Senior Product Security Engineer
Indexed description
The salary range for this role is $160,000 to $200,000 commensurate with experience and skills.
What You Will Do
Product security strategy & architecture
- Lead security design and architecture reviews for new and existing products, including web, mobile, and cloud-based custom applications, and provide clear, actionable recommendations
- Support the security of UTA’s custom-built digital products and platforms, including web applications, cloud services, agentic workflows, data-driven tools, AI-enabled business tools, and custom tools used by employees, business teams, and external partners and clients - from design through deployment and ongoing operation
- Partner with product and engineering leadership to define product security requirements, risk tolerances, and security roadmaps across multiple teams and initiatives
- Conduct and facilitate threat modeling workshops to proactively identify emerging risks and attack vectors and drive mitigations into product design
- Conduct security reviews for products and services deployed across AWS, Azure, and GCP including cloud-native architectures, and platform-specific security controls
- Own and mature the application and product security lifecycle, including threat modeling, secure design, secure coding practices, testing, and release validation
- Assess and secure early-stage product design, architecture and workflows, associated with rapid prototyping and deployment
- Drive the adoption of automated security checks in CI/CD pipelines (SAST, DAST, SCA, secrets scanning, etc.) and ensure they are tuned to balance risk reduction with developer velocity
- Lead and coordinate application security testing efforts, including tool-based and manual reviews, and work closely with development teams to prioritize and remediate findings
- Establish and evangelize secure coding standards, patterns, and reusable frameworks that can be leveraged across engineering teams
- Lead API security assessments, including authentication/authorization validation for REST/GraphQL APIs and API gateway configuration reviews
- Help establish security controls for AI-assisted software development, including AI-generated code review, agent-driven pull requests, dependency integrity, secrets prevention, and secure use of coding assistants such as Claude Code, Cursor, GitHub Copilot, or similar tools.
- Collaborate with security operations to ensure product-related logs, alerts, and events are captured, correlated, and integrated into monitoring and incident response workflows
- Own vulnerability triage and management for product and application findings, including those surfaced through penetration tests and attack surface monitoring, covering risk assessment, remediation planning, and validation of fixes
- Ensure products handle sensitive data appropriately, including data classification, storage, transit, and retention practices aligned with organizational security requirements
- Evaluate, select, and help implement product security focused tools and services, influencing build vs buy decisions
- Develop documentation, playbooks, and training to raise the overall level of security awareness and capability across product and engineering teams
- Provide best practices on the secure use of AI-assisted development tools, including risks around dependency integrity, code suggestions, and agent-driven changes
- Partner with engineering, DevOps, and security operations to mature vulnerability operations, including reachability-based prioritization, AI-assisted triage and remediation, developer-native fix workflows, and automated validation that critical attack paths have been closed
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field; or equivalent practical experience
- 5+ years of experience in security engineering, application security, or product aligned security roles, with a track record of owning and driving security initiatives
- Deep understanding of common web, mobile, and API vulnerabilities (e.g., OWASP Top 10) and practical experience preventing and remediating them at scale
- Strong experience securing applications and services in at least one major cloud provider (AWS preferred), including cloud native architectures
- Hands on experience with application security tooling (SAST, DAST, SCA, secret scanning, WAF, or similar) and integrating these into CI/CD workflows
- Familiarity with secure deployment practices, including Infrastructure-as-Code review of Terraform, CI/CD pipeline security (GitHub Actions), and secrets management.
- Familiarity with container security, including image hardening, Kubernetes RBAC, network policies, and runtime protection.
- Familiarity with securing AI/ML platforms in cloud environments and agentic workflows, including access control, data protection, and governance across the application development and deployment lifecycle.
- Solid experience collaborating with software engineering teams in agile environments, including participating in design reviews, code reviews, and sprint planning
- Strong knowledge of identity, authentication, and authorization concepts and technologies (e.g., OAuth, OIDC, SSO, modern identity platforms)
- Excellent communication and stakeholder management skills, with the ability to influence senior technical and nontechnical partners and drive consensus
- The unique and exciting opportunity to work at one of a leading global entertainment companies
- Access to the tools, leadership, and resources you will need to create and drive a center of excellence
- The opportunity to do the best work of your career
- Work in an inclusive and diverse company culture
- Competitive programs to support your well-being
- Experience working in a collaborative environment with room to grow
For more information: https://www.unitedtalent.com/about/
UTA and its Affiliated Companies are Equal Employment Opportunity employers and welcome all job seekers.
https://www.unitedtalent.com/privacy-policy
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search