Product Security Engineer improving security of Lattice’s applications and services through engineering partnerships and security operations. Contributing to secure coding practices and AI/LLM security assessments.
Responsibilities
Partner with engineers to identify, triage, and remediate security issues in product features and services
Participate in security reviews and threat modeling for new features and systems
Perform security-focused code reviews and help identify common vulnerabilities
Help implement and operate security tooling (SAST, DAST, dependency scanning, etc.)
Support vulnerability management workflows, including internal findings and bug bounty reports
Assist in investigating security issues and assessing risk and impact
Collaborate with platform and infrastructure teams to improve application and cloud security posture
Contribute to improving security practices in AWS-based environments
Assist in identifying and mitigating risks in AI/LLM-powered features, including prompt injection, data leakage, and unsafe output handling
Apply emerging best practices (OWASP Top 10 for LLM Applications) to real product use cases
Contribute to security guidance, documentation, and training for engineering teams
Help improve how security is integrated into the development lifecycle.
Requirements
1–3+ years of experience in product security, application security, or software engineering
Experience writing and maintaining code in JavaScript/TypeScript (or similar languages like Python or Ruby)
Familiarity with common web and API vulnerabilities (e.g., OWASP Top 10)
Exposure to security testing tools (SAST, DAST, dependency scanning, etc.)
Experience working in or with cloud environments (AWS or similar).
Senior Red Team Operator executing Red Team and Purple Team operations in Canada. Delivering scenario - driven operations in a continuously evolving cybersecurity landscape.
Director of Access Request Control at RBC establishing a framework for access request compliance. Collaborating across teams to streamline access and audit processes.
Product Owner driving evolving proactive security services portfolio across Risk Advisory, Application Security, and Cloud & AI Security. Collaborating with technology stakeholders to deliver high - value outcomes.
Loss Prevention Home Office Security Coordinator ensuring workplace safety and security for TJX Canada. Responsible for day - to - day monitoring and crisis management as a first responder.
Manager of Global Security and Safety at Genetec leading global security programs and protecting physical assets. Collaborating with executive leadership to implement risk - based security strategies.
Consultant managing complex cybersecurity projects remotely for Optiv in Vancouver. Establishing relationships and leading technology deployment in business continuity and resilience.
Product Manager directing the product roadmap and execution for OCIANA capabilities. Collaborating with stakeholders to enhance maritime security and operational decision - making.
Principal Business Information Security Officer at LastPass leading risk advisory and governance processes. Driving cross - functional collaboration to ensure scalable security frameworks in a competitive environment.
Cybersecurity Generalist role at PwC focusing on security solutions and cybersecurity practices. Leading projects and mentoring team members while identifying opportunities for the firm’s success.