Logo for 365 Retail Markets

Principal Product Security Engineer

Key Facts

Remote From: 
Full time
Senior (5-10 years)
English

Other Skills

  • β€’
    Analytical Skills
  • β€’
    Communication
  • β€’
    Leadership

Roles & Responsibilities

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
  • 7+ years of experience in software engineering, application security, product security, or cybersecurity engineering.
  • Strong understanding of secure application architecture and modern security practices for web, mobile, cloud, and distributed systems.
  • Hands-on experience reviewing source code and identifying security vulnerabilities.

Requirements:

  • Own and mature the product security program, including security review processes and secure development standards.
  • Lead security architecture reviews and secure design initiatives across backend services, web applications, mobile applications, APIs, and remote devices.
  • Partner closely with Engineering, DevOps, QA, Infrastructure, and Product teams to integrate security into the software development lifecycle.
  • Drive vulnerability management efforts, including prioritization, remediation guidance, and validation.

Job description

Description

Responsibilities

  • Own and mature the product security program, including security review processes, secure development standards, risk prioritization, vulnerability remediation practices, and engineering enablement.
  • Lead security architecture reviews and secure design initiatives across backend services, web applications, mobile applications, APIs, and remote devices.
  • Review source code and application architecture to identify security vulnerabilities, insecure patterns, and operational risks.
  • Partner closely with Engineering, DevOps, QA, Infrastructure, and Product teams to integrate security into the software development lifecycle.
  • Establish and enforce secure coding standards, development guidelines, and security best practices.
  • Mentor and guide software engineers on secure development practices and remediation strategies.
  • Perform threat modeling and risk assessments for new and existing products and infrastructure.
  • Assist in incident response investigations, root cause analysis, and remediation planning.
  • Evaluate third-party libraries, frameworks, and dependencies for security and operational risks.
  • Collaborate with DevOps and Infrastructure teams on cloud security, CI/CD security, secrets management, and system hardening.
  • Drive vulnerability management efforts, including prioritization, remediation guidance, and validation.
  • Help define and implement logging, monitoring, and security alerting strategies.
  • Partner with external security consultants and vendors on penetration testing and security assessments.
  • Promote a security-first engineering culture across the organization.
Requirements

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
  • 7+ years of experience in software engineering, application security, product security, or cybersecurity engineering.
  • Strong understanding of secure application architecture and modern security practices for web, mobile, cloud, and distributed systems.
  • Hands-on experience reviewing source code and identifying security vulnerabilities.
  • Experience with OWASP Top 10, secure coding standards, authentication/authorization models, API security, and vulnerability remediation.
  • Experience securing cloud-native environments in AWS, Azure, or GCP.
  • Strong understanding of CI/CD pipelines, DevSecOps practices, container security, and infrastructure security.
  • Experience with threat modeling, penetration testing coordination, and incident response processes.
  • Ability to mentor engineers and influence technical direction across multiple teams.
  • Strong analytical, communication, and leadership skills.

Preferred Qualifications

  • Experience with unattended retail, IoT, edge devices, kiosks, payment systems, or embedded Linux environments.
  • Knowledge of PCI, security compliance frameworks, and enterprise risk management.
  • Experience with observability and monitoring tools such as Datadog, Splunk, Instana, or similar platforms.
  • Experience working with AI-assisted development tools and understanding emerging AI-related security risks.
  • Relevant industry certifications such as CISSP, CSSLP, OSCP, or cloud security certifications.

Security Engineer Related jobs

Other jobs at 365 Retail Markets

We help you get seen. Not ignored.

We help you get seen faster β€” by the right people.

πŸš€

Auto-Apply

We apply for you β€” automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

✨

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.