Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Product Security Engineer image - Rise Careers
Job details

Product Security Engineer

Who are we?


Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines.  Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.


We are looking for an experienced Product Security Engineer to partner with engineering teams and proactively identify, assess, and remediate security risks across our product portfolio. This role will focus on secure development practices, vulnerability management, threat modelling, and driving a shift-left security culture.

The ideal candidate is a pragmatic problem solver with strong technical expertise in application security, cloud security, and DevSecOps. You will work closely with product owners, software engineers, and platform teams to implement security controls that balance risk with business objectives.


How will you contribute?
  • Secure SDLC Integration: Embed security within the software development lifecycle, ensuring security is considered at every phase—from design to deployment.
  • Threat Modeling & Security Design Reviews: Conduct structured threat modelling and security assessments for new features, architectures, and services.
  • Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans.
  • Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process.
  • Automation & Tooling: Enhance security automation capabilities by integrating security testing tools into CI/CD pipelines.
  • Penetration Testing & Red Teaming: Facilitate internal and external penetration testing activities, helping to triage and remediate findings.
  • Security Champion Enablement: Collaborate with engineering teams to build security awareness and develop a network of Security Champions.
  • Incident & Response Readiness: Support Smarsh SOC and security incident response, including root cause analysis and post-mortem reviews for your product(s).
  • Security Compliance & Governance: Ensure alignment with regulatory requirements (SOC 2, ISO 27001, etc.) and support audit activities.


What will you bring?
  • 7+ years of experience in Product Security, Application Security, or a related security engineering role.
  • Deep expertise in secure software development, secure coding practices, and OWASP Top 10 / CWE 25.
  • Strong technical proficiency in modern programming languages (e.g., Python, Java, JavaScript, Go, or C#).
  • Experience with cloud-native security (AWS, Azure, GCP) and securing containerized environments (Docker, Kubernetes).
  • Proficiency in security testing tools such as Burp Suite, Endor, Semgrep, etc.
  • Strong background in network security, including firewalls, IDS/IPS, VPNs, and secure network design.
  • Hands-on experience with CI/CD security automation (GitHub Actions, Jenkins, GitLab CI, etc.).
  • Familiarity with infrastructure-as-code security (Terraform, CloudFormation) and cloud security posture management.
  • Strong understanding of identity & access management (OAuth, OIDC, SAML, JWT) and API security.
  • Knowledge of industry frameworks like NIST, ISO 27001, and SOC 2. 
  • Experience driving developer enablement and security training initiatives.
  • Excellent communication and collaboration skills to engage with engineering, product, and leadership teams.


Preferred Qualifications

  • Security certifications such as OSCP, GIAC (GWEB, GWAPT, GCSA), CISSP, or CSSLP.
  • Experience working in SaaS, and multi-tenant cloud environments.
  • Knowledge of machine learning security (AI/ML model risks, LLM security best practices).
  • Familiarity with attack surface management and threat intelligence.


What do we offer?
  • We value our people and offer a competitive salary along with company bonus
  • Strong maternity and paternity scheme
  • A workplace pension scheme
  • Take what you need holiday package
  • Private medical insurance
  • Dental plan
  • Group life assurance
  • Group income protection
  • Employee assistance programme
  • A monthly wellness allowance
  • Adoption assistance
  • Stock options


Don't meet every requirement? Apply anyway! We value diverse candidates and encourage applications, even if you don't perfectly match the job description. Studies have shown that some strong candidates may self-select out of the interview process prematurely, at Smarsh we encourage an inclusive, high-performing environment.


Smarsh is an equal opportunity and affirmative action employer. Qualified applicants will receive consideration without regard to their race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Smarsh invites all qualified interested applicants to apply for career opportunities. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. Including frequency of functions.


About our culture


Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

Smarsh Glassdoor Company Review
3.0 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star iconGlassdoor star icon
Smarsh DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Smarsh
Smarsh CEO photo
Kim Crawford Goodman
Approve of CEO
What You Should Know About Product Security Engineer, Smarsh

At Smarsh, we're on a mission to empower our customers by managing risk and unleashing intelligence in their digital communications. With a huge community of over 6500 organizations counting on us every day, we're looking for an experienced Product Security Engineer to join our dynamic team. In this role, you'll be right in the thick of the action, partnering with engineering teams to proactively spot and assess security risks across our product portfolio. You're the type of person who thrives on driving a culture of security—embedding secure practices into the software development lifecycle and collaborating closely with product owners and software engineers. You'll tackle everything from secure code reviews to vulnerability management, ensuring our products not only meet business objectives but also keep security front of mind. We want a pragmatic problem solver with considerable expertise in application security, cloud security, and DevSecOps, who can enhance our security automation and conduct thorough threat modeling. If you're ready to help build a solid security framework and support our incident response efforts while ensuring compliance with regulatory requirements, then this role is crafted for you. Plus, we’re not just about work; our vibrant culture values collaboration and continuous learning, making Smarsh a fantastic place for professional growth. If you share our passion for innovation and want to make a difference, we’d love to have you on board as our new Product Security Engineer!

Frequently Asked Questions (FAQs) for Product Security Engineer Role at Smarsh
What are the primary responsibilities of a Product Security Engineer at Smarsh?

As a Product Security Engineer at Smarsh, your primary responsibilities will include embedding security practices throughout the software development lifecycle, conducting structured threat modelling, and collaborating closely with engineering teams to manage vulnerabilities effectively. You'll also facilitate penetration testing, support incident response efforts, and ensure compliance with relevant security frameworks.

Join Rise to see the full answer
What qualifications should I have to become a Product Security Engineer at Smarsh?

To thrive as a Product Security Engineer at Smarsh, candidates typically should have over 7 years of experience in Product Security, Application Security, or related fields. Deep expertise in secure software development practices, along with proficiency in programming languages like Python and cloud security, is essential. Certifications such as OSCP, CISSP, or CSSLP are preferred.

Join Rise to see the full answer
How does Smarsh integrate security into the software development lifecycle for the Product Security Engineer role?

At Smarsh, security is integrated into the software development lifecycle by embedding secure practices from the initial design phase through to deployment. Product Security Engineers focus on conducting threat modeling, secure code reviews, and vulnerability management to ensure that security considerations are part of every step taken in the development process.

Join Rise to see the full answer
What tools and technologies will a Product Security Engineer use at Smarsh?

A Product Security Engineer at Smarsh will be proficient in various security testing tools like Burp Suite and Semgrep, and will utilize CI/CD tools (e.g., GitHub Actions, Jenkins) to enhance security automation. Familiarity with cloud-native security tools and container security best practices will also be important in this role.

Join Rise to see the full answer
What is the work culture like for a Product Security Engineer at Smarsh?

The work culture for a Product Security Engineer at Smarsh is collaborative and enriching. Lifelong learning is encouraged, and employees are valued for their ability to innovate and contribute to a supportive team environment. Smarsh also promotes diversity and inclusion, recognizing the importance of bringing authentic selves to work.

Join Rise to see the full answer
Common Interview Questions for Product Security Engineer
Can you describe your experience with secure software development?

In answering this question, detail your experience in implementing secure coding practices, how you've integrated security into the software lifecycle, and reference specific projects where you've successfully mitigated security risks.

Join Rise to see the full answer
What steps do you take to conduct a threat model?

When tackling this question, explain the methodologies you use for threat modeling, such as STRIDE or PASTA. Outline the steps you follow from identifying assets to determining threats and countermeasures while referencing your experience in previous roles.

Join Rise to see the full answer
How do you approach vulnerability management?

Discuss your systematic approach to vulnerability management, including tools you utilize for scanning, prioritizing vulnerabilities based on risk, and how you collaborate with other teams to remediate these issues effectively.

Join Rise to see the full answer
What is your experience with application security frameworks like OWASP?

Elaborate on your knowledge of the OWASP Top 10 and other frameworks. Share specific examples of how you've applied this knowledge in your previous positions to enhance the security posture of applications.

Join Rise to see the full answer
Describe a time you successfully delivered security training to a development team.

Use this opportunity to highlight a specific instance where you facilitated security training. Focus on the topics covered, the format of the training, and the outcomes, such as changes in development practices or improved security awareness.

Join Rise to see the full answer
What tools would you recommend for CI/CD security automation?

In your response, mention various tools such as Jenkins, GitHub Actions, and security testing software. Explain why you recommend them based on your hands-on experience and how they've helped streamline security integration into CI/CD pipelines.

Join Rise to see the full answer
How do you ensure compliance with security standards like SOC 2 or ISO 27001?

Detail your experience in aligning security practices with compliance standards. Discuss how you've conducted audits, implemented necessary controls, and kept documentation suitable for regulatory requirements.

Join Rise to see the full answer
What strategies do you use to build a culture of security among engineering teams?

Convey your strategies for building a security-aware culture, such as running workshops, promoting a network of security champions, and integrating security discussions into team meetings to foster continuous collaboration.

Join Rise to see the full answer
Can you explain your approach to incident response?

Describe your incident response process, from preparation and identification through containment and recovery. Provide an example of how you handled a security incident and the lessons learned from it.

Join Rise to see the full answer
What experience do you have with cloud-native security?

Share your experiences securing cloud environments, particularly AWS or Azure, highlighting how you've managed security in these platforms effectively, as well as any challenges faced.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Take the lead in delivering data migration projects for a fast-growing company dedicated to helping organizations manage risk and compliance.

Photo of the Rise User

Join Smarsh as a Sr. Manager, Global Compensation to drive strategic compensation frameworks and enhance business impact.

Tern Travel Remote No location specified
Posted 13 days ago

Join ARCO/Murray Engineering as a Senior Mechanical Engineer to drive innovative design solutions in a fast-paced environment.

Photo of the Rise User
Visa Hybrid Highlands Ranch, Colorado, United States
Posted 12 days ago

Join Visa as a Staff Data Center Facilities Engineer to contribute to optimizing data center operations and ensure compliance with safety protocols.

Photo of the Rise User
Posted 4 days ago

As a Mid-Level DevOps / Cloud Engineer, you'll enhance and maintain the infrastructure for a dynamic global HR platform.

EnsembleHP Remote Remote - Nationwide
Posted 5 days ago

Join Ensemble Health Partners as a Data Integration Engineer II, where you will innovate healthcare data solutions remotely.

Photo of the Rise User
Boeing Hybrid US, Saint Louis County, MO; Missouri, Berkeley, MO
Posted 5 days ago

Step into a crucial role at Boeing, leading structural analysis for military aircraft and ensuring their performance and safety.

Where we're headed Communications technology will continue to evolve. Businesses that can embrace these technologies, manage growing data volume and harness the value in their archived communications will thrive. To achieve this, companies need s...

73 jobs
MATCH
VIEW MATCH
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Dayton just viewed Remote Support Engineer at Frontier Technology Inc
Photo of the Rise User
8 people applied to Robotic engineer at New Balance
Photo of the Rise User
Someone from OH, Mason just viewed VP, Business Partners - Global Sales at Zscaler
F
Someone from OH, Oxford just viewed Supply Chain Intern at Fortune Brands
Photo of the Rise User
Someone from OH, Massillon just viewed FORKLIFT OPERATOR at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Shipper/Receiver - Day Shift at Avery Dennison
Photo of the Rise User
Someone from OH, Painesville just viewed Accountant - Mid at Progressive Insurance
Photo of the Rise User
87 people applied to Electrical Apprentice at Aerotek
Photo of the Rise User
Someone from OH, Georgetown just viewed Ohio Medicaid Inbound Contacts Rep at Humana
Photo of the Rise User
Someone from OH, Canton just viewed SEASONER at Shearer's Foods
Photo of the Rise User
Someone from OH, Perrysburg just viewed Casting: Hip Hop Music Video at Backstage
Photo of the Rise User
Someone from OH, Dayton just viewed Senior Financial Analyst, Connected Stores at Instacart
Photo of the Rise User
6 people applied to Engineering intern at Commvault
Photo of the Rise User
Someone from OH, Cincinnati just viewed Head of Marketing at Verified
M
Someone from OH, Cincinnati just viewed VP of Marketing at Max Retail
Photo of the Rise User
Someone from OH, Mount Gilead just viewed Minor Team Member (14-15) at Chick-fil-A