Senior Product Security Engineer
- AI
- GCP
- Terraform
- Java
- DevSecOps
- CI/CD
- SAST
- Python
Essential Responsibilities:
- Independently apply security best practices to enhance and optimize systems, ensuring robust protection and efficiency, while beginning to understand and align security solutions with business objectives.
- Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture.
- Analyze and resolve security challenges by adapting standard processes and exploring alternative approaches to address complex threats.
- Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
- Collaborate with other engineers to gather and incorporate feedback, driving continuous improvements in security processes.
Minimum Qualifications:
- 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.
Experience with SLSA, software bills of materials (SBOMs), provenance, artifact signing or verification, package repositories, or dependency governance.Â
Experience creating or tuning rules for static analysis,secrets detection, or policy-as-code systems.Â
Familiarity with security considerations for AI/LLM development tools, AI-assisted coding, or model and tool supply chains.Â
Experience with GCP, complemented by hands-onexpertise withKubernetes, Terraform, and other cloud-native technologies.Â
Familiarity in other programming and scripting languages, such as Java andJavascript, with the ability to troubleshoot codeÂ
Experience using telemetry and metrics to improve security tooling at scale, including coverage, quality, performance, adoption, or remediation outcomes.
3-5 minimumyears of relevant experience in software engineering,application or product security,DevSecOps, or cybersecurity, and aBachelor’s degree or an equivalent combination of education and experience.Â
Experience developing, integrating, oroperating security automation in CI/CD or developer workflows, including one or more of SAST, SCA,secrets detection, or software supply chain security.Â
Programming or scripting experience inmultiple languages such as Python, Go,andBash,with the ability to write, review, and troubleshoot code.Â
Working knowledge of secure software development, common application vulnerabilities, dependency and package ecosystem risks, and practical remediation approaches.Â
Ability to work independently and collaborate with software, platform, and security teams, with clear written and verbal communication of technical findings and tradeoffs.Â
Additional Responsibilities
Build andoperate scanning and guardrail capabilities across source control, CI/CD, package ecosystems, and developer platforms.Â
Tune SAST, SCA, and supply chain controls; investigate gaps and false positives and improve remediation guidance.Â
Write and review code, APIs, detection rules, and automation that process findings and enforce security policy.Â
Partner with developers, platform engineers, and security teams to troubleshoot integrations and deliver practical improvements.Â
Evaluate new technical surfaces, including AI/LLM tools, and help defineappropriate security controls.Â
Use metrics and feedback to improve reliability, coverage, performance, adoption, and remediation outcomes.Â
Senior Product Security Engineer · PayPal