Logo for 99x

Product Security Expert

Role overview

Qualifications

  • BSc or MSc in Computer Science, Engineering, or a related field
  • Experience with vulnerability assessment and security concepts (OWASP Top 10 level)
  • Familiarity with Azure cloud services
  • Ability to read and understand code (e.g., .NET/C#, JavaScript/TypeScript, Python)

Responsibilities

  • Review and triage security findings from ASPM tools
  • Classify findings as true positive, false positive, or requires additional context
  • Document classification rationale using standardized templates
  • Develop and refine a risk-based testing strategy

Key facts

  • Remote from: Anywhere
  • Full time
  • Product Security Engineer
  • English

Hard skills

Other skills

  • Communication
  • Detail Oriented
  • Collaboration

About the company

99x logo

99x

Software Development

Headquartered in Norway, 99x is a technology company co-creating well-engineered, innovative digital products for the Scandinavian market. Its expertise has been proven through a portfolio of over 150 impactful global digital products developed since 2004, together with leading Independent Software Vendors (ISVs). 99x employs over 500 technology and product specialists, who are high achievers, creative thinkers and team players. The company is one of Asia’s Best Workplaces for 2022 and has been named a Best Workplace in Sri Lanka for 10 consecutive years.

Company details

Company typeSME
IndustrySoftware Development
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

We are looking for a Product Security Engineer to join our team and support vulnerability triage, risk-based testing, and test automation initiatives across modern cloud-based platforms.

In this role, you will focus on identifying, classifying, and validating security findings while contributing to a robust testing strategy and automation framework. You will work closely with internal teams using asynchronous communication and apply both analytical and exploratory approaches to ensure high-quality software delivery.

The role combines application security, vulnerability assessment, and quality assurance, with a strong focus on structured analysis, automation, and cloud environments.

Responsibilities:
Review and triage security findings from ASPM tools
Classify findings as true positive, false positive, or requires additional context
Document classification rationale using standardized templates
Maintain and organize findings backlog per product
Flag ambiguous or unclear findings for further review
Work across multiple vulnerability categories:
SAST (code-level vulnerabilities)
SCA (dependency and transitive risks)
Secret detection (credentials exposure)
CSPM (Azure cloud misconfigurations)

Develop and refine a risk-based testing strategy
Apply exploratory testing techniques for complex and high-risk scenarios
Validate end-to-end business flows from a user perspective

Build and maintain automated test suites using:
Playwright (TypeScript) for new tests
Selenium (C#) for existing legacy tests

Support migration from Selenium to Playwright over time
Collaborate with the team to ensure scalable and maintainable test architecture

Leverage AI tools to accelerate:
Test design
Test data generation
Automated test development

Continuously improve QA processes based on:
Production incidents
User feedback
System logs and analytics

Requirements:
BSc or MSc in Computer Science, Engineering, or a related field
Experience with vulnerability assessment and security concepts (OWASP Top 10 level)
Familiarity with Azure cloud services
Ability to read and understand code (e.g., .NET/C#, JavaScript/TypeScript, Python)
Understanding of dependency scanning and transitive dependencies
Experience with test automation frameworks (Playwright and/or Selenium)
Strong attention to detail and structured work approach
Ability to work independently with asynchronous communication
Fluency in written English

Hands-on experience with:
ASPM / SAST / SCA tools
Test automation frameworks (Playwright, Selenium)
Exploratory and risk-based testing strategies

Nice-to-have:
Experience with tools such as:
Snyk
Checkmarx
Semgrep
SonarQube
Aikido
Wiz
OX or similar

Experience using AI tools for triaging and test automation

Strong communication skills
Analytical mindset with a focus on accuracy over speed
Ability to balance security, quality, and business priorities
Collaborative and proactive attitude

If this sounds like you, share your CV with us and let’s talk.



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Product Security Engineer Related jobs

Other jobs at 99x

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.