TRM Labs
Senior Product Security Engineer
North AmericaFull-timeGlobal
š° USD 215,000 - 230,000/yr
š Midš Remote
Job Description
[AI-summarized by JobStash]
You will lead application security reviews and threat modeling, perform secure code reviews, and test product security across services. You will develop automated security testing, mature the Secure SDLC, own vulnerability management and coordinate penetration testing. You will support engineers with security best practices, run the bug bounty program, bootstrap platform security initiatives, and provide just-in-time secure coding training and mentorship to engineering teams.
Requirements
- āMinimum 8 years of experience in Software Development and testing
- āBS or equivalent in Computer Science, Computer Engineering, or related field
- āProficiency in Python, NodeJS, React
- āStrong understanding of encryption, authentication, and authorization protocols
- āDeep experience with common software flaws (e.g., OWASP and CWE) and testing methodologies
- āExperience with SAST, DAST, and SCA tools and Github advanced security
- āProfessional experience with cloud providers such as GCP and AWS
- āExperience with threat modeling tools (e.g., OWASP Threat Dragon)
- āExperience with web application testing frameworks such as BurpSuite and OWASP ZAP
- āExperience triaging and remediating vulnerabilities in software packages or libraries
- āExperience conducting code security reviews regularly
- āExperience in agile-based software development roles
- āExperience with red teaming or penetration testing applications and infrastructure
- āStrong written and verbal communication skills
- āSecurity certifications such as OSCP, CEH, GWAPT are a plus
- āFamiliarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus
Responsibilities
- āLead application security reviews and threat modeling
- āPerform secure code reviews and security testing
- āDevelop automated testing and mature the Secure SDLC
- āOwn application security vulnerability management
- āCoordinate penetration testing engagements
- āSupport software engineers and product teams with security best practices
- āDevelop and maintain the bug bounty program
- āBootstrap platform security initiatives to protect data
- āFoster security champions and deliver secure code training
Benefits & Perks
- āEligibility to participate in TRM's equity plan
Tech Stack
bug bountysecure codingred teamingDASTSASTCWEagilePythonAWSNode.js