Point Click Care

Senior Product Security Engineer

Job Description

Job Summary:

The Senior Product Security Engineer is responsible for proactively identifying and mitigating product security level issues while working with the overall product team to detect potential issues in production. This multi-faceted role involves engineering solutions, guiding product teams on best practices, performing reviews, conducting thorough investigations, creating detection rules, monitoring security alerts, and collaborating with other security teams to enhance the organization’s overall security posture. The ideal candidate will have a strong technical background in software engineering, cyber security, excellent analytical skills, and a proactive approach to threat detection and response.

Key Responsibilities:

•Detection Rule Development: Create and maintain detection rules and signatures for various security tools (e.g., SIEM, IDS/IPS) to identify potential threats and anomalies.
•Product Advisement: "Shift-left" to work with existing product teams to identify, remediate, and fix new or existing product deficiencies.
•Incident Response: Collaborate with the incident response team to analyze and respond to security incidents, ensuring timely and effective mitigation.
•Data Analysis: Analyze security data from various sources, including logs, SIEM(s), network traffic, and endpoint data, to identify patterns, trends and anomalies indicative of potential threats.
•Tool Development & Management: Solution, develop, and maintain custom scripts, tools, and techniques to enhance threat detection and response capabilities. Manage and optimize security detection tools and platforms.
•Threat Intelligence: Integrate threat intelligence feeds and data into detection mechanisms to improve the accuracy and relevance of alerts.
•Reporting: Understand the nature of threats, potential impact, response actions taken, and recommended mitigation strategies.
•Collaboration: Work closely with other cyber security professionals, product teams, and external partners to share threat intelligence and improve overall security posture.
•Continuous Improvement: Stay up-to-date with the latest cyber threats, trends, and technologies to continuously improve threat hunting and detection methodologies and tools.

Qualifications:

•Education: Bachelor’s degree in Cyber Security, Information Technology, Computer Science, or a related field. Certifications are not required however being a Certified Ethical Hacker is a plus.
•Experience: Minimum of 10-15 years of experience in software engineering and/or cyber security, with a focus on product security, app security, threat hunting, security detection, incident response, or related areas.
•Technical Skills: Expert level understanding of software engineering skills with Java, C# or other OOO languages with focus on app security best practices.  Proficiency in using security tools and technologies such as SIEM, IDS/IPS, EDR, network analysis tools, and OWASP Top 10 knowledge. Strong scripting skills (e.g., Python, PowerShell) are highly desirable.
•Analytical Skills: Excellent analytical and problem-solving skills, with the ability to think critically and creatively to identify and mitigate threats.
•Communication: Strong written and verbal communication skills, with the ability to convey complex technical information to both technical and non-technical stakeholders.
•Team Player: Ability to work effectively both independently and as part of a team in a fast-paced, dynamic environment.



#LI-remote
#LI-AJ1