About The Position

The Product Security organization helps Optimum move faster, securely. We’re a team of engineers who work to enable other teams to build products as quickly as possible while continuing to protect our customers. We support developers in shipping secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authentication, authorization, and safe data handling across the company. As a Product Security Engineer focusing on application security, you'll be a trusted advisor, collaborating closely with engineering and product teams to ensure security is a cornerstone of every product. You will partner with leadership to shape product strategy, advocate for strong security controls, and influence future product iterations. By leveraging your deep industry knowledge, you'll lead the charge in implementing secure architecture and design principles, ensuring early detection and prevention of vulnerabilities. Your expertise in security assessments and software engineering will help identify and mitigate potential threats, while your mentorship and training efforts will foster a security-first culture.

Requirements

  • Bachelor’s degree in Computer Science, Electrical Engineering, a related field, or equivalent professional experience.
  • 5+ years of combined hands-on experience in software engineering and application and infrastructure security.
  • Demonstrable experience with product and application security concepts, including API, web, and mobile app security.
  • Excellent communication skills, both written and verbal.
  • Proven ability to establish credibility and build trust with engineers and operational staff.
  • Expertise in conducting comprehensive threat modeling and risk assessments.
  • Experience building, deploying, and securing workloads and infrastructure in Google Cloud Platform (GCP).
  • Experience utilizing and securing AI/ML models and AI-integrated solutions.
  • Proficient in modern security frameworks, tools, and techniques.
  • Proficiency in secure SDLC practices and commercial and open-source security testing tools.
  • Practical experience securing CI/CD pipelines and Infrastructure-as-Code (IaC) tools.
  • Strong understanding of both human and non-human identity management.
  • Experience overseeing vulnerability and threat management at the platform and application levels.
  • Strong understanding of cryptography and key management use cases.
  • Proficiency in one or more modern programming languages like Golang, Python, Node, and Java.

Nice To Haves

  • Familiarity with advanced networking products and capabilities like SASE and SD-WAN.
  • Familiarity with penetration testing and red teaming.
  • Site Reliability Engineering (SRE) experience.
  • Experience developing security-focused Terraform modules.

Responsibilities

  • Collaborate with engineering and product teams to integrate security and secure-by-default guardrails into the product lifecycle.
  • Conduct Threat Modeling and Risk Assessments from the early stages of the product development lifecycle.
  • Perform rigorous security testing and reviews to uncover and address security weaknesses.
  • Lead initiatives automating security processes from the developer workstation to cloud, SaaS, and datacenter environments.
  • Design, build, deploy, and support security-focused solutions across cloud and on-premise footprints.
  • Foster a security-first culture by educating and empowering engineering and product teams.
  • Stay updated on the latest security threats, vulnerabilities, and technology trends.
  • Contribute to incident response efforts, investigate root causes, and implement corrective actions.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service