Staff Product Security Engineer

SOHO Square Solutions
United States
9 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Cyber Security OAuth OpenID Systems Development Life Cycle Secure Coding Session Management Data Streaming Software Vulnerability Management Cloud Platform System Software Security
+5 more
Deep Web Production Code Virtual Agents Devsecops Static Application Security Testing

Job description

  • Own Product Security Lifecycle - Security requirements, threat modeling, risk assessments, security testing, and security documentation.
  • Perform Threat Modeling - Analyze trust boundaries, data flows, attack surfaces, and abuse/misuse cases.
  • Security Architecture - Design security controls for devices, applications, APIs, and cloud environments.
  • Secure SDLC / DevSecOps - Implement SAST, SCA, secrets scanning, container/IaC scanning, and security gates.
  • AI Security & Development - Build/develop GenAI, Agentic AI skills, agents, and services and integrate them into product development.
  • Application/API Security - Hands-on with OAuth2/OIDC, authorization, IDOR, SSRF, session security, and API vulnerabilities.
  • Secure Code Review - Manually review production code and triage/tune SAST findings.
  • SBOM & Vulnerability Management - Manage SBOMs, VEX, dependency risks, vulnerabilities, and remediation SLAs.
  • Medical Device Compliance - Support FDA cybersecurity submissions, risk assessments, SBOMs, and audit documentation.

Requirements

  • 5+ years of cybersecurity/product security engineering experience.
  • Strong Product Security / Secure SDLC experience, including threat modeling, risk assessment, security requirements, and security design reviews.
  • Hands-on security experience across embedded/medical devices + cloud + application/API security.
  • Experience with AI/GenAI/Agentic AI, including building or developing AI agents, skills, or services.
  • Strong secure code review skills and ability to triage/tune SAST/SCA findings.
  • Deep web/API security knowledge - OAuth2/OIDC, authorization/IDOR, SSRF, session management, API security, etc.
  • SBOM & vulnerability management experience, preferably SPDX/CycloneDX and VEX/CSAF/OpenVEX.
  • Experience with DevSecOps/security tools such as SAST, SCA, secrets scanning, container and IaC scanning.
  • Experience in regulated product development, ideally medical devices/FDA.
  • Knowledge of FDA cybersecurity requirements, ISO 14971 and IEC 62304 is highly valuable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:51 min

Setting the stage for local-first web development

Alexander Opalic Alexander Opalic · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all