Senior Product Security Engineer (Contract)

2 hours, 10 minutes ago
Contract
Senior
Cybersecurity

Iru

Iru is an AI-powered IT and security platform for securing users, apps, and devices. It unifies identity and access, endpoint security and management, and compliance automation into one platform.

Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Description

  • Perform security architecture and design reviews for products and features.
  • Conduct threat modeling for applications, APIs, and AI-enabled services.
  • Perform manual penetration testing across web, API, thick-client, and mobile applications.
  • Conduct secure code reviews and validate vulnerability remediation.
  • Partner with engineering teams to prioritize and remediate vulnerabilities.
  • Define secure coding standards, security guardrails, reusable patterns, and reference architectures.
  • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools while tracking remediation SLAs and metrics.
  • Assess AI and LLM applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Integrate security tooling into CI/CD and developer workflows and build automation to reduce manual work.
  • Collaborate with Product, Engineering, Infrastructure, Cloud Security, Compliance, and Sales Engineering teams.

Requirements

  • 5+ years of experience in Product Security or Application Security.
  • Experience securing web applications, APIs, microservices, and cloud-native applications.
  • Experience with threat modeling and penetration testing.
  • Strong knowledge of the OWASP Top 10, OWASP API Top 10, authentication, authorization, OAuth/OIDC, and secure SDLC practices.
  • Experience with SAST, DAST, SCA, and container security tools.
  • Experience partnering directly with engineering teams.
  • Strong written and verbal communication skills.
  • Experience securing AI/LLM applications (preferred).
  • Experience with Kubernetes, containers, cloud security, and GitHub Actions or CI/CD security (preferred).
  • Experience with Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security; OSCP, GWAPT, GWEB, CSSLP, or CISSP certifications are preferred.

Benefits

  • Competitive salary.
  • 100% individual and dependent medical, dental, and vision coverage.
  • 401(k) with a 4% company match.
  • 20 days of paid time off and an annual Wellness Week.
  • Equity for full-time employees.
  • Up to 16 weeks of paid leave for new parents.
  • Paid family and medical leave.
  • Career growth opportunities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer

Radicle Health 11-50 Internet Software & Services

Radicle Health is seeking a Senior Application Security Engineer to strengthen security across its 10 SaaS platforms by integrating security tooling and practices into software development and operations.

AWS HIPAA OWASP Penetration Testing
2 hours, 54 minutes ago

Lead Security Engineer - Penetration Testing & AI Security

HighLevel 251-1K Internet Software & Services

HighLevel is seeking a Lead Security Engineer to secure its SaaS platform and AI-enabled products through application security leadership, secure development practices, and adversarial testing of AI systems.

Bash CI/CD Cybersecurity DevSecOps Docker Go JavaScript JWT Kubernetes Microservices OpenID Connect OWASP Penetration Testing Python SAML
6 days, 3 hours ago

Application Security Engineer II - Contract ( 6 months )

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for client bug bounty programs, assess severity, and coordinate responses with researchers and customers.

Burp Suite Nmap
1 week, 1 day ago

Cyber Security Engineer (Application Security)

TherapyNotes 51-250 Health Care Providers & Services

TherapyNotes is seeking a hands-on Cyber Security Engineer to own application security across the SDLC and CI/CD pipeline for its healthcare-regulated behavioral health SaaS platform.

AWS Azure CI/CD Cybersecurity GitHub Actions HIPAA SIEM Terraform
1 week, 2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers