> Markdown version of [/jobs/ext/1473056-cybersecurity-engineer-focused-on-product-security](https://www.wearedevelopers.com/jobs/ext/1473056-cybersecurity-engineer-focused-on-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer focused on Product Security - **Company:** CHAOS Industries - **Location:** El Segundo, United States - **Experience:** Expert - **Salary:** $110,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Bash Shell, BIOS, Cloud Computing, Code Review, CompTIA Security+, Cyber Security, Computer Engineering, DevOps, Firmware, Hardware Security Module, Python (Programming Language), Key Management, Windows PowerShell, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Architecture, Software Vulnerability Management, Data Processing, Scripting, Extensible Firmware Interface, Cloud Platform System, Software Security, Cyber Threat Analysis, SC Clearance, U-Boot, Devsecops, Vulnerability Analysis - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/9040b54b-9a49-4d7f-bcc1-a29c98a7f8ab ## About the Role * 5+ years of experience in cybersecurity engineering, product security, application security, or related engineering roles * Experience with software security design and secure system architecture principles * Hands-on experience conducting threat modeling and cybersecurity risk assessments * Knowledge of secure software development lifecycle (SSDLC) practices and application security concepts * Familiarity with cybersecurity frameworks and compliance standards including: * RMF * NIST 800-53 * NIST 800-171 * CMMC * DFARS * Experience supporting security authorization activities such as ATO processes and security documentation development, and eMASS * Understanding of cloud, endpoint, network, and identity security concepts * Strong analytical, troubleshooting, and technical communication skills * Ability to operate effectively in a fast-paced startup environment * Ability to obtain additional security clearances as required by contract Preferred Requirements: * Active Security Clearance * Experience supporting defense, aerospace, government contracting, or regulated technology environments * Experience securing embedded systems, sensor platforms, or edge computing technologies * Familiarity with export control requirements including ITAR and EAR * Experience with secure DevSecOps pipelines and automation practices * Experience with Microsoft GCC High environments and regulated cloud architectures * Firmware development experience * BIOS/UEFI security or development experience * Hardware security design experience * Trusted Platform Module (TPM), secure boot, cryptographic hardware, or supply chain security knowledge * Experience with scripting or automation using Python, PowerShell, or Bash * Security certifications such as CISSP, CSSLP, GSEC, Security+, or equivalent ## Description We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and secure our next-generation sensor platforms and supporting software ecosystems. This role will work closely with Software Engineering, Embedded Systems, Hardware Engineering, Infrastructure, and Program teams to ensure security is integrated throughout the product lifecycle - from architecture and development through deployment and operational support. The ideal candidate has experience securing complex software and hardware systems within defense, aerospace, or other highly regulated environments. This individual will lead software security architecture efforts, perform threat modeling and risk assessments, support compliance initiatives, and help establish secure engineering standards across the organization. This is a highly collaborative and hands-on role with direct impact on the security and resiliency of mission-critical technologies deployed in operational environments. Responsibilities: * Product Security Engineering + Design and implement secure software and hardware system architectures for mission-critical platforms and supporting infrastructure + Partner with engineering teams to integrate security requirements throughout the software development lifecycle (SDLC) + Conduct architecture reviews and identify security risks across software, embedded, cloud, and hardware systems + Develop secure design standards, engineering guidance, and product security best practices + Support secure development initiatives including code review, dependency management, secrets management, and vulnerability remediation * Threat Modeling & Risk Assessment + Lead threat modeling exercises for software, embedded systems, hardware platforms, and supporting infrastructure + Conduct cybersecurity risk assessments for products, systems, and operational environments + Identify attack surfaces, trust boundaries, and potential exploitation paths + Work with engineering teams to prioritize and remediate identified security risks + Develop mitigation strategies for cybersecurity threats impacting deployed systems and sensitive technologies * Compliance & Security Authorization + Support cybersecurity compliance initiatives and product authorization efforts including: + RMF (Risk Management Framework) + ATO (Authority to Operate) + Export control and regulated data handling requirements + Assist with development of system security documentation, security controls, SSPs, and assessment artifacts + Support internal and external security audits, assessments, and accreditation activities + Collaborate with government, customer, and program stakeholders on security requirements and authorization activities * Security Testing & Validation + Assist with security testing activities including vulnerability assessments, penetration testing coordination, and validation of remediation efforts + Support secure configuration and hardening efforts across software, operating systems, and embedded environments + Review software and system telemetry to identify potential security weaknesses or anomalous behavior + Collaborate with Security Operations and Infrastructure teams to improve enterprise and product security visibility * Cross-Functional Collaboration + Work closely with Software, Embedded, Hardware, DevOps, and Infrastructure teams to balance security, performance, and operational requirements + Contribute to the development of scalable product security processes and governance + Support customer and internal security reviews related to deployed technologies and operational environments + Mentor engineering teams on secure development and security-by-design principles ## Related Videos - [10M Data Records Lost, Underwater Computing, and Psychedelic Fish - Matthias Geniar](https://www.wearedevelopers.com/videos/1908-10m-data-records-lost-underwater-computing-and-psychedelic-fish-matthias-geniar) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Submit CFPs and Get into Public Speaking - Moran Weber](https://www.wearedevelopers.com/videos/2112-how-to-submit-cfps-and-get-into-public-speaking-moran-weber) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)