> Markdown version of [/jobs/ext/105865-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/105865-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** SoundCloud - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Data Analysis, JIRA, Software as a Service, Data Governance, Github, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Soundcloud, Ruby, Secure Coding, Software Engineering, SQL Databases, Software Vulnerability Management, Google Cloud, DevOps Tools - Open-source, Software Security, Generative AI, Cloudformation, Infrastructure Automation Frameworks, Hardware Infrastructure, Terraform, Static Application Security Testing, Golang - **Published:** May 20, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=bd1524f7aad3e1a5 ## About the Role Do you have experience in Terraform?, * 8+ years of product or application security experience, or other relevant software engineering experience * Deep expertise in designing secure architecture * Enthusiasm about collaborating with engineering and product teams to proactively address security issues in products * Experience conducting threat modeling exercises and secure code reviews * Experience configuring DevSecOps tools (e.g. SAST, SCA, Secret Scanning) * Experience managing bug bounty programs * Familiarity with languages such as Javascript, Go, Ruby, Python, or Scala * Experience working with cloud providers (AWS, GCP) and Developer SaaS solutions (GitHub, Jira) * Familiarity with IaC tools such as Terraform and CloudFormation * Ability to effectively communicate risk to technical and non-technical audiences * Experience with data analysis (SQL) in order to determine scope and impact of vulnerabilities * Knowledge of industry-standard security frameworks and regulations, such as GDPR, CCPA, SOC2, NIS2, and OWASP is a plus * Experience with vulnerability management is a plus * Experience threat modelling and securing Generative AI applications & use-cases in the context of the EU AI Act is a plus * Experience with data governance is a plus ## Description SoundCloud empowers artists and fans to connect and share through music. Founded in 2007, SoundCloud is an artist-first platform empowering artists to build and grow their careers by providing them with the most progressive tools, services, and resources. With over 400+ million tracks from 40 million artists, the future of music is SoundCloud. We are looking for a Principal Product Security Engineer to join our Security team! As a Product Security Engineer, you will collaborate cross-functionally with engineering teams to identify and address potential vulnerabilities in our products and services. You will advocate and shape security best practices across SoundCloud's Engineering, Product, and Design ("EPD") organization. This position offers a unique opportunity to play a direct, pivotal role in safeguarding our products against emerging cyber threats to our platform, artists and creators, and listeners and fans., * Identify security anti-patterns in our codebases and architecture and drive cross-functional initiatives to systemically address them * Help guide our Engineering and Product teams around the safe and responsible use of agentic AI in our products and Software Development Lifecycle (SDLC) * Drive efforts to automate the security of our SDLC, including our CI/CD pipelines * Secure our AWS, GCP, and on-prem infrastructure through implementing proper access control and guardrails * Conduct secure code reviews and threat modeling exercises to identify and remediate potential security vulnerabilities * Define, implement, and oversee processes and policies in our Vulnerability Management Program * Triage and drive to remediation submissions from our external bug bounty program * Participate in our security incident response process * Make recommendations to external teams and stakeholders about how to improve the consumer security of our platform * Promote security best practices through educational initiatives such as CTFs and technical talks * Improve internal tooling, processes, and documentation * Help to define the Product Security program and team strategy * Mentor and onboard team members ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)