
Senior Product Security Engineer – Taiwan
Obsidian Security6 hours ago
Taipei, TaiwanSenior
Responsibilities
- Perform security architecture, design, code, threat-modeling, and infrastructure reviews.
- Lead end-to-end CVE and vulnerability management, including exploitability analysis, prioritization, remediation, testing, deployment, and validation.
- Improve patch reliability through regression testing, staged rollouts, compatibility validation, rollback mechanisms, and monitoring.
- Strengthen CI/CD pipelines with dependency scanning, static analysis, container scanning, infrastructure-as-code scanning, secrets detection, and policy enforcement.
- Build software supply chain security controls for source code, dependencies, build systems, artifacts, containers, and deployment workflows.
- Design and build security features, reusable security libraries, services, automation, policies, and developer tools.
- Investigate product and infrastructure security incidents and lead corrective engineering work.
- Define security requirements, standards, metrics, release criteria, and exposure and remediation visibility.
- Mentor engineers and collaborate with Product Engineering, Platform Engineering, SRE, Security Research, and Infrastructure teams across regions.
Requirements
- Significant experience in product security, application security, security engineering, cloud security, or a closely related discipline.
- Deep knowledge of secure software development and application security risks including authentication, authorization, injection, insecure deserialization, secrets exposure, and data leakage.
- Strong hands-on software engineering skills in Python, Go, Java, Kotlin, TypeScript, or a comparable language.
- Experience securing cloud-native SaaS products, distributed systems, APIs, microservices, and data-processing platforms.
- Experience managing vulnerabilities and CVEs across dependencies, containers, operating systems, cloud services, and infrastructure components.
- Experience implementing security controls in CI/CD and software development workflows.
- Familiarity with SAST, DAST, software composition analysis, container scanning, secrets detection, and infrastructure-as-code scanning.
- Strong understanding of cloud security, containers, Kubernetes, infrastructure as code, identity and access management, networking, encryption, and secrets management.
- Experience with architecture reviews, threat modeling, secure code reviews, security testing, and security automation.
- Strong troubleshooting, written and verbal English communication, and cross-regional collaboration skills.
- Preferred experience includes cybersecurity, identity security, SaaS security, software supply chain security, SBOM management, artifact signing, policy-as-code, penetration testing, vulnerability research, incident response, and globally distributed engineering.
- Mandarin proficiency is a nice-to-have.
Tech Stack
Categories
About Obsidian Security
Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.