Senior Product Security Engineer

Brunswick CorporationMettawa, IL
$118,400 - $174,000Hybrid

About The Position

The Product Security team is responsible for protecting our customers and Brunswick Corporation from evolving security threats in our products. Product security encompasses secure systems, hardware and software design of both devices and the systems to which they connect (cloud, infrastructure, server, etc.). The Product Security team partners with application development, product engineering, cloud, infrastructure, and DevSecOps teams to integrate security throughout the product lifecycle, instituting a Secure Systems/Software Development Life Cycle (SDLC) and application of applicable standards and best practices. As a Senior Product Security Engineer, you will serve as a technical leader and trusted advisor responsible for maturing product security capabilities, improving secure development practices, and reducing product security risk across Brunswick's product portfolio. The role requires close collaboration with development teams, architects, DevSecOps engineers, cloud engineers, and business stakeholders to ensure security is embedded throughout the product lifecycle with a secure by design and default approach. This position is responsible for advancing Brunswick's product security program through the implementation and oversight of product security governance, threat modeling, providing architectural/design guidance, developer enablement, vulnerability management, security testing, security tooling, and DevSecOps practices. The role provides technical leadership for product security initiatives, develops and maintains security policies, standards, guidelines, and best practices, and partners with engineering teams to embed security throughout the product lifecycle. Additionally, this position plays a key role in maturing and scaling Brunswick's Security by Design program to support secure, resilient, and high-quality product development across all business units. Success in this role requires a strong understanding of potential security threats, secure system architecture, hardware security, secure software development, application security, cloud-native technologies, software supply chain security, security automation, and modern development methodologies. The ideal candidate possesses strong technical, analytical, and communication skills and can effectively collaborate with stakeholders across engineering teams to drive secure development practices and advance Brunswick's product security objectives.

Requirements

  • Bachelor’s degree in Electrical or Electronic Engineering, Computer Science, Software Engineering, Cybersecurity, or equivalent professional experience.
  • 5+ years of experience in Product Security for IoT type devices and associated cloud/server systems.
  • Fundamental understanding of the application of a product security standard such as ISO/SAE 21434, IEC/ISA 62443-4-1/4-2, Articles 3.3 (d), (e), and (f) of the EU Radio Equipment Directive, EU Cybersecurity Resilience Act, or comparable.
  • Experience performing product threat modeling and security risk assessments.
  • Strong understanding of the application of hardware security components such as a Hardware Security Module, Trusted Platform Module or similar.
  • Strong understanding of the required implementation details of secure boot, secure communications, secure storage in embedded devices which leverage a hardware security component.
  • Demonstrated experience leading product security initiatives for resource constrained embedded products.
  • Strong understanding of SDLC and SSDLC methodologies.
  • Strong understanding of secure coding principles, OWASP Top 10 risks, CWE Top 25 weaknesses, and common application attack methodologies.
  • Experience with reviewing and addressing findings from Veracode or comparable application security testing platforms.
  • Experience supporting vulnerability management and remediation programs.
  • Knowledge of software supply chain security concepts, dependency management, open-source software governance, and SBOM practices.
  • Fundamental understanding of cloud application security principles across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
  • Familiarity with containerized applications, Kubernetes, and modern cloud-native architecture.
  • Knowledge of secure authentication, authorization, encryption, secrets management, and application-layer security controls.
  • Strong written and verbal communication skills.
  • Ability to effectively influence engineering teams and drive security outcomes without direct authority.

Nice To Haves

  • Certification as Automotive CyberSecurity Engineer (CASE), iSAQB® Certified Professional for Software Architecture —EMBEDDEDSEC module training, GIAC Security Essentials (GSEC) certification or comparable.
  • Experience applying product security standards such as ISO/SAE 21434, IEC/ISA 62443-4-1/4-2, Clause 3.3 d, e, f of the EU Radio Equipment Directive, or EU Cybersecurity Resilience Act, or comparable to an organization’s policies, processes and procedures.
  • Experience leading or playing a major role in the execution of a Threat Analysis and Risk assessment, per ISO/SAE 21434.
  • Experience integrating a hardware security component such as a Hardware Security Module, Trusted Platform Module or similar into a design and leveraging it in the implementation of secure boot, secure communications, or secure storage.
  • Experience with software development and DevSecOps platforms, including GitHub Enterprise, Azure DevOps, Bitbucket, Gerrit, Jenkins, or similar source code management, code review, build automation, and Continuous Integration / Continuous Deployment (CI/CD) platforms.
  • Experience developing security metrics, reporting programs, and risk dashboards.
  • Experience supporting software supply chain security initiatives and SBOM or HBOM management.
  • Familiarity with Generative Artificial Intelligence (GenAI), secure artificial intelligence development practices, and artificial intelligence-assisted software engineering.
  • Experience supporting product security programs that also encompass cloud-native, web, and mobile, software environments.
  • Experience operating within a large global enterprise environment.

Responsibilities

  • Help build maturity of product development teams in product security through training and mentoring.
  • Conduct threat modeling, attack surface analysis, and product security risk assessments for new and existing products and applications and recommend mitigating controls.
  • Lead product security design reviews and participate in architecture review processes, identifying potential weaknesses or vulnerabilities and recommend appropriate changes.
  • Partner with development teams to integrate security requirements into product architecture, design, development, testing, deployment, and maintenance activities.
  • Define, maintain, and promote product security policies, standards, procedures, best practices, and technical guidance.
  • Review false-positive requests, mitigation plans, and risk exception submissions in accordance with established security governance processes.
  • Establish security testing requirements and assist teams in implementing security verification and validation throughout the development lifecycle.
  • Provide security consultation for web applications, mobile applications, cloud-native applications, microservices, embedded software, and Application Programming Interfaces (APIs).
  • Serve as a senior subject matter expert for product security, secure software development, and DevSecOps practices.
  • Support the implementation of secure coding practices aligned with OWASP, CWE, Security by Design requirements, and Brunswick secure development standards.
  • Review and analyze application security findings and provide remediation guidance to development teams.
  • Support developers in resolving vulnerabilities related to applicable product security coding standards such as the Open Worldwide Application Security Project (OWASP) Top 10 risks, Common Weakness Enumeration (CWE) Top 25 weaknesses, authentication, authorization, session management, cryptography, injection attacks, and software supply chain risks.
  • Monitor vulnerability remediation activities and validate remediation effectiveness through rescanning and testing.
  • Provide guidance on software supply chain security, Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) creation, dependency management, and open-source software risk reduction.
  • Collaborate with Security Architecture, Cloud Security, Infrastructure Security, and Engineering teams to improve organizational security maturity.
  • Support vulnerability management processes, including finding triage, remediation validation, exception review, and security reporting.
  • Develop metrics, scorecards, dashboards, and executive reporting related to product security posture, vulnerability management, scan compliance, and remediation performance.
  • Assist development teams with secure design reviews, security-focused code reviews, and pre-release security assessments.
  • Evaluate emerging technologies, product and application security tools, software supply chain security capabilities, and artificial intelligence security solutions to identify opportunities for improving Brunswick's security posture.
  • Support security assessments, penetration testing activities, and remediation efforts for critical products based on business risk, regulatory requirements, or organizational priorities.

Benefits

  • medical
  • dental
  • vision
  • paid vacation
  • 401k (up to 4% match)
  • Health Savings Account (with company contribution)
  • well-being program
  • product purchase discounts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service