Advanced Product Security Engineer
$122,800–$184,200 year
HybridHoltsville, New York, United States
Job Summary
Conduct threat modeling and design reviews to embed secure-by-design principles into firmware and software for thermal printers and barcode scanners. Develop and enforce security controls throughout the SSDLC, manage security tools like SAST and DAST within CI/CD pipelines, and lead the remediation of vulnerabilities and security incidents. Collaborate with hardware, firmware, and engineering teams to integrate security requirements without compromising functionality, while serving as the primary contact for customer security questionnaires and audits. Create security architecture documentation, deliver training to development teams, and mentor junior engineers to foster a culture of security awareness.
Required Qualifications
- Bachelor's degree
- 8+ years of experience
- Hands-on experience in product security, embedded systems security, or a closely related field
- Location- ***Role is required to be onsite in the Holtsville, NY office. (Hybrid- Minimum of 3 days in the office per week)
- Collaborate with stakeholders, including product management and engineering, to define and prioritize security requirements for new and existing products
- Participate in design and architecture reviews with the engineering teams to conduct threat modeling and ensure security is built into software and firmware from the ground up
- Develop, implement, and enforce security controls and best practices throughout the secure software development lifecycle (SSDLC)
- Collaborate closely with hardware, firmware, software, and systems engineering teams to ensure security requirements are seamlessly integrated without compromising product functionality or time-to-market
- Respond to, investigate, and lead the remediation of product security vulnerabilities and participate if an incident happens
- Oversee security assessments, including penetration testing and code reviews, to proactively identify and mitigate security flaws
- Serve as the primary technical contact for responding to customer security questionnaires, audits, and inquiries, clearly communicating our security posture
- Align with the corporate security teams to implement and adapt corporate security policies, standards, and best practices within product development
- Create and maintain detailed documentation for security architecture, and security best practices
- Develop and deliver security training to development teams to foster a culture of security awareness and accountability
- Stay current with the latest security threats, vulnerabilities, and mitigation techniques relevant to IoT, embedded systems, software, and firmware
- Mentor junior engineers and act as a security champion and subject matter expert within the engineering organization
- Evaluate, implement, and manage security tools (e.g., SAST, DAST, SCA) to automate security testing within the CI/CD pipeline
Desired Qualifications
- Proven experience in product security for embedded systems, consumer electronics, or IoT devices
- Full stack software security, Information Security, DevSecOps Certifications, Cloud Security, CISSP certification
- Proficiency in one or more programming languages such as C, C++, Python, or Java. (Not necessary but desirable)
- Deep technical expertise in Hardware Security (e.g., TPM, TrustZone, secure boot, tamper resistance, cryptography)
- Vulnerability management tool experience
- Security standards compliance and regulations
- Cloud security experience
- Penetration testing experience
- Experience in SAMM or BSIMM
- Cryptographic standards understanding/knowledge
- Incident response experience
- Disaster Recovery Planning and implementation experience
- Effective verbal and written communication skills
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.