Product Security Engineer

As our platform continues to scale, security becomes a core product capability rather than a separate function. We're looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up.

This is a highly technical, hands-on role where you'll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle.

Responsibilities

Application Security

  • Review application architecture and new product features from a security perspective.

  • Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.

  • Perform threat modeling and security design reviews.

  • Support internal and external penetration testing activities.

Secure Development

  • Build and improve Secure SDLC across engineering teams.

  • Integrate security tooling into CI/CD pipelines.

  • Improve developer security practices and provide technical guidance.

  • Help engineering teams remediate vulnerabilities.

Cloud & Infrastructure Security

  • Improve the security posture of our cloud infrastructure.

  • Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components.

  • Implement security monitoring and hardening best practices.

  • Work closely with Platform and DevOps teams.

Security Automation

  • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection.

  • Automate security checks and developer workflows.

  • Continuously improve security visibility across the engineering organization.

Requirements

  • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.

  • Strong software engineering background.

  • Experience securing backend systems, REST APIs, and microservices.

  • Experience with cloud platforms (AWS, GCP, or Azure).

  • Strong understanding of Kubernetes, Docker, networking, and infrastructure security.

  • Experience with Secure SDLC and security automation.

  • Hands-on experience with SAST, DAST, dependency scanning, and secrets management.

  • Understanding of OWASP Top 10, common attack vectors, and secure coding practices.

  • Ability to work closely with software engineers and influence technical decisions.

  • Fluent English.

Nice to have

  • Mobile application security experience.

  • Experience in fintech, crypto, payments, or blockchain.

  • Offensive security or penetration testing experience.

  • Security certifications are a plus but not required.

Benefits

  • Professional growth: support for courses, conferences, and English learning (up to 100% coverage).

  • Work-life fit: remote or hybrid format with flexible hours across international teams.

  • Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year

  • Recognition programs: structured performance reviews and team awards.

  • Team culture: retreats in international locations (for example, company apartments in Cyprus).

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available