> Markdown version of [/jobs/ext/1207051-senior-product-security-engineer-applications](https://www.wearedevelopers.com/jobs/ext/1207051-senior-product-security-engineer-applications). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Security Engineer (Applications) - **Company:** Astranis Space Technologies - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $180,000.0 - $285,000.0 - **Contract:** Permanent contract - **Skills:** C++ (Programming Language), Firmware, Joint Test Action (IEEE Standards), Python (Programming Language), Open Web Application Security, Secure Coding, Software Engineering, Universal Asynchronous Receiver/Transmitter, Web Applications, Web Services, Software Security, U-Boot, Service Stack - **Published:** July 8, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87075341/1 ## About the Role * 5+ years of experience in software engineering with a focus on security. * Strong investigative, analytical problem-solving skills and attention to detail. * Experience with secure architecture design and threat modeling for complex systems (including both web services and IoT/embedded devices). * Software development and security expertise in both high-level languages (e.g., Python) and low-level languages (e.g., C, C++). * Experience with security best practices for web applications (OWASP Top 10) and familiarity with embedded security concepts (e.g., secure boot, JTAG, UART). * Proven ability in auditing code for security flaws across different technology stacks. * Strong knowledge of security best practices, applied cryptography, and security frameworks. * Strong communication skills, with the ability to discuss security with both software and hardware engineers. * Ability to work collaboratively within a multi-disciplinary team environment. ## Description As a Senior Product Security Engineer, you will help secure both the software and embedded components that power our systems. This hybrid role focuses primarily on product/application security while contributing to embedded security reviews where software and hardware intersect. You will guide secure design, evaluate critical components, and partner closely with engineering teams across the stack to ensure our products are secure by default. This role does not expect deep hardware hacking but requires a broad security mindset to provide expertise where embedded systems and software meet., * Lead threat modeling, architecture reviews, and design-level risk assessments for both application and embedded system components. * Conduct secure code reviews for critical modules in Python and C/C++, supporting secure coding practices across all engineering teams. * Evaluate cryptographic usage, authentication/authorization flows, and protocol security across the stack. * Identify and prioritize vulnerabilities in software and firmware; partner with developers on remediation and mitigation strategies. * Participate in security assessments of embedded devices, especially where software interfaces with hardware. * Provide security input on high-level aspects of secure boot, firmware update integrity, and device identity mechanisms. * Partner with software, firmware, hardware, and systems teams to implement consistent, secure solutions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Rust Beyond Systems: Revolutionizing Web Development](https://www.wearedevelopers.com/videos/1111-rust-beyond-systems-revolutionizing-web-development) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)