You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Tessera Labs

Senior Product Security Engineer

  • Remote
  • 6+ years

Salary

$50,000 - 60,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Remote in Brazil or LATAM

Responsibilities

  • We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.
  • This role partners closely with product engineering and platform engineering teams.
  • Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.
  • Lead security design and architecture reviews, and run threat modeling on new features and services.
  • Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.
  • Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
  • Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.
  • Help engineers understand the "why" behind findings so the same class of issue doesn't recur.
  • Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).

Requirements

  • A strong track record in product or application security — you've measurably made real products more secure.
  • Hands-on penetration testing experience against web applications and APIs.
  • Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).
  • Experience running security design reviews and threat modeling.
  • Solid understanding of the SDLC and how to embed security into it.
  • Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.
  • Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).
  • A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).
  • Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.
  • Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.
  • Background in enterprise or regulated environments where deployment security is non-negotiable.
  • What Success Looks Like (First 90 Days)
  • You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.
  • A repeatable, lightweight process exists for security design reviews on new work.
  • Security findings have a clear triage-to-remediation path, and developers know how to engage you early.

Conditions

Remote in Brazil or LATAM

About the company

Tessera Labs

Also hiring in San Jose, United States, New York City, United States, Seattle, United States and 2 more places

6 of their 15 open roles are remote

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 21 checks run
  • 4 red flags

Still hiring?

14 checks

2 red flags

How crowded?

7 checks

2 red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details10 facts · Role, Location, Compensation, Employment
Tech stack
  • AWS
  • Google Cloud
  • Kubernetes
  • Azure
Seniority
Senior
Type
Contract
Specialty
Security
Region
United States
Pay period
Annual
Show 4 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
6+ years
Tech stack
  • AWS
  • Google Cloud
  • Kubernetes
  • Azure

Location

Work model
Remote
Region
United States

Compensation

Salary
$50,000 - 60,000 / year
Pay period
Annual

Employment

Type
Contract

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason