Sr. Product Security Engineer

hace 1 semana


Madrid, Madrid, España Incode Technologies A tiempo completo

The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program.

The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as our customers expect.

We're looking for someone who loves to solve significant challenges in Product Security.

These challenges include ensuring a secure software supply chain from idea to operation, providing software provenance, automating everything in CI/CD, and building and breaking software to make it more secure.

To be successful as a Product Security Engineer, you should have hands-on experience securing the software supply chain and products of a SaaS and mobile-first company, enjoy partnering with fellow engineers, and be able to speak to the big picture of the SDLC and how to achieve a desired state in reasonable chunks.

As an engineer, you should lead with a hacker mindset and be able to roll up your sleeves and design, architect, and threat model security critical solutions.

Reporting to the Sr.

Director of Information Security, you will be an early hire to the security team and will have the opportunity to influence and evolve our product security program.

Responsibilities Partner with engineering and product management teams to perform threat modeling, architecture & design, and code reviews. Assess security implications, requirements for the secure development of new systems, features, and technologies.

Provide hands-on remediation guidance to development teams and design security architecture, features and controls that keeps our customers' data safe and preserves their privacy.

Build a security paved road through automation and tooling (SAST, SCA, MAST, IaC, DAST, Fuzzing, etc.) into the SDLC and CI/CD integrations that enables our developers to easily produce secure software.

Define, architect, build, improve and validate secure software supply chain and build provenance mechanisms.
Manage, triage, and provide support to external researchers in our vulnerability disclosure and bug bounty programs.
Provide proof of concept exploits, facilitate vulnerability remediation, and drive adherence to software security standards through policy as code.
You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.

Qualifications:

Deep expertise in at least one domain: web application and browser security, mobile application security, applied cryptography, machine learning and artificial intelligence security, offensive security, cloud security, hardware security.

Experience in software engineering, infrastructure engineering, site reliability engineering, or offensive security for a SaaS product company.

Experience with a variety of security tooling, to include:
SAST, DAST, SCA, IaC Scanning, Image and Container Scanning, MAST, IAST, and offensive security and proxy tooling.

Deep expertise with common application security flaws, security controls, and common security libraries and identifying security issues through code review, threat modeling, penetration testing, and other techniques manually and with tools.

You are a strong communicator who is comfortable working cross-functionally, with a track record of delivering results and demonstrating strong ownership.

Extensive experience in SaaS product development and security space; securing complex interconnected web and mobile applications and their architectures using Python, Javascript, Swift, Java, C++, Kotlin, or any other modern language.

You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.


Preferred Experience and Certification:

Have SaaS Startup experience in security-focused industries, such as fintech, security software and services, healthtech, and identity and access management.

Experience with virtualization, containerization technology, orchestration, and cloud native security.
Certifications in Security, Product Securityand/or Offensive Security (eg. OSCP, OSWP, OSEP, OSWA, OSED, OSMR, OSWE, OSEE, GPEN, GWAPT, CEH, etc).Cloud Certifications, such as AWS Certified Solutions Architect, AWS Security SpecialtyHands-on experience in offensive security, and CVEs to prove it.
#J-18808-Ljbffr

  • Madrid, Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and...

  • Mid/Sr Security Engineer

    hace 1 semana


    Madrid, Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...


  • Madrid, Madrid, España Okta A tiempo completo

    Get to know OktaOkta is The World's Identity Company. We free everyone to safely use any technology-anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Celonis A tiempo completo

    We're Celonis, the global leader in Process Mining technology and one of the world's fastest-growing SaaS firms. We believe there is a massive opportunity to unlock productivity by placing data and intelligence at the core of business processes - and for that, we need you to join us.We're Celonis, the global leading Process Mining software company and one of...

  • Cyber Security Architect

    hace 1 semana


    Madrid, Madrid, España SR Technics Holding A tiempo completo

    We are a world leading Engine MRO service provider, headquartered in Zurich, Switzerland, with over 90 years of operational experience. Our unwavering dedication to innovation, excellence and environmental responsibility propels us forward on our journey to becoming the leading, most customer-centric, and sustainable Engine focused MRO worldwide.Working with...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Oracle A tiempo completo

    New opportunity for recent University graduates!Are you on your way to completing your Bachelor's or Master's degree this year and ready to jumpstart your career in a small and dynamic team?Join our product security team at Oracle and be part of building a secure ecosystem for our cloud services.As an Application Security Engineer, you will play a key role...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Swiss Re - Schweizerische Rückversicherungs-Gesellschaft A tiempo completo

    Join a team of cybersecurity professionals and contribute to Swiss Re's mission of increasing global resilience. As a Security Engineer, you will be in charge of implementing cutting-edge enhancements for our security tools, including malware protection and email sandboxing, maintaining a hybrid work model where you can work both remotely and in the...

  • Sr Data Engineer

    hace 1 semana


    Madrid, Madrid, España Jr Spain A tiempo completo

    col-wideJob Description:SR Data Engineer SGT&O Madrid or CantabriaCountry: SpainWHAT YOU WILL BE DOING*SGTO is looking for a SR DATA ENGINEER based in our MADRID or CANTABRIA offices.As a SR Data Engineer , you will be integrated into the CoE where your mission will be to develop data management pipelines and components aligned with CTO policies and act as a...

  • Sr Data Engineer

    hace 1 semana


    Madrid, Madrid, España Jr Spain A tiempo completo

    col-wideJob Description:SR Data Engineer SGTO Madrid or CantabriaCountry: SpainWHAT YOU WILL BE DOING*SGTO is looking for a SR DATA ENGINEER based in our MADRID or CANTABRIA offices.As a SR Data Engineer , you will be integrated into the CoE where your mission will be to develop data management pipelines and components aligned with CTO policies and act as a...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Ebury A tiempo completo

    Full-Stack Security Engineer Work Pattern: 4 days in the office, 1 day from homeAbout the role Ebury is investing in the expansion of its security engineering team to help with security feature implementations across our entire product portfolio. In this role you will be able to work closely with application, platform, and product teams to embed security...

  • Cyber Security Architect

    hace 1 semana


    Madrid, Madrid, España SR Technics A tiempo completo

    Do you want to make aviation more secure? Do you want to work with advanced aviation industry solutions?You will work with Security team, IT architects, solution engineers to develop new infrastructure and our digital core, in more secure environment.As a single point of contact for operational security, you will have opportunity to design new secure...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Ebury A tiempo completo

    Ebury is a rapidly growing FinTech company, recognized as one of the top FinTechs to work for by Glassdoor and AltFi. We provide a variety of services including FX risk management, trade finance, currency accounts, international payments, and API integration.Full-stack Security Engineer4 days in the office - Ebury MadridAbout the roleEbury is expanding its...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Ebury A tiempo completo

    Full-Stack Security EngineerWork Pattern: 4 days in the office, 1 day from homeAbout the roleEbury is investing in the expansion of its security engineering team to help with security feature implementations across our entire product portfolio. In this role you will be able to work closely with application, platform, and product teams to embed security best...


  • Madrid, Madrid, España Swiss Re - Schweizerische Rückversicherungs-Gesellschaft A tiempo completo

    Detection Security Engineer (Hybrid setup) Join a group of cybersecurity experts and assist Swiss Re in achieving its goal of increasing the world's resilience. As the Detection Security Engineer, your main responsibility will be to help close security vulnerabilities by collaborating with incident responders and proactively searching for complex cyber...


  • Madrid, Madrid, España Marks Sattin A tiempo completo

    Are you an experienced Full-stack Security Engineer looking for your next adventure?My client, a leading financial services company is looking to add an experienced Full stack Security Engineer to their growing teams in either London, Lisbon or Madrid As an experienced Full-stack Security Engineer, you must have at least 4-5 years of experience, working...

  • Cloud Security Engineer

    hace 1 semana


    Madrid, Madrid, España Semrush A tiempo completo

    Security Position: RemoteHey there! We're Semrush, a global IT company focused on developing a cutting-edge platform for digital marketers. Exciting opportunities await, so don't let this one slip by!Cloud Security Engineer Role:Contribute to the swift implementation of security controls and features in the cloud.Conduct technical security assessments and...

  • Security Engineer Remoto

    hace 1 semana


    Madrid, Madrid, España Dtagency A tiempo completo

    Desde DTA estamos seleccionando un perfil de SECURITY ENGINEER para I+D con al menos 2 años de experiencia.¿QUÉ NECESITAMOS?Licenciatura/grado en Ingeniería de Telecomunicación Informática o titulación técnica afín.Al menos 2 años acreditables de experiencia como Security Engineer. El nivel de experiencia determinará las funciones y condiciones...

  • Security Engineer

    hace 1 semana


    Madrid, Madrid, España Fortra, Llc A tiempo completo

    As a hands-on role, the Security Engineer is to collaborate with all parts of the organization globally, including IT, DevOps, and Development. The role is responsible for cybersecurity controls, and processes to identify, protect, detect, respond, and recover to protect the organization and its assets. A mix of Office 365, email security, endpoint security,...


  • Madrid, Madrid, España Digital Talent Agency A tiempo completo

    Security Engineer Remoto en 100% En remoto. Desde DTA estamos seleccionando un perfil de SECURITY ENGINEER para I+D con al menos 2 años de experiencia. ¿QUÉ NECESITAMOS? Licenciatura grado en Ingeniería de Telecomunicación Informát...< p>


  • Madrid, Madrid, España Digital Talent Agency A tiempo completo

    Security Engineer Remoto en 100% En remoto. Desde DTA estamos seleccionando un perfil de SECURITY ENGINEER para I+D con al menos 2 años de experiencia. ¿QUÉ NECESITAMOS? Licenciatura grado en Ingeniería de Telecomunicación Informát...< p>