Senior Product Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Brazil
Remote
50K-60K Annually
Senior level
Artificial Intelligence • Information Technology • Software
The Role
Secure the product throughout its lifecycle by partnering with developers on security design and architecture reviews, threat modeling, penetration testing, secure code reviews, and security standards. Operate SAST, DAST, dependency, and supply-chain scanning tools; triage findings and guide remediation. Contribute security evidence to SOC 2 and ISO 27001 compliance efforts while improving developer security practices.
Summary Generated by Built In

Senior Product Security Engineer

The Role

We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.

This role partners closely with product engineering and platform engineering teams.

What You'll Do

  • Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.

  • Lead security design and architecture reviews, and run threat modeling on new features and services.

  • Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.

  • Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.

  • Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.

  • Help engineers understand the "why" behind findings so the same class of issue doesn't recur.

  • Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).

What You'll Need (Required)

  • A strong track record in product or application security — you've measurably made real products more secure.

  • Hands-on penetration testing experience against web applications and APIs.

  • Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).

  • Experience running security design reviews and threat modeling.

  • Solid understanding of the SDLC and how to embed security into it.

  • Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.

Nice to Have

  • Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).

  • A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).

  • Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.

  • Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.

  • Background in enterprise or regulated environments where deployment security is non-negotiable.

What Success Looks Like (First 90 Days)

  • You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.

  • A repeatable, lightweight process exists for security design reviews on new work.

  • Security findings have a clear triage-to-remediation path, and developers know how to engage you early.

Location and Work Model

Remote in Brazil

Skills Required

  • Strong track record in product or application security
  • Hands-on penetration testing experience against web applications and APIs
  • Deep understanding of modern web applications, APIs, authentication, authorization, sessions, and OWASP Top 10
  • Experience conducting security design reviews and threat modeling
  • Solid understanding of the software development lifecycle and embedding security into it
  • Strong communication skills for working directly with developers and explaining actionable risk
  • Familiarity with open-source security tooling such as OWASP ZAP, Burp Suite, Semgrep, Trivy, Grype, or Nuclei
  • Relevant offensive-security certification such as OSCP
  • Cloud security experience with AWS, Microsoft Azure, or Google Cloud Platform
  • Container or Kubernetes security experience
  • Experience supporting SOC 2, ISO 27001, or a similar compliance program
  • Background in enterprise or regulated environments
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, California
48 Employees
Year Founded: 2024

What We Do

Enterprise transformations shouldn't take years or cost fortunes. At Tessera, we've built a multi-agent AI platform that cuts ERP transformation timelines from years to weeks and reduces costs by more than half—while delivering first-time-right outcomes with enterprise-grade security and governance. We combine the dependability of a trusted integrator with the speed of an AI innovator. Our vendor-agnostic platform is pre-trained on thousands of enterprise landscapes and hundreds of years of expertise, so it adapts to your environment from day one—harmonizing systems and data to deliver secure, governed execution across ERP and other critical systems. Unlike traditional system integrators, ERP vendor tools, AI point solutions, or in-house builds, Tessera delivers transformations that compress timelines by 90%, replace people-heavy manual work with intelligent automation, ensure systems and data harmonize correctly from the start, and avoid vendor lock-in through adaptive intelligence that evolves with your workflows. Tessera creates lasting change in how your processes and systems operate together. As the platform adapts to your environment and evolves with new data, you gain the confidence to modernize with less risk—freeing up resources to reinvest in growth rather than maintaining legacy complexity. Proven in regulated industries. Built for enterprise reality. Reshaping how organizations transform.

Similar Jobs

Remote
Brazil
490 Employees

SailPoint Logo SailPoint

RVP of Strategic Sales- Brazil

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
Brazil
2461 Employees

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
São Paulo, BRA
29000 Employees

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
São Paulo, BRA
29000 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account