> Markdown version of [/jobs/ext/2622910-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2622910-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** SOHO Square Solutions - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cyber Security, OAuth, OpenID, Systems Development Life Cycle, Secure Coding, Session Management, Data Streaming, Software Vulnerability Management, Cloud Platform System, Software Security, Deep Web, Production Code, Virtual Agents, Devsecops, Static Application Security Testing - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/9a61b89e-f790-4b64-ae72-3270527b89a2 ## About the Role * 5+ years of cybersecurity/product security engineering experience. * Strong Product Security / Secure SDLC experience, including threat modeling, risk assessment, security requirements, and security design reviews. * Hands-on security experience across embedded/medical devices + cloud + application/API security. * Experience with AI/GenAI/Agentic AI, including building or developing AI agents, skills, or services. * Strong secure code review skills and ability to triage/tune SAST/SCA findings. * Deep web/API security knowledge - OAuth2/OIDC, authorization/IDOR, SSRF, session management, API security, etc. * SBOM & vulnerability management experience, preferably SPDX/CycloneDX and VEX/CSAF/OpenVEX. * Experience with DevSecOps/security tools such as SAST, SCA, secrets scanning, container and IaC scanning. * Experience in regulated product development, ideally medical devices/FDA. * Knowledge of FDA cybersecurity requirements, ISO 14971 and IEC 62304 is highly valuable. ## Description * Own Product Security Lifecycle - Security requirements, threat modeling, risk assessments, security testing, and security documentation. * Perform Threat Modeling - Analyze trust boundaries, data flows, attack surfaces, and abuse/misuse cases. * Security Architecture - Design security controls for devices, applications, APIs, and cloud environments. * Secure SDLC / DevSecOps - Implement SAST, SCA, secrets scanning, container/IaC scanning, and security gates. * AI Security & Development - Build/develop GenAI, Agentic AI skills, agents, and services and integrate them into product development. * Application/API Security - Hands-on with OAuth2/OIDC, authorization, IDOR, SSRF, session security, and API vulnerabilities. * Secure Code Review - Manually review production code and triage/tune SAST findings. * SBOM & Vulnerability Management - Manage SBOMs, VEX, dependency risks, vulnerabilities, and remediation SLAs. * Medical Device Compliance - Support FDA cybersecurity submissions, risk assessments, SBOMs, and audit documentation. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Accessibility Features in Chrome DevTools and beyond](https://www.wearedevelopers.com/videos/2077-accessibility-features-in-chrome-devtools-and-beyond) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [WeAreDevelopers LIVE – Keeping Up with Styles, Data & More](https://www.wearedevelopers.com/videos/1803-wearedevelopers-live-keeping-up-with-styles-data-more) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)