Job Openings Product Security Engineer (Vulnerability Management)

About the job Product Security Engineer (Vulnerability Management)

Job Title: Product Security Engineer (Vulnerability Management)
Experience: 5–8 Years
Job Type: Full Time
Notice Period: Immediate to 15 Days
Work Location: Remote

About the Role

We are looking for a highly skilled Product Security Engineer (Vulnerability Management) to join the Product Security Engineering team. In this role, you will work closely with engineering and product teams to reduce security risks across the Software Development Lifecycle (SDLC). You will be responsible for vulnerability management, application security reviews, secure development practices, security automation, and driving remediation efforts across engineering teams.

This is an excellent opportunity for security professionals passionate about application security, vulnerability assessment, secure coding practices, cloud security, and developer enablement.

Key Responsibilities

  • Triage, validate, prioritize, and manage security vulnerabilities identified through:
    • Manual security reviews
    • Automated security tools
    • Bug bounty programs
    • AI-powered security analysis platforms
  • Participate in security on-call rotations to support:
    • Security incident triage
    • Code reviews
    • Security consultations
  • Collaborate with engineering teams to:
    • Drive vulnerability remediation
    • Provide actionable security recommendations
    • Ensure timely closure of security findings based on risk
  • Review source code, pull requests, and design changes to identify security weaknesses before production deployment.
  • Analyze findings from AI-powered security agents, validate results, eliminate false positives, and improve remediation workflows.
  • Work closely with Product Security Architecture teams to enhance vulnerability detection, prioritization, and remediation processes.
  • Support security incident investigations and perform root cause analysis.
  • Develop security automation, tools, and workflows to improve application security coverage and reduce manual effort.
  • Administer and maintain vulnerability scanning platforms such as Tenable or equivalent tools.
  • Configure and optimize scanning policies, schedules, and reporting.
  • Track remediation progress, generate security metrics, and monitor organizational risk reduction initiatives.
  • Create security documentation, secure coding guidelines, and developer awareness materials.
  • Promote secure-by-design and secure-by-default engineering practices throughout the SDLC.

Required Skills & Experience

  • 5–8 years of experience in Application Security or Product Security.
  • Strong understanding of the Secure Software Development Lifecycle (SSDLC/SDLC).
  • Experience managing vulnerabilities from:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Dependency scanning
    • Penetration testing
    • Bug bounty programs
  • Hands-on experience reviewing source code and identifying application security vulnerabilities.
  • Strong knowledge of:
    • OWASP Top 10
    • API Security
    • Authentication & Authorization
    • Cryptography
    • Secrets Management
    • Secure Coding Practices
  • Experience with vulnerability management platforms and security scanning tools such as:
    • Tenable
    • SAST tools
    • DAST tools
    • SCA tools
    • IaC Scanning
    • Secrets Detection
  • Experience working with AWS Cloud and cloud-native architectures.
  • Ability to evaluate security findings, eliminate false positives, and communicate risk-based remediation recommendations.
  • Strong collaboration skills with engineering, DevOps, and product teams.
  • Excellent communication, documentation, and stakeholder management skills.
  • Experience handling vulnerability reports and coordinating remediation across multiple teams.

Preferred Skills

  • Experience with AI-assisted development workflows and AI-powered security platforms.
  • Knowledge of LLM security use cases and AI-based vulnerability analysis.
  • Experience building security automation and custom security tooling.
  • Understanding of DevSecOps practices and CI/CD security integration.
  • Experience working in large-scale cloud-native product environments.

Technical Skills

  • Application Security
  • Product Security
  • Vulnerability Management
  • Secure SDLC
  • Secure Code Review
  • SAST
  • DAST
  • SCA
  • OWASP Top 10
  • API Security
  • Penetration Testing
  • Bug Bounty Management
  • Tenable
  • AWS Security
  • DevSecOps
  • CI/CD Security
  • Vulnerability Scanning
  • Security Automation
  • AI Security
  • Risk Assessment
  • Security Incident Response

Soft Skills

  • Excellent communication and interpersonal skills
  • Strong analytical and problem-solving abilities
  • Cross-functional collaboration
  • Stakeholder management
  • Ability to prioritize work in a fast-paced environment
  • Strong documentation and reporting skills