Staff Product Security Engineer in Cambridge

Staff Product Security Engineer in Cambridge

Cambridge Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Renesas Electronics

At a Glance

  • Tasks: Join us to enhance product security and tackle real vulnerabilities in our innovative cloud platform.
  • Company: Renesas, a leader in embedded semiconductor solutions with a diverse and inclusive culture.
  • Benefits: Flexible work environment, remote options, and opportunities for career advancement.
  • Other info: Collaborative atmosphere with a focus on personal growth and innovation.
  • Why this job: Make a real impact on security while working with cutting-edge technology and talented teams.
  • Qualifications: 5+ years in application security, strong hands-on experience in web and API security.

The predicted salary is between 60000 - 80000 £ per year.

Build the cloud platform that’s transforming electronics design. Altium 365 for cloud lets design engineers communicate, collaborate and bring their ideas to market more efficiently than any platform in the industry. We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention.

This role is responsible for:

  • Building and executing security regression testing
  • Driving threat modeling across existing and new functionality
  • Conducting targeted offensive security activities (Red Team–style testing)
  • Identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks

The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.

Key Responsibilities

  • Security Regression Testing
    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for:
    • Existing system components
    • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into:
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to:
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10–Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are:
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck:
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with:
    • Engineering teams
    • Architecture
    • SRE / Platform teams
    • Contribute to secure-by-design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through:
      • Reusable patterns
      • Automation
      • Security guidance

Qualifications

Required Qualifications

  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in:
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
    • Authentication, authorization, and session management
    • Multi-tenant architectures
    • Cloud-native systems

Preferred Qualifications

  • Experience in SaaS / multi-tenant platforms
  • Familiarity with:
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of:
    • AWS
    • Identity systems and federation (SSO, MFA)
    • Background in software engineering (ability to read/write code)

Renesas is an embedded semiconductor solution provider driven by its Purpose ‘To Make Our Lives Easier.’ As the industry’s leading expert in embedded processing with unmatched quality and system-level know-how, we have evolved to provide scalable and comprehensive semiconductor solutions for automotive, industrial, infrastructure, and IoT industries based on the broadest product portfolio, including High Performance Computing, Embedded Processing, Analog & Connectivity, and Power. With a diverse team of over 21,000 professionals in more than 30 countries, we continue to expand our boundaries to offer enhanced user experiences through digitalization and usher into a new era of innovation. We design and develop sustainable, power-efficient solutions today that help people and communities thrive tomorrow, ‘To Make Our Lives Easier.’

At Renesas, you can: Launch and advance your career in technical and business roles across four Product Groups and various corporate functions. You will have the opportunities to explore our hardware and software capabilities and try new things. Make a real impact by developing innovative products and solutions to meet our global customers' evolving needs and help make people’s lives easier, safe and secure. Maximise your performance and wellbeing in our flexible and inclusive work environment. Our people-first culture and global support system, including the remote work option and Employee Resource Groups, will help you excel from the first day.

Are you ready to own your success and make your mark? Join Renesas. Let’s Shape the Future together.

Renesas Electronics is an equal opportunity and affirmative action employer, committed to supporting diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by law. For more information, please read our Diversity & Inclusion Statement.

Staff Product Security Engineer in Cambridge employer: Renesas Electronics

Renesas Electronics is an exceptional employer that fosters a people-first culture, offering flexible work arrangements and a commitment to diversity and inclusion. As a Staff Product Security Engineer, you will have the opportunity to make a significant impact on innovative products while advancing your career in a supportive environment that prioritises employee growth and wellbeing.

Renesas Electronics

Contact Details:

Renesas Electronics Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Product Security Engineer in Cambridge

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Renesas Electronics, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Renesas Electronics

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Renesas Electronics. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Staff Product Security Engineer in Cambridge

Web Application Security Testing
API Security
Threat Modeling Methodologies
OWASP Top 10
Manual Penetration Testing
Security Regression Testing
CI/CD Security Integration

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Renesas Electronics insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Renesas Electronics that you’re committed to staying ahead in the game.

How to prepare for a job interview at Renesas Electronics

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Renesas Electronics to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Renesas Electronics.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.