BeyondTrust

Sr Product Security Engineer

BeyondTrust
Apply
14 hours ago
Remote, CanadaSenior

Responsibilities

  • Build, maintain, configure, and continuously improve product security tooling pipelines across the software development lifecycle.
  • Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security, Wiz CLI, and related code, secret, dependency, and container scanning tools.
  • Design automated product security review workflows with human-in-the-loop checkpoints for triage, risk classification, recommendations, and escalation.
  • Integrate security tooling with GitHub pull requests, CI/CD pipelines, IDE plugins, and developer dashboards while reducing false positives.
  • Build automation for code review triage, vulnerability detection, fix suggestions, policy enforcement, and security review summarization.
  • Support product incident response, investigation, impact scoping, emergency fixes, root cause analysis, and post-incident improvements.
  • Partner with Security Testers, Security Architects, the TPM, and engineering teams on findings, policies, reporting, configuration, and troubleshooting.

Requirements

  • At least 4 years of experience in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on security tooling and CI/CD experience.
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments.
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms.
  • Strong understanding of CI/CD pipeline architecture and integrating security controls without disrupting developer velocity.
  • Experience with scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration.
  • Familiarity with container security scanning tools and cloud security fundamentals, preferably AWS.
  • Knowledge of common vulnerability classes sufficient to tune tools, triage findings, and advise engineers on severity and remediation.
  • Preferred qualifications include GitHub Advanced Security at scale, CodeQL custom queries, Wiz CLI or similar scanning, incident response, OPA/Rego, Kyverno, endpoint or identity security, developer enablement, and AWS, Azure, or Kubernetes security experience.

Benefits

  • BeyondTrust describes a flexible, trust-based culture emphasizing continual learning, growth, diversity, and inclusion.

Categories

BeyondTrust

About BeyondTrust

1,001-5,000 employees

BeyondTrust builds identity and privileged access management software that controls admin rights, manages passwords and keys, and monitors privileged sessions across cloud and on-prem systems. The privately held company, founded in 1985 and headquartered in Johns Creek, Georgia, emerged after Bomgar acquired BeyondTrust and adopted its name. It serves more than 20,000 customers, including 75 of the Fortune 100, via enterprise subscriptions and partner channels.

Contact me