remote
Product Security Engineer - MirrorWeb
Security Engineer
Product Security Engineer who writes production code to harden supply‑chain components, builds real‑time attack detections, and secures cloud‑native services using Python, Go, and modern security engineering practices.
About the role
Key Responsibilities
- Design, develop, and maintain security‑focused code in Python and Go to protect critical product supply‑chain components.
- Implement detection mechanisms for prompt‑injection, dependency compromise, and other adversary techniques in production environments.
- Collaborate with engineering teams to harden APIs, CI/CD pipelines, and cloud infrastructure (AWS/Azure) against emerging threats.
- Perform threat modeling and failure‑mode analysis to anticipate attacker behavior and prioritize mitigations.
- Integrate static and dynamic application security testing tools into the development lifecycle and drive remediation of findings.
Requirements
- 3+ years of software engineering experience with strong proficiency in Python and Go.
- Deep understanding of secure coding practices, vulnerability assessment, and cloud security concepts.
- Hands‑on experience building detection or response capabilities for real‑world attacks.
- Proven ability to conduct threat modeling, adversary emulation, and failure‑mode analysis.
- Familiarity with CI/CD pipelines, containerization, and security testing tools (SAST, DAST, runtime monitoring).