Skip to content
← Back to job listings

Staff Product Security Engineer

Navan · San Francisco, United States

External listingfull-timeabout 2 months ago

About The Role

Join Navan as a Staff Product Security Engineer, where you will be responsible for securing our products by identifying risks early in the software development lifecycle (SDLC) and developing application security tooling and processes. You will lead the building and scaling of our application security program, ensuring the continuous security of customer-facing products and internal tools. This position requires advanced technical leadership, strong communication skills, and the ability to influence people at all levels of the organization.

  • Identifying risks early in the Software Development Life Cycle (SDLC) and developing application security tooling & processes to promote a ‘shift left’ security culture.
  • Defining and scaling the product security function by integrating security in the application development process, conducting security-related research and assessments, and developing custom automated security solutions.
  • Leading the building and scaling of an application security program, ensuring the continuous security of customer-facing products and internal tools, and driving the expansion and maturation of the Navan S-SDLC program across the organization.
  • Proven experience performing application, cloud and mobile penetration testing in high risk environments like financial or healthcare companies
  • Cloud environment (AWS, or similar)
  • Java Spring Framework (3+ years), Hibernate or similar ORM technologies, JavaScript/CSS, and Angular
  • Source code management (GitHub, or similar.)
  • Application security testing tools (SAST, DAST, IAST, SCA, or similar.)
  • Ability to provide pragmatic security advice for web applications, mobile applications, and cloud software
  • Integration of Security testing tools into CI pipelines
  • Experience working in Agile development with experience in technologies such as:
  • Deep knowledge of cloud operational models and secure SaaS architecture in a containerized microservices world
  • Continuous integration (Jenkins, Github Actions or similar)
  • Proven ability to mentor junior engineers and lead cross-functional initiatives in multifaceted and highly technical organizations
  • Proven experience delivering critical org-wide product security initiatives
  • 8-10+ years of Technical Product Security experience with a proven track record of system-wide impact in SSDLC tooling, automation, and threat modeling/attack surface analysis
  • Containers (Docker, Kubernetes, or similar)
  • Defect tracking (Jira,or similar.)
  • In-depth knowledge of common application & network protocols, cryptographic primitives, authentication & authorization protocols, and common security threats, such as attack techniques, evasive techniques, and preventative & defensive methods
  • Infrastructure as code (Terraform, or similar)
  • Proven experience performing threat modeling and architecture reviews for complex applications

This is an external listing. JobSpring does not represent or verify the employer. Report this listing