Senior Product Security Engineer

Posted 9 hours ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Product Security Engineer building AI-driven SDLC security tooling for BeyondTrust’s identity security SaaS. Automating reviews, integrating CI/CD controls, and supporting product incident response.

Responsibilities

  • Build and maintain the product security tooling pipeline across the software development lifecycle
  • Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security, and Wiz CLI across repositories and CI/CD pipelines
  • Configure policies and continuously improve security tooling for accurate, actionable feedback
  • Design and operate automated product security review workflows with human-in-the-loop checkpoints
  • Use Claude and LLM platforms for review triage, risk classification, recommendation generation, vulnerability detection, fix suggestions, policy enforcement, and summarization
  • Integrate security tooling into GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards
  • Reduce false positives and build feedback loops to improve findings
  • Support product incident response, investigation, impact scoping, emergency fixes, root cause analysis, and post-incident improvements
  • Partner with Security Testers, Architects, the TPM, and engineering teams
  • Provide security tooling configuration, troubleshooting, and support to engineering teams

Requirements

  • 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent)
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms
  • Strong understanding of CI/CD pipeline architecture and security-control integration
  • Experience with scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration
  • Familiarity with container security scanning tools and cloud security fundamentals
  • Understanding of common vulnerability classes, finding triage, severity, and remediation
  • Strong collaboration and communication skills
  • Automation-first mindset

Benefits

  • Culture of flexibility, trust, and continual learning
  • Growth recognition and opportunities for continual learning
  • Diversity and inclusion-focused workplace culture
  • Employee care and support

Job type

Full Time

Experience level

Senior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

Cloud

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.