> Markdown version of [/jobs/ext/2123002-software-product-security-engineer-3](https://www.wearedevelopers.com/jobs/ext/2123002-software-product-security-engineer-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Product Security Engineer 3 - **Company:** Megan Soft, Inc. - **Location:** Dearborn, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Spring Security, Amazon Web Services, Apache Tomcat, Applications Architecture, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, Configuration Management, Cyber Security, Data Integrity, Linux, DevOps, Web Development, Disaster Recovery, Java Platform Enterprise Edition (J2EE), Identity and Access Management, Information Systems Security Architecture Professional, JSON, JQuery, Python (Programming Language), Network Security, Microsoft Office, Network Protocols, Salesforce.Com, Secure Coding, Microsoft SharePoint, Software Engineering, TCP/IP, Web Applications, Pega, Data Logging, Scripting, Google Cloud, ReactJS, Spring-boot, Software Security, Technical Debt, Web Technologies, Dynatrace, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 19, 2026 - **Apply:** https://www.careerjet.com/jobad/us115755ca98c709ed8d57ff14ae195d7c ## About the Role Scripting, User Stories, Troubleshooting (Problem Solving), Data/Analytics dashboards, Software Development Lifecycle, Software Development, Web Development, TCP/IP, Data Integrity, Microsoft Office, Web Applications, Web Technologies, Cyber Security, Data Modeling, Developer, SharePoint, Web Design & Development Skills Preferred: Tooling, Disaster Recovery, Risk Management, Spring Security, Solution Architecture, Software Development Lifecycle, AIPGEE, Coding, JavaScript, KANBAN, Linux, Network Protocols & Standards, Penetration Testing, J2EE, Salesforce, Spring Boot, Change control , Cloud Computing, Dynatrace, Apache Tomcat, Application Development, Cloud Infrastructure, Computer Security, Google Cloud Platform, ISO 27001, Pega, Problem Solving, React, Application Architect, Burp Suite, Configuration Management, JQuery, Network Security, Java, Analytical skills, Application Design, Business Risk Mgt, IAM, Information Security, JSON, Python, Risk Assessment Experience Required: Engineer 3 Exp: Prac. In 2 coding lang. or adv. Prac. in 1 lang. 6+ years in IT; 4+ years in development Experience Preferred: Certifications are highly valued (CISSP, CISA, CISM, etc.) Additional Information : Overall, we are looking for someone who can understand the developer's perspective while also bringing a strong cybersecurity and risk-management mindset. The ideal candidate is someone who can sit in the middle, understand the technical details, work through the grey areas, and help the development/business teams arrive at the right security decision Thanks & Regards ## Description Guide development teams to triage and remediate findings from SAST, DAST, SCA, and bug bounty/vulnerability reports. Serve as a trusted liaison between engineering and security stakeholders, translating risk into practical, prioritized action. Consult on secure architecture, API security, IAM, logging, and secure coding practices across cloud platforms (Azure, GCP, AWS). Integrate and automate security testing within CI/CD pipelines alongside platform and DevOps teams. Help teams manage technical debt, upgrade paths, and software supply chain/SBOM risks. Communicate complex technical risk clearly to both engineers and business stakeholders - without creating panic or friction. This position will leverage broad experience and a jack of all trades in IT maybe an ideal candidate. The team handles compliance activities for cybersecurity, so experience there is a plus. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)