Product Security Engineer

Product Security Engineer

Full-Time 60000 - 80000 € / year (est.) No home office possible
Deepstreamtech

At a Glance

  • Tasks: Embed security into the software development lifecycle and support engineering teams.
  • Company: Join a forward-thinking tech company focused on secure software solutions.
  • Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
  • Other info: Collaborative culture with a focus on innovation and continuous improvement.
  • Why this job: Make a real impact by enhancing product security in a dynamic environment.
  • Qualifications: Experience in application security and familiarity with cloud technologies.

The predicted salary is between 60000 - 80000 € per year.

Requirements

  • Hands-on product/application security experience supporting engineering teams in a modern SDLC (requirements, design review, secure coding guidance, release support).
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns; familiarity with OWASP ASVS is a plus.
  • Experience implementing or improving SAST/DAST processes: tool selection/tuning, signal-to-noise reduction, and scalable remediation workflows.
  • Working understanding of cloud and container security fundamentals in an environment using AWS and Docker (and related CI/CD practices).
  • Comfort working across a primarily C# ecosystem (with some Java/Python), including the ability to review code and explain security issues clearly to developers.
  • Ability to translate security risk into actionable engineering priorities—balancing risk, delivery timelines, and operational realities.
  • You’re pragmatic: you care about real risk reduction, not checkbox compliance or perfect theoretical security.
  • You communicate clearly and respectfully, able to influence without authority and build trust across multiple product teams.
  • You’re structured and evidence-driven: you document decisions, measure outcomes, and iterate based on what’s working.
  • You’re comfortable in ambiguity and can shape an approach when requirements, tooling, or ownership aren’t fully defined yet.

What the job involves

  • As a Product Security Engineer, you’ll embed security into the software development lifecycle across multiple product teams.
  • You’ll help teams build, ship, and operate secure software by defining requirements, improving detection and prevention (SAST/DAST), assisting teams with application security governance, and running threat modelling.
  • Partner with engineering and product teams to define and operationalise security requirements across the SDLC (from design to release).
  • Audit application code for weaknesses and vulnerabilities.
  • Own or co-own application security governance practices: secure-by-default standards, patterns, guardrails, and exceptions/risk acceptance.
  • Drive SAST/DAST adoption and quality: tool tuning, triage workflows, severity calibration, and “fix-forward” enablement.
  • Support adoption of threat modelling for new features, architectural changes, and high-risk services—turning findings into actionable engineering work.
  • Provide product security guidance for cloud-native environments (AWS + containerised workloads), with an emphasis on secure service design and deployment practices.
  • Build strong relationships with product teams through clear communication, coaching, and security enablement.
  • Review and assist in the development of engineering policies aligned with security best practices.
  • Contribute secure shared libraries/paved-road components or perform targeted security testing/pentesting to validate controls.
  • Work with product teams to support implementation of AI, including LLMs, SLMs, and MCP.

30 Days

  • Onboard into Redgate’s products, SDLC, and delivery rhythms (how work moves from idea → code → deploy).
  • Get access to core systems and security tooling; understand what’s in place today (SAST/DAST coverage, alert volumes, current processes).
  • Shadow the Product Security Architect and sit in on a handful of ceremonies (planning/refinement/retro) to understand team dynamics and where security naturally fits.
  • Triage a small set of findings with guidance (e.g., top recurring SAST issues), focusing on learning severity expectations and remediation patterns.
  • Start building a knowledge base: common app patterns, approved controls, “how we do security here,” and where to find the right people.

60 Days

  • Begin owning a defined slice of AppSec work with supervision (e.g., one product area or a specific SDLC initiative like SAST tuning or DAST onboarding).
  • Build working relationships with a small set of partner teams and establish a predictable engagement model (intake path, review checklist).
  • Start contributing to security reviews for new features or higher-risk changes—initially as a second set of eyes, then independently for scoped areas.
  • Help improve signal-to-noise in SAST/DAST: tune rules, reduce duplicates, and document triage guidance that developers can follow.
  • Support lightweight threat modelling sessions alongside the Architect (prep, note-taking, translating outcomes into engineering actions).

90 Days

  • Independently handle routine AppSec support for agreed scope (e.g., first-pass triage, basic secure design guidance, follow-ups with teams), escalating appropriately.
  • Deliver tangible process improvements that reduce friction (e.g., clearer severity rubric, a repeatable intake template, a “common findings” fix guide).
  • Demonstrate steady throughput on findings: consistent triage quality, meaningful developer support, and reduced turnaround time for the scoped area.
  • Contribute to a secure-by-default library/SDK.

Tech / tool stack

  • C# / .NET (primary engineering ecosystem), React, Java (J2EE), TypeScript, and Python.
  • AWS (cloud infrastructure and services), Docker (containerised workloads).
  • SAST/DAST tooling (specific products may vary; you’ll help tune and operationalise them).

Product Security Engineer employer: Deepstreamtech

At Redgate, we pride ourselves on fostering a collaborative and innovative work culture that empowers our Product Security Engineers to make a real impact in securing software development. With a strong emphasis on employee growth, we offer continuous learning opportunities and the chance to work with cutting-edge technologies in a supportive environment. Located in a vibrant tech hub, our team enjoys a flexible work-life balance and the unique advantage of being part of a company that values security as a fundamental aspect of our product lifecycle.

Deepstreamtech

Contact Detail:

Deepstreamtech Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer

Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repo showcasing your work, especially any projects related to product security. This gives potential employers a taste of what you can do.

Tip Number 3

Prepare for interviews by practising common questions and scenarios related to product security. Think about how you’d tackle real-world problems and be ready to share your thought process.

Tip Number 4

Don’t forget to apply through our website! We love seeing candidates who are genuinely interested in joining us. Plus, it’s the best way to ensure your application gets noticed.

We think you need these skills to ace Product Security Engineer

Product/Application Security Experience
Knowledge of OWASP Top 10
Familiarity with OWASP ASVS
SAST/DAST Processes Implementation
Cloud Security Fundamentals
Container Security (Docker)
C# Programming

Some tips for your application 🫡

Show Your Hands-On Experience:Make sure to highlight your practical experience in product/application security. We want to see how you've supported engineering teams in a modern SDLC, so share specific examples of your work with secure coding guidance and design reviews.

Know Your OWASP:Demonstrate your strong knowledge of the OWASP Top 10 and any mitigation patterns you've implemented. If you're familiar with OWASP ASVS, don't forget to mention that too! It shows us you’re serious about security.

Communicate Clearly:We value clear communication, so make sure your application reflects that. Explain your security risk assessments and how you've influenced engineering priorities without authority. This will help us see how you can build trust across teams.

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. We can’t wait to see what you bring to the table!

How to prepare for a job interview at Deepstreamtech

Know Your Stuff

Make sure you brush up on your product/application security knowledge, especially the OWASP Top 10. Be ready to discuss practical mitigation patterns and how you've applied them in past roles. This shows you're not just familiar with the theory but can also implement it effectively.

Showcase Your Experience with SAST/DAST

Be prepared to talk about your experience with SAST and DAST processes. Discuss specific tools you've used, how you selected and tuned them, and any improvements you've made to workflows. This will demonstrate your hands-on experience and problem-solving skills.

Communicate Clearly

Since you'll be working across multiple teams, practice explaining complex security concepts in simple terms. Think of examples where you've influenced others without authority, as this will highlight your ability to build trust and communicate effectively.

Embrace Ambiguity

In this role, you'll need to navigate uncertainty. Prepare examples from your past where you've shaped an approach despite unclear requirements or tooling. This will show that you're pragmatic and can adapt to changing situations, which is crucial for a Product Security Engineer.