Staff Product Security Engineer
SOHO Square Solutions
United States
9 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Artificial Intelligence
Cyber Security
OAuth
OpenID
Systems Development Life Cycle
Secure Coding
Session Management
Data Streaming
Software Vulnerability Management
Cloud Platform System
Software Security
+5 more
Deep Web
Production Code
Virtual Agents
Devsecops
Static Application Security Testing
Job description
- Own Product Security Lifecycle - Security requirements, threat modeling, risk assessments, security testing, and security documentation.
- Perform Threat Modeling - Analyze trust boundaries, data flows, attack surfaces, and abuse/misuse cases.
- Security Architecture - Design security controls for devices, applications, APIs, and cloud environments.
- Secure SDLC / DevSecOps - Implement SAST, SCA, secrets scanning, container/IaC scanning, and security gates.
- AI Security & Development - Build/develop GenAI, Agentic AI skills, agents, and services and integrate them into product development.
- Application/API Security - Hands-on with OAuth2/OIDC, authorization, IDOR, SSRF, session security, and API vulnerabilities.
- Secure Code Review - Manually review production code and triage/tune SAST findings.
- SBOM & Vulnerability Management - Manage SBOMs, VEX, dependency risks, vulnerabilities, and remediation SLAs.
- Medical Device Compliance - Support FDA cybersecurity submissions, risk assessments, SBOMs, and audit documentation.
Requirements
- 5+ years of cybersecurity/product security engineering experience.
- Strong Product Security / Secure SDLC experience, including threat modeling, risk assessment, security requirements, and security design reviews.
- Hands-on security experience across embedded/medical devices + cloud + application/API security.
- Experience with AI/GenAI/Agentic AI, including building or developing AI agents, skills, or services.
- Strong secure code review skills and ability to triage/tune SAST/SCA findings.
- Deep web/API security knowledge - OAuth2/OIDC, authorization/IDOR, SSRF, session management, API security, etc.
- SBOM & vulnerability management experience, preferably SPDX/CycloneDX and VEX/CSAF/OpenVEX.
- Experience with DevSecOps/security tools such as SAST, SCA, secrets scanning, container and IaC scanning.
- Experience in regulated product development, ideally medical devices/FDA.
- Knowledge of FDA cybersecurity requirements, ISO 14971 and IEC 62304 is highly valuable.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
24 days ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago