Product Security Engineer
Indexed description
As a Product Security Analyst, you will be a key member of the team responsible for ensuring the security of Qualgo's products throughout their entire lifecycle. You will work closely with product managers, engineers, and the security team to integrate security into the design, development, testing, and deployment of our products. You will be a hands-on security expert, conducting threat modeling, security reviews, and providing guidance on secure coding practices. You will be a champion for "security by design" and help build a culture of security within the product development organization.
Key Responsibilities:
Threat Modeling:
- Conduct threat modeling sessions with product and engineering teams to identify potential security vulnerabilities in new and existing features.
- Specifically address threats relevant to VPN protocol vulnerabilities, server compromise, man-in-the-middle attacks, DNS leaks or E2EE weaknesses, message forgery, impersonation, account takeover.
- Develop and maintain threat models for all products.
Security Requirements Definition:
- Translate security best practices and regulatory requirements (e.g., Vietnamese cybersecurity laws, data privacy regulations) into concrete, actionable security requirements for product teams.
- Ensure that security requirements are incorporated into product specifications and user stories.
- Specifically address requirements related to blocking, anti-tracking, malware/phishing protection, parental controls and E2EE, secure messaging, group chats
Security Design Reviews:
- Review product designs and architectures to identify potential security flaws.
- Provide guidance to engineers on secure design principles.
- Ensure that security is considered at every stage of the design process.
- Specifically review designs related to VPN protocol implementation, server infrastructure, and client-side security features. Review E2EE implementation, key management, and authentication mechanisms.
Code Reviews (Security Focus):
- Conduct security-focused code reviews to identify vulnerabilities and ensure adherence to secure coding practices.
- Focus on areas of code relevant to security, such as authentication, authorization, encryption, data validation, and network communication.
Security Testing:
- Work with QA and engineering teams to develop and execute security tests, including penetration testing, vulnerability scanning, and fuzzing.
- Coordinate with external security researchers or penetration testing firms as needed.
- Specifically test VPN functionality, server security, and client-side security features. Test E2EE implementation, message integrity, and authentication mechanisms.
Secure Development Lifecycle (SDL):
- Promote and implement secure development lifecycle (SDL) practices throughout the organization.
- Develop and deliver security training to engineers.
- Develop and maintain secure coding guidelines.
Vulnerability Management:
- Track and manage security vulnerabilities identified in our products.
- Work with engineering teams to prioritize and remediate vulnerabilities.
Incident Response (Product Focus):
- Participate in incident response activities related to product security vulnerabilities.
- Contribute to post-incident analysis and lessons learned.
Collaboration:
- Work closely with product managers, engineers, designers, and security team.
- Communicate effectively with both technical and non-technical stakeholders.
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field. Master's degree
- Minimum of 4+ years of experience in product/app security engineer, penetration tester...
- Strong understanding of security principles and best practices.
- Experience with threat modeling methodologies (e.g., STRIDE, DREAD).
- Experience with secure coding practices and common security vulnerabilities (e.g., OWASP Top 10).
- Experience with security testing tools and techniques.
- Experience with VPN technologies, end-to-end encryption (E2EE) and messaging protocols is a strong plus.
- Experience with mobile application security (iOS and Android) is a plus.
- Experience with cloud security (AWS, GCP, Azure) is a plus.
- Experience working in an Agile environment.
Required skills:
- Excellent communication and collaboration skills.
- Ability to explain complex security concepts to non-technical audiences.
- Ability to work independently and as part of a team.
- Passion for building secure and trustworthy products.
- Fluency in English is a plus.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search