Obsidian Security

Senior Product Security Engineer – Taiwan 

Obsidian Security
Apply
6 hours ago
Taipei, TaiwanSenior

Responsibilities

  • Perform security architecture, design, code, threat-modeling, and infrastructure reviews.
  • Lead end-to-end CVE and vulnerability management, including exploitability analysis, prioritization, remediation, testing, deployment, and validation.
  • Improve patch reliability through regression testing, staged rollouts, compatibility validation, rollback mechanisms, and monitoring.
  • Strengthen CI/CD pipelines with dependency scanning, static analysis, container scanning, infrastructure-as-code scanning, secrets detection, and policy enforcement.
  • Build software supply chain security controls for source code, dependencies, build systems, artifacts, containers, and deployment workflows.
  • Design and build security features, reusable security libraries, services, automation, policies, and developer tools.
  • Investigate product and infrastructure security incidents and lead corrective engineering work.
  • Define security requirements, standards, metrics, release criteria, and exposure and remediation visibility.
  • Mentor engineers and collaborate with Product Engineering, Platform Engineering, SRE, Security Research, and Infrastructure teams across regions.

Requirements

  • Significant experience in product security, application security, security engineering, cloud security, or a closely related discipline.
  • Deep knowledge of secure software development and application security risks including authentication, authorization, injection, insecure deserialization, secrets exposure, and data leakage.
  • Strong hands-on software engineering skills in Python, Go, Java, Kotlin, TypeScript, or a comparable language.
  • Experience securing cloud-native SaaS products, distributed systems, APIs, microservices, and data-processing platforms.
  • Experience managing vulnerabilities and CVEs across dependencies, containers, operating systems, cloud services, and infrastructure components.
  • Experience implementing security controls in CI/CD and software development workflows.
  • Familiarity with SAST, DAST, software composition analysis, container scanning, secrets detection, and infrastructure-as-code scanning.
  • Strong understanding of cloud security, containers, Kubernetes, infrastructure as code, identity and access management, networking, encryption, and secrets management.
  • Experience with architecture reviews, threat modeling, secure code reviews, security testing, and security automation.
  • Strong troubleshooting, written and verbal English communication, and cross-regional collaboration skills.
  • Preferred experience includes cybersecurity, identity security, SaaS security, software supply chain security, SBOM management, artifact signing, policy-as-code, penetration testing, vulnerability research, incident response, and globally distributed engineering.
  • Mandarin proficiency is a nice-to-have.
Obsidian Security

About Obsidian Security

201-500 employees

Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.

Contact me