Staff Product Security Engineer

Auth21
Cambridge, UK
13 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Business Logic Software System Penetration Testing User Authentication Software as a Service Cloud Computing Continuous Integration Open Web Application Security Regression Testing Red Team (Cyber Security) Web Application Security
+7 more
Session Management Software Engineering Data Streaming Software Security Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention.

The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do., * Security Regression Testing

  • Design and maintain security regression test suites covering critical application flows
  • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
  • Integrate security regression into CI/CD pipelines
  • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
  • Lead structured threat modeling sessions for: o Existing system components o New features and architectural changes

  • Identify attack surfaces, abuse cases, and trust boundaries
  • Translate threats into: o Test cases o Security requirements o Mitigation plans

  • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
  • Perform manual and automated security testing simulating real attacker behavior
  • Focus on high-impact vulnerabilities, not theoretical findings
  • Validate exploitability and business impact
  • Partner with engineering teams to: o Reproduce issues o Prioritize fixes o Validate remediation

  • OWASP Top 10-Driven Vulnerability Discovery
  • Continuously assess the platform against OWASP Top 10 categories
  • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
  • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
  • Review new features and changes for security risks
  • Ensure all changes are: o Threat-modeled o Covered by regression tests

  • Act as a security gatekeeper without becoming a bottleneck: o Enable teams with guidance and tooling o Avoid heavy process overhead

  • Collaboration & Enablement
  • Work closely with: o Engineering teams o Architecture o SRE / Platform teams

  • Contribute to secure-by-design practices
  • Support developers in understanding and fixing vulnerabilities
  • Help scale security through: o Reusable patterns o Automation o Security guidance

Requirements

  • 5+ years in Application / Product Security
  • Bachelor’s Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in:
  • Web application security testing
  • API security
  • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
  • Manual penetration testing
  • Security regression testing
  • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
  • Authentication, authorization, and session management
  • Multi-tenant architectures
  • Cloud-native systems, * Experience in SaaS / multi-tenant platforms
  • Familiarity with:
  • Bug bounty programs
  • Red teaming
  • Security automation frameworks
  • Knowledge of:
  • AWS
  • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

Benefits & conditions

We believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process. #J-18808-Ljbffr

About the company

Altium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software-defined world with our industry-first cloud-based platform that unites every stakeholder and phase of electronics development.

From startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

1:32 min

Decoupling business logic with policy as code

Anderson Dadario +1 · LIVE

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:52 min

Anchoring models to specialized enterprise business logic

Damir Dobric · Coffee With Developers

Videos

See all

Related articles

See all