CENSUS logo
CENSUSPosted 10 months ago

Senior Product Security Consultant - 100% Remote

Remote

ContractSenior LevelMasters DegreeSmall

Job Summary

Evaluate the security posture of software and system products by validating architecture, threat models, and security controls against industry standards like Common Criteria and ISO/IEC 27002. Review and validate security documentation including trust boundaries and asset inventories, while assessing the completeness and risk coverage of frameworks such as STRIDE, LINDDUN, and OWASP. Conduct architectural and implementation-level reviews of security controls, perform targeted white-box and black-box testing on APIs, mobile apps, and cloud infrastructure, and verify cryptographic controls and secure communication protocols. Deliver comprehensive, standards-aligned technical reports and communicate product security risks clearly to both technical and non-technical audiences.

Required Qualifications

  • MSc or BSc in Computer Science, Electrical/Software Engineering, Cybersecurity, or a related technical discipline
  • 3+ years of experience in product security, software evaluation, or penetration testing
  • Proven ability to evaluate threat models, security requirements, and mitigation effectiveness
  • Strong technical writing and documentation skills in English
  • Excellent analytical skills and attention to detail
  • In-depth understanding of security architecture and common system design patterns (e.g., API gateways, microservices, message queues, service meshes)
  • Hands-on experience performing design-level security reviews and verifying implementation alignment with defined threat models
  • Familiarity with structured security frameworks such as Common Criteria, FIPS 140, ISO 15408, OWASP ASVS, and MASVS
  • Practical experience with security testing in diverse product environments (mobile, embedded, web/cloud, API)
  • Knowledge of authentication, authorization, identity, and secrets management technologies (e.g., OAuth2, MFA, PKI, SSO, Cloud IAM, HashiCorp Vault)
  • Proficiency in applied cryptography (e.g., mTLS, E2EE, AEAD, key derivation, key wrapping, remote attestation)
  • Ability to identify security vulnerabilities across platforms (e.g., OWASP Top 10, misconfigurations, transport security gaps)
  • Excellent documentation and communication skills, able to articulate technical risks and findings to diverse audiences
  • Problem solving skills, analytical thinking, and willingness to learn/grow

Desired Qualifications

  • Ability to read and analyze source code for logic flaws in one or more language families: Mobile: Swift, Obj-C, Kotlin, Java, Dart, JavaScript
  • Experience debugging or instrumenting applications across edge, embedded, or cloud platforms
  • Familiarity with Zero Trust architectures, enclaves, and confidential computing technologies
  • Exposure to fuzzing, symbolic execution, or static analysis techniques
  • Experience collaborating with distributed teams across different time zones and cultures

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce