Product Security Engineer
OttoMateAbout the Role
The Product Security Engineer will lead product security initiatives for a remote-first technology platform, partnering closely with developers to embed security throughout the software development lifecycle (SDLC). The role focuses on identifying and mitigating application security risks through penetration testing, threat modeling, security design reviews, secure code reviews, and security tooling while supporting secure and agile product delivery.
Responsibilities
- Partnering with developers to embed security practices throughout the SDLC without unnecessarily slowing development cycles.
- Performing hands-on penetration testing of web applications and APIs to identify and assess security vulnerabilities.
- Leading security design reviews and threat modeling for new features and product changes.
- Conducting secure code reviews and defining secure-coding standards and practices.
- Operating and tuning SAST, DAST, and software supply-chain scanning tools.
- Translating complex security findings into clear, actionable, and developer-friendly solutions while balancing security and compliance considerations with agile product delivery.
Requirements
- 3+ years of experience
- Demonstrate professional English proficiency.
- Have proven experience in product security or application security roles.
- Possess hands-on experience conducting penetration testing of web applications and APIs.
- Demonstrate a deep understanding of modern web application architectures, security threats, and attack methods.
- Have experience conducting security design reviews and threat modeling.
- Possess experience in at least one of the following industries: B2B Enterprise SaaS (ERP, CRM, or HRIS) or Cybersecurity Software (Endpoint or Network).
Nice to Have
- Understand compliance frameworks such as SOC 2 and ISO 27001 and their relationship to agile product delivery.