Product Security Engineer
Indexed description
Product Security Engineer
An innovative technology organization is expanding its cybersecurity capabilities and is seeking a Product Security Engineer to help shape and mature security practices across a growing portfolio of connected products and industrial technologies.
This role will focus on integrating security throughout the product development lifecycle, partnering with engineering teams to identify risks, define security requirements, and architect solutions that protect both software and hardware platforms operating in critical environments. The position offers significant influence over security strategy, tooling, processes, and technical direction.
Key Responsibilities
- Lead product security initiatives across the full product development lifecycle, from concept and design through deployment and ongoing support.
- Conduct threat modeling exercises and security assessments for software, firmware, embedded systems, and connected devices.
- Define and implement secure-by-design principles for industrial and IoT-enabled technology platforms.
- Identify, assess, communicate, and mitigate product security vulnerabilities.
- Collaborate with architecture, engineering, compliance, and product teams to align security requirements with business objectives.
- Develop security standards, processes, and best practices for product engineering teams.
- Support security reviews for new features, integrations, communications protocols, and connected systems.
- Evaluate and recommend security tools, monitoring solutions, and vulnerability management approaches.
- Partner with development teams to integrate security controls into engineering workflows and release processes.
- Assist with incident response, risk assessments, and remediation planning related to product security concerns.
- Contribute to the development of long-term product security roadmaps and security maturity initiatives.
Required Qualifications
- Experience leading or owning product security initiatives within software, embedded systems, industrial technology, or connected device environments.
- Strong understanding of secure software development lifecycle (SSDLC) principles and application security practices.
- Hands-on experience conducting threat modeling exercises using industry-recognized methodologies such as STRIDE or similar frameworks.
- Ability to identify vulnerabilities within software, firmware, and product architectures and effectively communicate remediation strategies.
- Experience securing connected products, operational technology (OT), industrial control environments, IIoT platforms, or cyber-physical systems.
- Strong knowledge of security architecture, vulnerability management, risk assessment, and secure design principles.
- Experience collaborating with technical and non-technical stakeholders, including leadership teams and executive audiences.
- Excellent communication, documentation, and relationship-building skills.
Preferred Qualifications
- Experience with industrial automation, connected devices, smart infrastructure, energy systems, manufacturing environments, or operational technology networks.
- Familiarity with security monitoring, SIEM platforms, vulnerability scanning tools, or threat detection technologies.
- Experience developing product security programs or maturing security practices within engineering organizations.
- Knowledge of compliance and regulatory requirements relevant to connected technologies and critical infrastructure environments.
- Experience working alongside software development, systems engineering, architecture, and compliance teams.
Ideal Candidate Profile
Successful candidates will demonstrate:
- A growth mindset and passion for continuous learning
- Strong leadership and mentoring capabilities
- Ability to influence without direct authority
- Excellent emotional intelligence and stakeholder management skills
- A collaborative, team-first approach
- Strong problem-solving and strategic thinking abilities
- Comfort operating in evolving environments and building new processes from the ground up
Work Environment
- Highly collaborative environment working with cybersecurity, engineering, compliance, product management, and systems teams.
- Opportunity to help establish and mature security practices within a rapidly growing organization.
- Flexible work environment with a preference for candidates located within reasonable proximity to company operations.
- Hybrid work model with regular in-person collaboration opportunities.
Employment Details
- 6 months contract-to-hire opportunity with long-term growth potential.
- Immediate project needs with flexibility around start dates.
- Strong opportunity for career advancement as the cybersecurity organization continues to expand.
- Opportunity to make a significant impact on the security architecture of next-generation connected products and platforms.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search