Staff Product Security Engineer
$174,200–$293,702 year
RemoteUnited States
Job Summary
Partner with Engineering teams throughout the software development lifecycle to identify and mitigate security risks, implement secure deployment practices, and define secure coding standards. Support threat modeling activities, coordinate internal and external application and penetration testing initiatives, and validate vulnerability findings to prioritize remediation. Perform root cause analysis, collaborate on security monitoring and detection capabilities, and oversee remediation for security researcher disclosures via the bug bounty program. Develop security training, guidance, and technical documentation while acting as a consultant on security-related matters across the organization. This role focuses on shaping the future through process and technology optimization within a shared security model that shifts checks to the earliest phases of the secure software development lifecycle. The candidate will leverage AI-powered tools to enhance security engineering productivity and contribute to maturing existing security activities.
Required Qualifications
- 5-7 years of experience in product security, application security, software engineering, or a related field
- Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners
- Experience with CI/CD security controls and DevSecOps practices
- Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby
- Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts
- Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows
- Deep expertise in threat modeling, secure architecture design, and vulnerability management
- Experience influencing engineering organizations and driving security initiatives across multiple teams
- Knowledge of artificial intelligence software security frameworks, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework
Desired Qualifications
- Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues
- Have a continuous learning mindset and passion for security
- Have strong analytical and problem-solving skills
- Be flexible, with the ability to balance security vs the needs of the business
- Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation
- Be able to translate technical risks into business impact
- Be collaborative and able to foster relationships with teams we partner with
- They'll already be comfortable with the 4 I's at SailPoint (individual, Impact, Innovation, and Integrity)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.