← Zurück zur Liste
Stelle · Senior

Product Security Engineer

Security Engineer • Senior • Remote • Vollzeit • Serbien Serbien

Action1 is looking for a Product Security Engineer to join the team securing its multi-tenant SaaS platform. A hands-on role working directly with developers to build security into the product. Fully remote.

Responsibilities

  • ▹Support the Product Security Incident Response Team (PSIRT) and vulnerability handling
  • ▹Validate, triage, track and coordinate security reports
  • ▹Provide practical remediation guidance to engineering teams
  • ▹Help validate security fixes and reduce product security risks
  • ▹Review code, APIs and system architecture to identify security issues early
  • ▹Conduct threat modeling and security design reviews
  • ▹Improve security automation within engineering workflows
  • ▹Support SAST, SCA, secrets scanning and other security controls
  • ▹Maintain software bills of materials (SBOMs), dependency visibility and remediation follow-up
  • ▹Support security assessments, vulnerability assessments and penetration testing
  • ▹Maintain vulnerability-handling playbooks, product security procedures and incident response runbooks

Requirements

  • ▹3+ years of experience in product security, application security, DevSecOps or a related cybersecurity field
  • ▹Strong software engineering background and the ability to work effectively with engineering teams
  • ▹Understanding of application, API, infrastructure and software supply chain security risks
  • ▹Experience applying cloud security concepts and practices
  • ▹Understanding of identity and access management, network security, logging, monitoring and secure cloud architecture patterns
  • ▹Familiarity with vulnerability management, incident response, security assessments and secure SDLC practices
  • ▹Experience with threat modeling and security design reviews
  • ▹Strong communication skills, including with external security researchers and vendors
  • ▹Ability to work independently and collaboratively in a fast-moving environment

Nice to have

  • ▹Genuine interest in cybersecurity and motivation to grow as a product security expert
  • ▹Hands-on experience with AWS security controls, best practices and architecture patterns
  • ▹Hands-on experience with C++ or JavaScript
  • ▹Security testing and automation using scripts, APIs, CI/CD pipelines or specialized tools
  • ▹Threat modeling for SaaS, API, cloud or on-premises product components
  • ▹Experience with SBOM generation, dependency visibility or software supply chain security

Soft skills

Communication with external researchers and vendorsIndependent and collaborative workClear thinkingOwnership

What we offer

  • ▹Fully remote work environment
  • ▹Work on a real-world security product used by IT and security teams
  • ▹High ownership and direct impact on product security practices
  • ▹Close collaboration with engineering, product and security teams
  • ▹A fast-growing software company with low bureaucracy
  • ▹Opportunity to improve security processes, automation and engineering workflows

About the company

Action1 is an autonomous endpoint management platform trusted by many Fortune 500 companies. It is cloud-native and free for the first 200 endpoints. In 2025 Inc. 5000 recognized it as the fastest-growing private software company in America.

Ähnliche Stellen