Staff Product Security Engineer

On-siteSalary not specified

Tech Stack

CI/CDManual TestingAPI

Job Description, Responsibilities & Requirements

About the Position

Staff Product Security Engineer

We are looking for a Senior Product Security Engineer to join A365 Software Engineering, a division of Renesas, to enhance our cloud platform's security with a strong focus on vulnerability discovery and prevention.

Responsibilities

  • Security Regression Testing

    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling

    • Lead structured threat modeling sessions for:
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into:
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities

    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to:
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10–Driven Vulnerability Discovery

    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes

    • Review new features and changes for security risks
    • Ensure all changes are:
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck:
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement

    • Work closely with:
      • Engineering teams
      • Architecture
      • SRE / Platform teams
    • Contribute to secure-by-design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through:
      • Reusable patterns
      • Automation
      • Security guidance

Requirements

Required Qualifications

  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in:
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
    • Authentication, authorization, and session management
    • Multi-tenant architectures
    • Cloud-native systems

Preferred Qualifications

  • Experience in SaaS / multi-tenant platforms
  • Familiarity with:
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of:
    • AWS
    • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

We Offer

  • Competitive salary
  • Opportunity to work in a leading cloud platform for electronics design
  • Collaborative and innovative work environment

About the Company

Renesas is a global leader in semiconductor solutions, dedicated to transforming electronics design. By joining A365 Software Engineering, you will be part of a team that is revolutionizing the industry with our cloud platform, Altium 365 for cloud.

Job Details

Company name:
Altium Limited
Location:
Serbia
Employment Type:
Full-time
Work Mode:
On-site
Posted on TheJob:
Jul 13, 2026
Last checked:
Jul 13, 2026
Posted on the source:
Jul 3, 2026
Apply Now
© 2026 TheJob, Inc. All rights reserved.