actions). Familiarity with Kubernetes orchestration is strongly preferred. Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite. Ability to reproduce vulnerabilities in a lab environment to demonstrate impact. Strong ability to perform manual code reviews or AI assisted reviews in Python, Go, and Node.js, looking for flaws that automated tools might miss (e.g., broken access control or insecure business logic). Leveraged AI-driven automation to accelerate secure code development and scale security assessments across the SDLC. Independence: Ability to work independently on complex technical tasks with minimal supervision, while knowing when to escalate architectural decisions to Senior and Staff engineers. Strategic Mindset: Experience determining not just how to fix a bug, but why and how it happened and then automate how to prevent it systemically. Soft Skills: Strong communication skills for guiding teams and liaising with various stakeholders. Requisite Education and Experience: 3 to 5 years of experience working in Product Security or Application Security roles. Bachelor's in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience).
Upwork'te aç

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Giriş yap