At a Glance
- Tasks: Safeguard products and platforms by identifying and resolving security risks.
- Company: Join a cutting-edge tech company focused on innovation and security.
- Benefits: Enjoy competitive pay, professional growth opportunities, and Apple gear.
- Why this job: Make a real impact in product security while working with talented colleagues.
- Qualifications: 5+ years in application or product security with strong technical skills.
- Other info: Diverse and inclusive workplace committed to your success.
The predicted salary is between 36000 - 60000 ÂŁ per year.
We are seeking a highly capable and pragmatic Senior Product Security Analyst to safeguard our products, platforms, and customers as we scale. This is a senior individual contributor role with clear accountability and decision-making authority, responsible for independently identifying, assessing, and driving resolution of security risks across the product lifecycle. Reporting to the Director, Product Security, you will act as the primary application and product security owner for assigned products, partnering closely with engineering, product management, cloud, and platform teams. You will embed application-focused security practices into design and delivery, exercise sound technical and risk judgment in release decisions, and play a key role in advancing the maturity, consistency, and resilience of our product security capabilities in a fast-growing environment.
Product & Application Security Ownership
- Act as the primary application and product security partner for assigned products and services, owning end-to-end security reviews from design through release.
- Lead application-focused security assessments, including architecture reviews, threat modeling, and secure design validation for APIs, microservices, and SaaS platforms.
- Independently assess security risk and approve, delay, or block releases when required, escalating decisions where business urgency or customer commitments necessitate alignment.
- Provide authoritative, risk-based guidance to engineering teams, helping them understand not just what needs to be fixed, but also include security and risk context.
Application Security & Vulnerability Management
- Own vulnerability triage and prioritization for assigned products, ensuring findings are contextualized based on exploitability, exposure, and business impact.
- Interpret results from application security testing activities (SAST, DAST, SCA, manual reviews), translating technical findings into actionable remediation guidance.
- Monitor relevant external threats, attack techniques, and vulnerability trends, proactively assessing applicability to products and platforms.
- Support investigation and remediation of product- and application-related security incidents.
Secure SDLC & Platform Enablement
- Partner with engineering, platform, and cloud teams to embed secure-by-design practices into the SDLC, with a strong emphasis on application-layer controls.
- Apply hands‑on technical judgment to validate engineering assumptions, challenge risk decisions, and ensure security controls are implemented effectively.
- Contribute to the evolution of application security standards, guardrails, and review practices that scale across multiple product teams.
Compliance & Assurance Support
- Support alignment of application and product security practices with applicable frameworks such as PCI DSS and GDPR, focusing on practical security outcomes rather than checkbox compliance.
- Translate internal controls into actionable engineering requirements and support evidence collection for audits and assessments as needed.
- Coordinate and support penetration testing, bug bounty programs, and third‑party security assessments, ensuring timely remediation and risk closure.
Collaboration, Influence & Maturity Growth
- Build trusted, durable relationships with product, engineering, cloud, platform, and CGRC teams.
- Clearly articulate security risk, trade‑offs, and remediation options to both technical and non‑technical stakeholders.
- Contribute to the long‑term maturity of the product and application security program through pattern recognition, continuous improvement, and shared learning.
Requirements
- 5+ years of experience in application security, product security, or a closely related domain.
- Strong practical understanding of secure SDLC, application security principles (e.g., OWASP Top 10), threat modeling, vulnerability management, and security risk assessment.
- Demonstrated experience owning end-to-end security reviews for applications or products, including release decision support.
- Hands‑on familiarity with application security testing approaches (SAST, DAST, SCA), with the ability to interpret findings and assess real‑world risk.
- Experience working with cloud‑native SaaS environments, preferably AWS, including API driven and microservice based architectures.
- Working knowledge of PCI DSS and GDPR, with experience translating security and compliance requirements into engineering practices.
- Ability to apply independent technical and risk judgment, including challenging assumptions and driving remediation.
- Strong communication skills, capable of engaging both engineers and business stakeholders.
- Experience working in agile or iterative development environments.
- Strong verbal and written communication skills in English.
- Willingness to collaborate across distributed teams and time zones with reasonable flexibility.
Nice to have
- Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field.
- Relevant certifications such as CCSP, CSSLP, AWS Certified Security, or AWS Solutions Architect.
- Experience with manual application security testing, secure design reviews, or API security analysis.
- Exposure to customer‑facing SaaS platforms with regulatory or data protection requirements.
- Familiarity with AI‑enabled or data‑intensive systems, including emerging application security and privacy considerations.
- Experience contributing to the evolution of security standards, review patterns, or guardrails across multiple teams or products.
- Background in quickly evolving organizations that rapidly scale and mature security and compliance practices.
Benefits
- Fixed compensation; Long‑term employment with the working days vacation;
- Development in professional growth (courses, training, etc);
- Being part of successful cutting‑edge technology products that are making a global impact in the service industry;
- Proficient and fun‑to‑work‑with colleagues;
- Apple gear.
Omilia is proud to be an equal opportunity employer and is dedicated to fostering a diverse and inclusive workplace. We believe that embracing diversity in all its forms enriches our workplace and drives our collective success. We are committed to creating an environment where everyone feels welcomed, valued, and empowered to contribute their unique perspectives without regard to factors such as race, color, religion, gender, gender identity or expression, sexual orientation, national origin, heredity, disability, age, or veteran status, all eligible candidates will be given consideration for employment.
Senior Product Security Analyst employer: Omilia
Contact Detail:
Omilia Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Product Security Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A personal connection can often get you a foot in the door faster than a CV.
✨Tip Number 2
Prepare for interviews by researching the company and its products. Understand their security challenges and think about how you can contribute to their goals. Show them you’re not just another candidate!
✨Tip Number 3
Practice your pitch! Be ready to explain your experience and how it relates to the role. Highlight your hands-on skills in application security and your ability to make tough decisions under pressure.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Senior Product Security Analyst
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security and product security. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Technical Skills: When detailing your experience, be specific about the tools and methodologies you've used, like SAST, DAST, or threat modelling. We love seeing hands-on experience, so let us know how you've applied these in real-world scenarios.
Be Clear and Concise: Keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate clarity, especially when it comes to complex topics like security!
Apply Through Our Website: We encourage you to submit your application directly through our website. This helps us keep everything organised and ensures your application gets the attention it deserves. Plus, it’s super easy to do!
How to prepare for a job interview at Omilia
✨Know Your Security Fundamentals
Make sure you brush up on your application security principles, especially the OWASP Top 10. Being able to discuss these concepts confidently will show that you have a solid foundation and can apply them in real-world scenarios.
✨Prepare for Technical Questions
Expect to dive deep into technical discussions about secure SDLC, threat modelling, and vulnerability management. Practise explaining your thought process when assessing security risks and how you would approach remediation.
✨Showcase Your Collaboration Skills
Since this role involves working closely with various teams, be ready to share examples of how you've built relationships and communicated security risks to both technical and non-technical stakeholders. Highlighting your ability to influence and collaborate is key!
✨Stay Updated on Industry Trends
Familiarise yourself with the latest security threats and trends, especially those relevant to cloud-native environments. Being able to discuss current vulnerabilities and how they might impact the company's products will demonstrate your proactive approach to security.