Product Security Engineer @Bloomreach
All Others
Salary eur 28,114 - 35..
Remote Location
Employment Type full-time
Posted 2wks ago

[Hiring] Product Security Engineer @Bloomreach

2wks ago - Bloomreach is hiring a remote Product Security Engineer. πŸ’Έ Salary: eur 28,114 - 35,143 per year πŸ“Location: Slovakia

Role Description

You will act as the designated security focus on a specific product domain, driving threat modeling, security assessments, and vulnerability management across Bloomreach's platform.

Your Job Will Be:

  • Support the implementation and adoption of Secure Software Development Lifecycle (SSDLC) practices across engineering teams, helping integrate security throughout the product development process.
  • Perform security reviews of application designs, system architectures, and infrastructure components, with guidance as needed, to identify security risks and recommend appropriate mitigations.
  • Participate in threat modeling exercises for new and existing products, helping identify threats, assess risk, and document practical security recommendations.
  • Provide security guidance to product and engineering teams by applying established security standards, patterns, and best practices, escalating complex security concerns when appropriate.
  • Conduct security assessments, penetration testing, and validation testing across applications and environments using established methodologies and processes.
  • Triage, validate, and assign vulnerabilities identified through security tools and assessments, working with the appropriate stakeholders to support timely remediation.
  • Collaborate with engineering, DevOps, compliance, and other cross-functional teams to address security requirements and support secure product development.
  • Develop knowledge of assigned product domains and serve as a security point of contact for routine security questions and activities, with support from senior security team members for complex or higher-risk matters.

Qualifications

  • 2+ years of hands-on experience in cybersecurity, application security, product security, or a related security discipline.
  • Practical experience performing or supporting security assessments and penetration testing of web applications.
  • Familiarity with threat modeling concepts and methodologies such as STRIDE, with the ability to identify common threats and security risks.
  • Understanding of vulnerability management fundamentals, including vulnerability validation, risk-based prioritization, remediation tracking, and retesting.
  • Exposure to AI and LLM technologies with an interest in developing knowledge of associated security risks and controls.
  • Working knowledge of modern application architectures, APIs, authentication and authorization mechanisms, and common application security considerations.
  • Knowledge of OWASP standards and resources, including the OWASP Top 10, Testing Guide, and secure development practices.
  • Hands-on experience with, or familiarity with, security testing tools such as Burp Suite, OWASP ZAP, Nmap, SAST/SCA tools, and other application security technologies.
  • Ability to analyze and validate security findings and prioritize vulnerabilities based on technical risk and business context, with guidance as needed.
  • Strong communication skills with the ability to clearly document findings and communicate technical concepts to engineering and other stakeholders.
  • Self-motivated and proactive, with a willingness to learn, take ownership of assigned tasks, and contribute to process improvements.
  • Team-oriented mindset with the ability to collaborate effectively with Security, Engineering, DevOps, and other cross-functional teams.
  • Continuous learning mindset with a strong interest in developing technical security expertise and staying current with emerging technologies and threats.
  • Excellent command of the English language, demonstrating strong listening, speaking, reading, and written communication skills.

Requirements

  • Develop a foundational understanding of Bloomreach's product portfolio, architecture, and core services within the first 30 days.
  • Become familiar with internal SOPs, security policies, standards, and Product Security team workflows within the first 30 days.
  • Gain working knowledge of the security tools, technologies, and platforms used by the Product Security team within the first 30 days.
  • Understand established processes for security assessments, threat modeling, vulnerability management, and penetration testing within the first 30 days.
  • Actively contribute to penetration tests and security assessments of web applications and product components within the first 60 days.
  • Participate in threat modeling sessions using methodologies such as STRIDE and contribute to identifying potential threats and design risks within the first 60 days.
  • Review and triage vulnerability data and security findings from scanning tools, manual testing, and other security sources within the first 60 days.
  • Independently perform well-defined security assessments and testing activities within the first 90 days.
  • Engage directly with Engineering teams to communicate security findings, support remediation efforts, and validate implemented fixes within the first 90 days.
  • Identify opportunities to improve team processes, documentation, tooling, or workflows and contribute to implementing those improvements within the first 90 days.

Benefits

  • A great deal of freedom and trust with flexible working hours.
  • Virtual-first work environment with several Bloomreach Hubs available across three continents.
  • Company events to experience the global spirit of the company.
  • 5 paid days off to volunteer.
  • People Development Program with personal development workshops.
  • $1,500 professional education budget on an annual basis.
  • Employee Assistance Program with counselors for non-work-related challenges.
  • Subscription to Calm - sleep and meditation app.
  • β€˜DisConnect’ days for additional time off each quarter.
  • Extended parental leave up to 26 calendar weeks for Primary Caregivers.
  • Restricted Stock Units or Stock Options based on role, seniority, and location.
  • Participation in the company's performance bonus.
  • Employee referral bonus of up to $3,000.
  • Celebration of work anniversaries - Bloomversaries.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Slovakia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Product Security Engineer @Bloomreach
All Others
Salary eur 28,114 - 35..
Remote Location
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Slovakia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,073+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later