Skip to content
← Back to job listings

Product Security Engineer

Candid Health · Denver, United States

External listingfull-time2 months ago

About The Role

Join our team as a Product Security Engineer, where you will be a champion for security within our product engineering organization. You will work closely with development squads to perform threat modeling, guide secure architecture decisions, and automate security gates in our CI/CD pipelines. Your responsibilities will include leading threat modeling sessions, driving the adoption of secure development practices, managing vulnerabilities, building and maintaining security automation tools, developing secure coding standards, supporting incident response, and ensuring supply chain security. You should have proficiency in one or more programming languages, a deep understanding of modern web/cloud architecture, and at least 5 years of experience in software or security engineering.

  • Act as a champion for security within the product engineering organization, ensuring products are designed, developed, and maintained with security as a core pillar.
  • Lead threat modeling sessions during the architectural design phase of new features, drive the adoption of "Shift Left" security practices, and integrate security tooling into developer workflows.
  • Triage, prioritize, and partner with engineering teams to remediate vulnerabilities found in code, third-party libraries, and cloud infrastructure.
  • Proficiency in one or more programming languages (e.g., Python, Go, Java, or JavaScript)
  • Problem Solving: Strong analytical skills to evaluate complex systems and design innovative, practical security solutions
  • Deep understanding of modern web/cloud architecture (e.g., APIs, Microservices, Kubernetes, AWS/GCP/Azure)
  • Technical Skills:
  • Familiarity with the OWASP Top 10 and common exploitation techniques
  • Experience: 5+ years of experience in software engineering or security engineering, specifically focusing on product security or application security
  • Collaboration: Proven ability to influence and collaborate with engineering teams without hindering development velocity
  • Experience with Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation)
  • Experience in designing cryptographic implementations or secure authentication/authorization flows (e.g., OAuth, OIDC, JWT)
  • Knowledge of compliance frameworks relevant to our industry (e.g., SOC2, ISO27001, HIPAA)

This is an external listing. JobSpring does not represent or verify the employer. Report this listing