GrepJob
SoundCloud

Principal Product Security Engineer

SoundCloud
Apply
2 days ago
New York, NY, USASenior / Staff+

Base Salary

$190k - $220k/yr

Responsibilities

  • Identify security anti-patterns in codebases and drive initiatives to address them.
  • Guide Engineering and Product teams on the safe use of AI in products and SDLC.
  • Automate security processes in the SDLC, including CI/CD pipelines.
  • Secure AWS, GCP, and on-prem infrastructure with proper access controls.
  • Conduct secure code reviews and threat modeling exercises.
  • Define and oversee processes in the Vulnerability Management Program.
  • Triage and remediate submissions from the external bug bounty program.
  • Participate in the security incident response process.
  • Make recommendations to improve consumer security on the platform.
  • Promote security best practices through educational initiatives.
  • Improve internal tooling, processes, and documentation.
  • Help define the Product Security program and team strategy.
  • Mentor and onboard team members.

Requirements

  • 8+ years of product or application security experience or relevant software engineering experience.
  • Deep expertise in designing secure architecture.
  • Enthusiasm for collaborating with teams to address security issues.
  • Experience conducting threat modeling exercises and secure code reviews.
  • Experience configuring DevSecOps tools like SAST and SCA.
  • Experience managing bug bounty programs.
  • Familiarity with programming languages such as Javascript, Go, Ruby, Python, or Scala.
  • Experience with cloud providers like AWS and GCP.
  • Familiarity with IaC tools such as Terraform and CloudFormation.
  • Ability to communicate risk to technical and non-technical audiences.
  • Experience with data analysis (SQL) to assess vulnerabilities.
  • Knowledge of security frameworks and regulations like GDPR and OWASP is a plus.
  • Experience with vulnerability management is a plus.
  • Experience with threat modeling for Generative AI applications is a plus.
  • Experience with data governance is a plus.

Benefits

  • Comprehensive health benefits including medical, dental, and vision plans.
  • Robust 401k program.
  • Employee Equity Plan.
  • Generous professional development allowance.
  • Creativity and Wellness benefit for gym memberships or courses.
  • Flexible vacation and public holiday policy with up to 35 days of PTO annually.
  • 16 paid weeks for all parents to welcome newborns or adopted children.
  • Snacks, goodies, and 2 free lunches weekly at the office.

Tech Stack

AWSGoGoogle Cloud PlatformJavaScriptPythonRubyScalaSQLTerraform