Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.
Senior Product Security Engineer
Location
United States
Posted
11 days ago
Salary
0
Seniority
Senior
Job Description
Senior Product Security Engineer
BeyondTrust
• Build and maintain the product security tooling pipeline integrated across the software development lifecycle. Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot), and Wiz CLI across repositories and CI/CD pipelines. Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development. • Design and operate automated product security review workflows with human-in-the-loop checkpoints. Use Claude and LLM platforms to automate initial review triage, risk classification, and recommendation generation, escalating to Security Architects or senior engineers for decisions that require judgment. The goal is every change gets appropriate security review coverage without manual review becoming the bottleneck. • Ensure security tooling integrates cleanly into engineering workflows: GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards. Reduce false positives, tune rulesets to the product's actual risk profile, and build feedback loops so findings improve over time. You own the engineering experience of security tooling. When a developer interacts with a security gate, it should be clear, fast, and useful. • Leverage Claude Code Security, Codex Security, and LLM platforms to build automation that scales security engineering. This includes automated code review triage, vulnerability pattern detection, fix suggestion generation, policy-as-code enforcement, and security review summarization. Contribute reusable prompts, skills, and plugins back to the Product Security team's shared library. • Support product incident response alongside the Product Security team. Help investigate security incidents affecting products, scope impact, coordinate with engineering on emergency fixes, and contribute to root cause analysis and post-incident improvements. • Work closely with Security Testers to ensure scanning and automated tooling feed validated findings into their workflow. Partner with Architects on translating secure design standards into enforceable pipeline policies. Coordinate with the TPM on tracking and reporting for tooling-generated findings. Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting.
Job Requirements
- 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines
- Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent)
- Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms
- Strong understanding of CI/CD pipeline architecture and how security controls integrate without disrupting developer velocity
- Experience building automation workflows: scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration
- Familiarity with container security scanning tools (Wiz CLI, Trivy, Snyk Container, or equivalent) and cloud security fundamentals (AWS preferred)
- You understand common vulnerability classes well enough to tune tooling, triage findings, and have credible conversations with engineers about severity and remediation
- Strong collaboration skills. You'll work across Security Testers, Architects, TPM, and engineering teams daily and need to communicate effectively with all of them
- Automation-first mindset. You default to building repeatable, scalable workflows and reach for manual processes only when automation genuinely falls short
- Experience with GitHub Advanced Security at scale: CodeQL custom queries, secret scanning custom patterns, and organization-wide rollout
- Background operating Wiz CLI or similar cloud/container security scanning integrated into CI/CD
- Experience supporting product incident response or security incident investigation
- Familiarity with policy-as-code frameworks (OPA/Rego, Kyverno, or similar)
- Background in securing endpoint technologies, identity systems, or enterprise security platforms
- Experience building developer enablement programs, security documentation, or self-service security tooling
- Cloud security experience across AWS, Azure, or Kubernetes environments.
Benefits
- Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
- We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer – Pre-sales
TenableCloud Security | Operational Technology | Identity Security | and more
• Deliver compelling technical presentations and live demonstrations of Tenable Enterprise products • Manage enterprise software trials and Proof of Concept evaluations, mapping unique business values with customer business objectives • Answer technical questions and provide consultative guidance on security best practices, compliance frameworks, and risk management • Apply advanced technical skills to demonstrate the value and impact of Tenable’s solutions in solving real-world customer challenges • Maintain and strengthen relationships with existing customers, while identifying and cultivating new strategic opportunities • Present thought leadership content and represent Tenable at industry events, executive briefings, and customer-facing sessions • Leverage strategic technical selling skills to engage key stakeholders, from engineers to CISOs, and influence decision-making • Travel as needed (typically around 25%) to support key customer engagements, critical sales opportunities, and high-impact cybersecurity events • Collaborate cross-functionally with product management and engineering to surface customer feedback and prioritize critical customer use cases • Help shape future innovations by identifying gaps and contributing ideas for new product features and capabilities • Deliver clear status reports for Proofs of Value (POVs) and active opportunities; this data is mission-critical for forecasting business health and ensuring alignment with territory and organizational growth goals • Meet with prospective clients to discover what their biggest security challenges and highest priority business drivers are
Physical Security Manager
SoFiSoFi helps you save, spend, earn, borrow, invest, and protect your money–all in one app. NMLS 1121636
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role: Responsible for the design, implementation, maintenance, and operational management of enterprise physical security systems and security technology infrastructure across corporate environments. Serve as a senior leader within the broader Corporate Security organization, responsible for leading day-to-day security technology operations, physical security initiatives, guard force management, and security infrastructure projects while supporting enterprise security strategy and operational resilience. This role combines hands-on technical expertise with operational leadership and strategic program management. The position oversees enterprise security technologies including access control systems, video surveillance platforms, AI-driven analytics, intrusion systems, and integrated physical security infrastructure while partnering cross-functionally with Facilities, IT, Construction, Compliance, Risk, HR, Workplace Services, and executive stakeholders. The ideal candidate is both technically proficient and operationally mature; capable of managing enterprise scale security systems, leading physical security projects, responding to critical incidents, and driving continuous improvement across security operations, technology, investigations, and workplace safety initiatives. What you'll do: Security Technology & Infrastructure Management - Administer, configure, maintain, and optimize enterprise access control and video management systems including: - Genetec Security Center - LenelS2 OnGuard - Ambient.ai - ExacqVision - Entrapass - Envoy - Configure, troubleshoot, and support: - Access control hardware and software - Badge readers and credential systems - IP video surveillance systems - Camera analytics and AI event detection - Intercoms, intrusion systems, and integrated security technologies - Lead sourcing, evaluation, testing, and implementation of emerging security technologies to improve operational efficiency, threat detection, automation, and incident response capabilities. - Perform technical evaluations, proof-of-concept deployments, vendor assessments, and system integration testing for new physical security and AI-driven technologies. - Manage enterprise security technology lifecycle planning including upgrades, patching, maintenance coordination, hardware replacement, and vendor support. - Partner with IT and cybersecurity teams to ensure compliance with enterprise network security standards and technology governance requirements. - Develop and maintain security system architecture documentation, network diagrams, installation standards, and operational workflows. Security Operations Management - Oversee daily operational management of enterprise physical security systems and security infrastructure across assigned corporate locations. - Manage enterprise guard force operations including: - Guard scheduling and staffing coordination - Post order development - Incident escalation procedures - Vendor and contract management - Performance oversight and operational compliance - Monitor and respond to security incidents, alarms, system alerts, and operational issues while ensuring uptime and reliability of critical security infrastructure. - Develop and maintain standard operating procedures (SOPs), response protocols, incident workflows, and operational documentation. - Conduct security assessments, operational reviews, and system audits to identify vulnerabilities and recommend mitigation strategies. - Support workplace violence prevention, incident response, threat management, and emergency preparedness initiatives. - Coordinate escalation and response activities during critical incidents, emergencies, executive events, and elevated threat situations. - Conduct and support investigations involving physical security incidents, unauthorized access, theft, policy violations, and operational concerns. Physical Security Installations & Construction Support - Serve as technical lead for physical security installations and infrastructure projects including: - IP camera deployments - Access control installations - Low-voltage cable routing and management - CAT5/CAT6 cable runs - Cable termination and testing - Rack and network hardware installation - Device commissioning and troubleshooting - Conduct field installation work and hands-on technical support including camera mounting, device configuration, system diagnostics, connectivity validation, and physical infrastructure upgrades. - Coordinate with network engineering and IT teams to ensure proper VLAN configuration, bandwidth allocation, network segmentation, and integration of physical security systems into enterprise environments. - Support corporate construction, expansion, and office buildout projects by: - Designing security layouts - Reviewing architectural plans - Determining camera coverage requirements - Coordinating deployment timelines - Managing contractor and integrator activities - Ensure all installations and deployments align with corporate standards, life safety requirements, operational needs, and security best practices. Crisis Management & Emergency Preparedness - Support crisis management, emergency response, and business continuity initiatives from a physical security and operational readiness perspective. - Assist with development and execution of emergency procedures including: - Active assailant response - Evacuation protocols - Shelter-in-place procedures - Fire/life safety response - Severe weather and emergency coordination - Participate in tabletop exercises, drills, incident reviews, and operational readiness assessments. - Serve as a key operational resource during incidents requiring coordinated security response and executive communication. Cross-Functional Leadership & Vendor Management - Partner closely with Facilities, Workplace Services, IT, Legal, Compliance, Risk, HR, Fraud, and executive leadership on physical security initiatives and operational priorities. - Maintain strong relationships with integrators, manufacturers, consultants, and technology vendors to ensure optimal system performance and cost-effective deployment strategies. - Manage vendor performance, contract execution, project timelines, service delivery, and operational expectations. - Support executive-level reporting related to security operations, technology performance, incidents, project status, and risk mitigation initiatives. - Train internal teams, guards, and stakeholders on physical security systems, operational procedures, and incident response protocols. - Provide technical guidance and operational leadership to security personnel, vendors, contractors, and cross-functional teams. Technical Skills & Functional Expertise - Physical Security Information Management (PSIM) - Video Management Systems (VMS) - Access Control Systems - AI-Driven Security Analytics - Enterprise Security Operations - IP Camera Systems - Low-Voltage Infrastructure - Networked Security Devices - Access Credentialing - Incident Response & Investigations - Threat Management & Workplace Safety - Security Integrations & Automation - Vendor & Technology Evaluation - Security Infrastructure Project Management - Security System Commissioning - Cable Termination & Testing - Construction Coordination - Guard Force Management - Emergency Response Coordination - Security Operations Center Support Platforms & Technologies - Genetec - Lenel - Ambient.ai - Envoy - Axis - Hanwha Vision - Enterprise access control hardware ecosystems - Intrusion detection systems - IP networking and low-voltage infrastructure - Video analytics and AI monitoring platforms - Integrated physical security ecosystems What you need: - Bachelor’s degree in Security Management, Criminal Justice, Information Technology, Emergency Management, Business Administration, or related field; equivalent experience may be considered. - 10+ years of experience in corporate physical security, security technology, security operations, low-voltage systems, or related security leadership roles. - Demonstrated experience administering, installing and maintaining enterprise access control and video management systems. - Hands on experience with physical security installations, infrastructure deployment, and integrated security technologies. - Experience managing vendors, contractors, guard force operations, and security technology projects. - Strong understanding of: - Corporate security operations - Security technologies and integrations - Incident response - Investigations - Emergency preparedness - Workplace violence prevention - Physical security best practices - Working knowledge of IP networking, VLANs, low voltage infrastructure, and enterprise technology environments. - Strong troubleshooting, analytical, and problem solving skills. - Ability to manage multiple projects and operational priorities simultaneously. - Strong communication skills with ability to interact effectively across technical teams, operational stakeholders, and executive leadership. - High level of professionalism, discretion, and operational judgment. Preferred Qualifications: - Industry certifications such as: - CPP (Certified Protection Professional) - PSP (Physical Security Professional) - PCI (Professional Certified Investigator) - Security technology certifications - Experience in financial services, fintech, corporate enterprise, or highly regulated environments. - Experience supporting multi-site or geographically distributed operations. - Familiarity with AI enabled monitoring platforms and advanced video analytics. - Experience supporting executive protection operations or high-profile corporate events. - Background in investigations, threat assessment, or security operations center environments. Compensation and Benefits The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page! SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.The Company hires the best qualified candidate for the job, without regard to protected characteristics.Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.New York applicants: Notice of Employee RightsSoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.Internal Employees If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.
Security Consultant
ProArchConsulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.
• Lead security strategy development and roadmap planning aligned to business priorities. • Produce and deliver executive security reporting (risk, trends, outcomes, and next steps). • Provide security assessments, vulnerability management guidance, and awareness program support as part of managed services and professional services engagements. • Own solution implementation and program onboarding, including documentation, handoffs, and acceptance criteria. • Implement and manage SIEM/XDR architecture (e.g., Microsoft Sentinel and Microsoft Defender XDR) including configuration, tuning, and workflows. • Maintain solution health and integrations (connectors, data sources, agents, and alert fidelity). • Perform account/permission management and governance for security solutions. • Provide guidance and escalation support for Security Specialists; coordinate incident and service issue escalations to resolution. • Support presales meetings, proof-of-value/proof-of-concept efforts, and security program cost & scope modeling. • Deliver vendor and ProArch workshops; contribute to presentations, webinars, and approved marketing initiatives. • Research and evaluate emerging technologies; contribute to solution design and service evolution. • Deliver services using ProArch standard playbooks, templates, quality gates, and reporting packs. • Improve programs through automation and security engineering (where appropriate) to increase repeatability and reduce manual effort.
Microsoft Security Architect
Armor Defense IncJoin Armor if you want to be part of a company that is redefining cybersecurity. Here, you will have the opportunity to shape the future, disrupt the status quo, and be a part of a team that celebrates energy, passion, and fresh thinking. We are not looking for someone who simply fills a role – we want talent who will help us write the next chapter of our growth story. Commitment to Growth: A growth mindset that encourages continuous learning and improvement with adaptability in the face of challenges. Integrity Always: Sustain trust through transparency and honesty in all actions and interactions regardless of circumstances. Empathy In Action: Active understanding, compassion, and support to the needs of others through genuine connection. Immediate Impact: Taking initiative with swift, informed actions to deliver positive outcomes. Follow-Through: Dedication to delivering finished results with attention to quality and detail to achieve the desired outcomes.
Role Description Armor Defense Inc. is seeking a Microsoft Security Architect / Senior Consultant to lead and deliver advanced consulting engagements across the full Microsoft security ecosystem. This role goes beyond a single product area, requiring deep architectural expertise spanning: - Microsoft Defender (Endpoint, Cloud, Identity, Office 365, and OT) - Microsoft Sentinel - Microsoft Purview (Information Protection, DLP, Data Governance) - Microsoft Entra (ID, Permissions Management, Verified ID, Workload Identities) - Conditional Access policy design The successful candidate will serve as a trusted advisor to enterprise customers, conducting security assessments, designing end-to-end security architectures, and implementing solutions that address modern threats, data protection requirements, AI readiness, and Zero Trust maturity. This role combines hands-on technical delivery with strategic advisory, pre-sales support, and the development of reusable intellectual property for Armor Defense's Professional Services practice. This is a contract engagement with flexibility for part-time or full-time commitment, depending on the project pipeline. The candidate will work closely with Armor Defense's delivery leadership, account teams, and Microsoft partner ecosystem to drive customer outcomes and expand Armor's consulting footprint. Qualifications - 4+ years of experience in cybersecurity, security engineering, sales engineering, or solution consulting, with a strong focus on Microsoft security technologies. - 2+ years of hands-on experience with Microsoft security solutions, including Microsoft Defender (full stack), Microsoft Sentinel, Microsoft Purview, Microsoft Entra, and Conditional Access. - 1+ years of customer-facing experience in a delivery, pre-sales, or consulting capacity. - Demonstrated expertise in endpoint, on-premises, and cloud security concepts, features, and reference architectures across the Microsoft platform. - Specific deep expertise in at least three of the following: - Microsoft Sentinel (SIEM/ SOAR) - The full Defender stack (including Defender for Cloud and OT) - Microsoft Purview (Information Protection, DLP, Data Governance) - Microsoft Entra (Identity Governance, Permissions Management) - Conditional Access policy design - Experience leading and delivering consulting engagements with high-quality outcomes delivered on time and within budget. - Proven ability to develop technical and conceptual reference architectures for enterprise security environments. - Strong ability to correlate and communicate security gaps with their respective business risks to executive stakeholders. - Broad security expertise with a deep understanding of security principles, risk management, compliance frameworks, and Zero Trust architecture. - Excellent written and verbal communication skills in English, with senior-level presentation and stakeholder engagement capabilities. - Strong problem-solving skills and the ability to work independently and as part of distributed teams. - Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline (or equivalent professional experience). Requirements - Relevant Microsoft Security certifications: SC-200, SC-300, SC-400, AZ-500, or MS-500. - Experience with Microsoft Copilot for Security and understanding of AI-driven security operations. - Familiarity with Azure Information Protection (AIP) scanner, Microsoft Purview Data Governance capabilities. - Experience designing Conditional Access frameworks that integrate with Intune device compliance. - Exposure to non-Microsoft security platforms (AWS Security Hub, GCP Security Command Center). - Experience with data governance frameworks such as DAMA-DMBOK and data protection regulations (GDPR, CCPA, HIPAA, PCI DSS). - Understanding of AI/ML data pipelines and the security and governance prerequisites for responsible AI deployment. - Prior experience in large-scale enterprise environments spanning financial services, healthcare, aviation, energy, telecommunications, or government. - Experience managing consulting engagements from the provider side, including SOW development, scope management, SLA delivery, and client relationship management. - CISSP, CISM, or other recognized industry security certifications. Benefits - Opportunity to shape the future of cybersecurity. - Join a team that celebrates energy, passion, and fresh thinking. - Flexibility in work commitment (part-time or full-time). - Possibility of conversion to a full-time employee based on project pipeline. Company Description At Armor, we are committed to making a meaningful difference in securing cyberspace. Our vision is to be the trusted protector and de facto standard that cloud-centric customers entrust with their risk. We strive to continuously evolve to be the best partner of choice, breaking norms and tirelessly innovating to stay ahead of evolving cyber threats and reshaping how we deliver customer outcomes. - Unique offerings to help customers understand, co-manage, or completely outsource their risk. - Learn more at: https://www.armor.com



