Product Security Engineer
Worldwide
Key Responsibilities: Security Engineering & Automation Automate Everything: Develop custom automation to manage security processes and implement "Secure-by-Design" processes in the CI/CD pipeline using Python. Container Security: Identify, design, and implement controls to safeguard our containerized production environments. Tooling Management: Deploy and manage product security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). Threat Modeling: Review technical designs for new features, leading threat models to prioritize risks and educate developer teams on secure coding practices. Customer Trust & Vulnerability Management Threat Assessment & Security Analysis: Conduct and automate end-to-end vulnerability, threat, and exploitability assessments for actionable fixes and mitigations in DataRobot products. Incident Response: Perform initial technical investigation for customer reports and security incidents, coordinating with Engineering and IT Security to validate and track fixes. Customer Engagement: Work directly with Sales & Support teams to resolve concerns regarding security exposure and architecture. Customer-Centric Communication: Balance business needs with security rigor. You must be able to stand firm on security policies while maintaining strong professional relationships through clear, diplomatic, and solutions-oriented communication. Knowledge, Skills, and Abilities: Technical Proficiency: Fluent in writing code using Python to build security automation. Must have a deep understanding of Linux containers (internals, security isolation). Experienced in Git-based collaboration and automating software delivery through CI/CD integration (Jenkins, Harness, or GitHub Actions). Familiarity with Kubernetes orchestration is strongly preferred. Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite. Ability to reproduce vulnerabilities in a lab environment to demonstrate impact. Strong ability to perform manual code reviews or AI assisted reviews in Python, Go, and Node.js, looking for flaws that automated tools might miss (e.g., broken access control or insecure business logic). Leveraged AI-driven automation to accelerate secure code development and scale security assessments across the SDLC. Independence: Ability to work independently on complex technical tasks with minimal supervision, while knowing when to escalate architectural decisions to Senior and Staff engineers. Strategic Mindset: Experience determining not just how to fix a bug, but why and how it happened and then automate how to prevent it systemically. Soft Skills: Strong communication skills for guiding teams and liaising with various stakeholders. Requisite Education and Experience: 3 to 5 years of experience working in Product Security or Application Security roles. Bachelor's in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience).
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
$17.00
-
$25.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:5 to 10
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- PolandWarsaw6:21 PM
- $1K total spent1 hire, 0 active
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by