> Markdown version of [/jobs/ext/2824688-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2824688-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** Auth21 - **Location:** Cambridge, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Software as a Service, Cloud Computing, Continuous Integration, Open Web Application Security, Regression Testing, Red Team (Cyber Security), Web Application Security, Session Management, Software Engineering, Data Streaming, Software Security, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2859577034-staff-product-security-engineer ## About the Role * 5+ years in Application / Product Security * Bachelor's Degree or equivalent of 12 years of work experience * Strong hands-on experience in: + Web application security testing + API security + Threat modeling methodologies * Deep understanding of OWASP Top 10 * Experience with: + Manual penetration testing + Security regression testing + CI/CD security integration * Ability to identify business logic vulnerabilities * Strong understanding of: + Authentication, authorization, and session management + Multi-tenant architectures + Cloud-native systems, * Experience in SaaS / multi-tenant platforms * Familiarity with: + Bug bounty programs + Red teaming + Security automation frameworks * Knowledge of: + AWS + Identity systems and federation (SSO, MFA) * Background in software engineering (ability to read/write code) ## Description We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention. The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do., * Security Regression Testing + Design and maintain security regression test suites covering critical application flows + Ensure vulnerabilities, once fixed, are permanently prevented from recurring + Integrate security regression into CI/CD pipelines + Define coverage targets for security-critical areas (auth, access control, APIs, data flows) * Threat Modeling + Lead structured threat modeling sessions for: o Existing system components o New features and architectural changes + Identify attack surfaces, abuse cases, and trust boundaries + Translate threats into: o Test cases o Security requirements o Mitigation plans + Ensure threat modeling becomes a continuous lifecycle activity * Offensive Security / Red Team Activities + Perform manual and automated security testing simulating real attacker behavior + Focus on high-impact vulnerabilities, not theoretical findings + Validate exploitability and business impact + Partner with engineering teams to: o Reproduce issues o Prioritize fixes o Validate remediation * OWASP Top 10-Driven Vulnerability Discovery + Continuously assess the platform against OWASP Top 10 categories + Use deep product knowledge to find non-obvious, context-specific vulnerabilities + Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths * Security Assurance for Product Changes + Review new features and changes for security risks + Ensure all changes are: o Threat-modeled o Covered by regression tests + Act as a security gatekeeper without becoming a bottleneck: o Enable teams with guidance and tooling o Avoid heavy process overhead * Collaboration & Enablement + Work closely with: o Engineering teams o Architecture o SRE / Platform teams + Contribute to secure-by-design practices + Support developers in understanding and fixing vulnerabilities + Help scale security through: o Reusable patterns o Automation o Security guidance ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Algorithm That Nearly Killed Me: When Testing Isn't Enough](https://www.wearedevelopers.com/videos/2110-the-algorithm-that-nearly-killed-me-when-testing-isn-t-enough) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Where we're going we don't need JavaScript - Programming with Type Annotations](https://www.wearedevelopers.com/videos/455-where-we-re-going-we-don-t-need-javascript-programming-with-type-annotations) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)