> Markdown version of [/jobs/ext/677819-security-engineer-product-appsec](https://www.wearedevelopers.com/jobs/ext/677819-security-engineer-product-appsec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Product AppSec - **Company:** Veeam Software Corporation - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $237,800.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, JIRA, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Github, Python (Programming Language), Windows PowerShell, Systems Development Life Cycle, Security Software, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Policy as Code, Google Cloud, Enterprise Software Applications, Cloud Platform System, Software Security, Containerization, Gitlab-ci, Kubernetes, Information Technology, Terraform, Devsecops, Api Management, Docker, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 28, 2026 - **Apply:** https://www.dice.com/job-detail/9c056aa9-d134-45c2-801a-4b1fbb8cd020 ## About the Role * 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering * 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines * 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams * Strong experience with Secure SDLC, threat modeling, and software supply chain security * Experience building API integrations and workflow automation across security platforms * Bachelor's degree in Computer Science, Engineering, or equivalent experience Bonus Skills * Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper * Familiarity with AI/ML security risks and emerging AI application security practices * Demonstrated experience leading cross-functional security initiatives and influencing without direct authority * Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications ## Description We're looking for a Senior Product Security Engineer to advance the integration and operational maturity of enterprise application security tooling and vulnerability management across a modern software delivery environment. You'll serve as a senior technical contributor responsible for embedding security into the SDLC, improving developer security enablement, and driving scalable vulnerability management programs across cloud-native, enterprise, and AI-enabled products. This role works closely with Engineering, DevOps, Platform Engineering, Security Operations, and Compliance teams to improve visibility, automation, governance, and remediation workflows at scale. Security clearance is not required, but there is a slight chance it maybe requested in the future What You'll Do * Evaluate, deploy, integrate, and optimize security tooling - including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing - across CI/CD pipelines and developer workflows * Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools * Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards * Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments * Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security * Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience * Mentor engineers and security practitioners on secure development and DevSecOps best practices Technologies You'll Work With * CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI * Security tooling: SAST, DAST, SCA, IAST, CSPM tools, container scanning platforms * Cloud providers: Azure (primary), AWS, or Google Cloud Platform * IaC and containerization: Terraform, Kubernetes, Docker * Supply chain security: SLSA, Sigstore, SBOM tooling * Scripting and automation: Python, Bash, PowerShell ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)