Job Closed

This listing is no longer active.

Staff Product Security Engineer

Security EngineerSecurity EngineerOtherRemoteLeadTeam 5,001-10,000Since 1985H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

135 days ago

Salary

$105K - $155K / year

Seniority

Lead

Bachelor Degree5 yrs expEnglishAWSAzureGCPJavaJavaScriptPythonTypeScript

Job Description

Staff Product Security Engineer

PTC

• Serve as a subject matter expert (SME) on Information Security • Identify and implement new security technologies and best practices • Review security test results from vulnerability scans, penetration testing • Guide and influence multi-disciplinary teams in implementing and operating Cyber Security controls • Consults with internal teams on engineering designs and development of cloud-based systems • Learn with agility; empowered to update and enhance current security practices

Job Requirements

  • US Citizen or Green Card holder based in the US required to meet ITAR Compliance
  • Bachelor's degree in computer science, Information Security, Engineering, or equivalent experience
  • 5+ years of experience in Application Security, Product Security, or Software Security Engineering
  • Strong knowledge of Secure Software Development Lifecycle (SSDLC)
  • Hands-on experience with threat modeling, secure design reviews, and application security assessments
  • In-depth understanding of OWASP Top 10 and OWASP API Top 10
  • Experience using SAST, DAST, SCA, and secrets scanning tools and integrating them in CI/CD
  • Proficiency in at least one programming language: Java, Python, JavaScript/TypeScript, or Go
  • Experience securing mobile applications, including offline data and sync workflows
  • Secure REST and event-driven APIs used by customers, partners, and internal services
  • Strong understanding of cloud platforms (AWS, Azure, or GCP)
  • Strong written and verbal communication skills.

Benefits

  • Medical, dental, and vision insurance
  • Paid time off and sick leave
  • Tuition reimbursement
  • 401(k) contributions and employer match
  • Flexible spending accounts
  • Life insurance
  • Disability coverage
  • Employee share purchase program (ESPP)
  • Performance-based bonus
  • Commuter subsidy

Related Categories

Related Job Pages

More Security Engineer Jobs

Charlie Health logo

Lead Security Engineer

Charlie Health

Personalized mental health treatment for teens, young adults & families in crisis.

Security Engineer135 days ago
OtherRemoteTeam 501-1,000H1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Charlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will be the subject matter expert on application and cloud infrastructure security, guiding the business in building secure, scalable and HIPAA-compliant software solutions. Responsibilities - Lead application security program including SAST/DAST integration, security code reviews and developer training. - Perform threat modeling and architecture reviews to identify potential security risks early in design phases. - Integrate security tooling and automate security processes into CI/CD and DevOps pipelines. - Manage application and cloud security vulnerability management program including configuration of scanning tools, validation and prioritization of findings, and remediation of risks. - Review and document new third-party integrations with Charlie Health applications and cloud infrastructure. - Perform internal penetration testing and manage third-party penetration tests. - Work with teams to build and enforce secure SDLC controls in a fast-paced agile environment. - Develop cloud security configuration baselines and monitor for gaps. - Document business continuity and disaster recovery procedures for cloud infrastructure environment. - Participate in security incident response activities related to Charlie Health applications and infrastructure systems. - Help define metrics and KPIs that demonstrate the effectiveness of the application and cloud security programs. Qualifications - 10+ years of experience in application security, secure software development, cloud security or related roles. - Bachelor’s degree in Computer Science or related field, or equivalent experience. - Proficiency in secure coding practices and languages such as Typescript, Node, Python, Java, C++ or similar. - Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler). - Knowledge of container security concepts, including container image scanning, secure image pipelines, and common misconfigurations in containerized environments. - Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc. - Experience implementing security in CI/CD pipelines such as GitHub Action and agile development workflows. - Familiarity with AWS cloud platform and AWS security best practices. - Familiarity with management and deployment of SAST, DAST, and SCA tooling. - Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications. - Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences. Preferred Qualifications - Experience with HIPAA and securing applications in healthcare, or other regulated, environments. - OSCP, OSWE, AWS Security or other relevant security certifications. - Experience securing custom software collaboratively on a team. - Experience with Wiz or similar CNAPP tools. - Knowledge of AI/ML security best practices. - Familiarity with Infrastructure as Code (IaC). - Knowledge of security standards such as SOC2, ISO 27001/2, NIST 800-53, HITRUST, or HIPAA Security Rule. Benefits - Comprehensive benefits for all full-time, exempt employees. - Total target base compensation between $180,000 and $240,000 per year. - Cash compensation may include stock options and other Charlie Health-sponsored benefits.

United States
$180K - $240K / year
Job Closed
Procter & Gamble logo

Senior Offensive Security Engineer, Red Team

Procter & Gamble

Procter & Gamble, or P&G, is the parent company behind some of the world's most recognizable household and personal care brands. The company was established in

Security Engineer135 days ago

• Lead end-to-end red team operations aligned to priority threat actors: scenario design, ROE, pre-briefs, execution, and hot-wash/AAR • Support purple-team engagements with DFIR/SOC and Detection Engineering to convert TTPs into durable detections, runbooks, and response improvements with measurable outcomes • Orchestrate assumed-breach campaigns emphasizing evasion and control bypass (EDR/AV, email/web security, identity/conditional access, network segmentation, cloud guardrails) • Perform campaign/TTP research, develop internal PoCs/tooling (e.g., tradecraft to exercise specific controls, lightweight payloads), and steward OPSEC • Produce executive-ready risk narratives and technical reporting (ATT&CK mapping, artifacts, evidence handling) and brief senior leadership • Mentor junior engineers; set standards for craft quality, methodology, and safety • Coordinate multi-party/third-party exercises; manage risk, deconflict with production, and ensure stakeholder alignment • Contribute to operational expansion by researching, prototyping, and developing novel capabilities for offensive use • Contribute to program maturity: metrics/KPIs, roadmap, methodology standardization, control validation cadence, and integration with vulnerability management

Ohio
$110K - $165K / year
Job Closed
CACI International Inc logo

Security Technical Implementation Guide Analyst

CACI International Inc

Expertise and Technology for National Security

Security Engineer135 days ago
OtherRemoteTeam 10,001+Since 1962H1B No Sponsor

• Conduct monthly reviews of Tenable and SteelCloud STIG reports • Analyze STIG data to remediation actions and identify responsible parties to conduct those actions • Document comprehensive action plans for identified STIGs • Develop and maintain custom STIG reports tailored for individual Air Force bases • Provide specific, actionable feedback to Air Force bases and leadership on how to remediate STIGs they are responsible for • Work closely with base IT teams, Enterprise security teams, and other stakeholders to ensure effective STIG management • Stay current with the latest STIG trends, threat intelligence, and best practices in STIG management

United States
$63.3K - $129.7K / year
Job Closed
CACI International Inc logo

SAP Security Lead

CACI International Inc

Expertise and Technology for National Security

Security Engineer135 days ago
OtherRemoteTeam 10,001+Since 1962H1B No Sponsor

• Lead the design and implementation of SAP Security across S/4HANA, Fiori, and the SAP NS2 Private Cloud Edition landscape. • Develop the SAP security architecture and ensure alignment with DoD cybersecurity, RMF, STIGs, and NIST 800-53 controls. • Own the identity and access management strategy, including business role design, authorization concepts, and user provisioning processes. • Lead implementation and ongoing use of SAP GRC Access Control (ARA, EAM, BRM, ARM). • Define and maintain USTRANSCOM-specific Segregation of Duties (SoD) rulesets and automated risk analyses. • Coordinate with SAP NS2 teams to support secure operations, boundary protections, patching, and compliance requirements. • Support security readiness activities, compliance assessments, vulnerability mitigation, and ATO documentation. • Guide security design through project phases including blueprinting, build, testing, cutover, deployment, and sustainment. • Provide consultative guidance on SAP Security and GRC best practices to internal teams and government stakeholders. • Manage and mentor SAP security analysts supporting daily operations and project delivery. • Work on Application Security, Compliance, and Delivery in the areas of SAP S/4HANA Security and GRC implementation.

Illinois
$105.1K - $231.1K / year
Job Closed