The Product Security Engineer is responsible for conducting comprehensive security assessments on various products, including mobile applications, IoT hardware/firmware, compiled software, and browser extensions.
Requirements
- Conduct comprehensive security assessments of mobile applications, IoT hardware / firmware, compiled software and browser extensions.
- Perform reverse engineering and vulnerability analysis, and penetration testing to uncover security risks.
- Analyze binary file formats (PE, ELF, Mach-O) and runtime behaviors for security flaws.
- Review browser extensions and software plugins for security flaws and compliance with best practices.
- Perform product data analysis to identify potential vulnerabilities and determine access scope.
- Collaborate with cross-functional teams to enhance security measures and improve resilience against cyber threats.
- Develop and recommend mitigation strategies and risk profiles for identified vulnerabilities.
- Document findings and communicate security recommendations to both technical and non-technical audiences.
- Maintain organizational product inventory with security assessment status and secure configuration requirements.
- Responsible for the production and maintenance of security documentation, such as bill of material repositories and analytical procedure guides.
Benefits
- Flexible time off and 11 paid holidays
- Family-building benefits, including Maternity, Adoption, and Parental Leave
- Tuition Reimbursement and certification support
- Wellness and Mental Health counseling services
- Concierge and work/life support resources