Security Engineer III, Product AppSec

1 month, 2 weeks ago
Full-time
Senior
DevOps and Infrastructure
Veeam Software

Veeam Software

Veeam Software is the global leader in Backup that delivers Modern Data Protection, offering solutions for virtual environments, enterprises, small businesses, and service providers worldwide.

Internet Software & Services
1K-5K
Founded 2006
$500M raised

Description

  • Monitor, assess, and manage security risks related to open-source dependencies, CVEs, and third-party components.
  • Triage and validate vulnerabilities across applications, containers, infrastructure, and dependencies, prioritizing by exploitability, exposure, and business impact.
  • Coordinate patch management initiatives and support automated patch deployment workflows with Release Engineering and DevOps teams.
  • Support and expand the Security Champion program by partnering with developers to improve secure coding awareness and adoption.
  • Integrate security controls into CI/CD pipelines and automate vulnerability scanning, dependency analysis, and security reporting.
  • Develop playbooks, documentation, and educational materials that enable self-service security within engineering teams.
  • Contribute to threat modeling, secure architecture discussions, and continuous improvement of secure SDLC processes.

Requirements

  • 5+ years of experience in Product Security, Application Security, DevSecOps, or Vulnerability Management.
  • 3+ years of hands-on experience with application security testing tools such as SAST, DAST, and SCA.
  • 2+ years in vulnerability management, including triage, SLA tracking, and remediation coordination.
  • Familiarity with CVEs, CVSS scoring, SBOM concepts, and software supply chain security.
  • Experience with CI/CD platforms, modern DevOps workflows, and cloud-native technologies.
  • Bachelor's degree in Computer Science, Engineering, or equivalent experience.
  • Experience participating in or managing Security Champion programs (preferred).
  • Knowledge of OWASP Top 10 and secure coding practices for cloud-native and enterprise products (preferred).
  • Familiarity with IaC, regulated environments, and compliance-driven security activities (preferred).
  • Relevant certifications such as CSSLP, GWEB, CCSP, OSCP, or GPEN (preferred).
  • US citizenship is required; security clearance is not currently required but may be requested in the future.

Benefits

  • Unlimited paid time off, 12 paid holidays, 4 global VeeaMe Days for self-care, and 24 paid volunteer hours annually.
  • Paid parental leave: 8 weeks for all parents and 16 weeks for birthing parents.
  • Medical, dental, and vision coverage starting on the first day.
  • Mental health support, therapy sessions, and digital wellness tools through the Employee Assistance Program.
  • 401(k) retirement plan with company matching contributions.
  • Fertility, adoption, and surrogacy support through Maven.
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting.
  • Learning and development support through LinkedIn Learning, O’Reilly, mentoring, workshops, and Global Day of Learning.
  • Competitive total target compensation with a performance-based bonus, with U.S. ranges from $151,200 to $347,500 depending on location.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
20 hours, 33 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
21 hours, 18 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 20 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 21 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers