aedify securityDenver, CO
Product Security Engineer
Product Security Engineer
Product Security Engineer
aedify securityDenver, CO
Apply for this role →2 days ago
Position Type:
Contractor, Full-time (1880 hrs. per year) Position Location: Full remote, US-based General Responsibilities Aedify and its customers are seeking a Product Security Engineer to support the Product Security Director and help deliver scalable product security capabilities across modern applications, APIs, cloud-native services, third-party products, desktop applications, and emerging AI-native development. This is a hands-on role focused on identifying meaningful security risk, validating exploitability and business impact, partnering with engineering teams on remediation, and helping operationalize security testing throughout the product lifecycle. Product Security Testing – Design and execute risk-based manual and automated security testing for web and mobile applications, their backing APIs, cloud services, SaaS products, desktop applications, third-party integrations, and other product technologies. Pre-Production Security – Design and execute security testing within product delivery and release workflows, using application architecture, threat models, data sensitivity, exposure, and change risk to determine appropriate testing depth. Threat Modeling & Design Review – Lead or participate in threat modeling and secure design reviews, identify trust boundaries and attack paths, and translate design risks into actionable security requirements and testing objectives. Vulnerability Validation & Remediation – Analyze and validate security findings, assess severity and business impact, provide actionable remediation guidance, verify fixes, and support exception workflows where appropriate. Security Tooling & Automation – Implement and operationalize security testing capabilities such as DAST, API testing, SAST, SCA, secrets, cloud/container, and other relevant security tooling. Develop lightweight automation and integrations where useful. Specialized Product Security Assessment – Contribute expertise in one or more advanced areas such as AI/LLM security, cloud-native security, thick-client security, COTS/third-party assessment, software supply-chain security, or advanced application/API testing. Product Security Program Development – Help create reusable security standards, testing methodologies, engineering guidance, workflows, test cases, and metrics that allow Product Security services to operate consistently at enterprise scale. Cross-Functional Collaboration – Work across engineering, architecture, cloud, infrastructure, identity, networking, governance, vendor, and security teams to resolve technical and process blockers and drive security work through completion. Qualifications Strong understanding of application/product security fundamentals, including manual security testing, API security, authentication and authorization, vulnerability analysis, threat modeling, and secure design. Demonstrated ability to independently navigate complex technical and organizational environments, resolve ambiguity, identify appropriate stakeholders, and drive security initiatives with limited supervision. Strong understanding of modern application architecture, including cloud services, APIs, identity, databases, distributed systems, and SaaS security principles. Ability to translate technical security findings into actionable engineering guidance and communicate risk effectively to technical and non-technical stakeholders. Ability to develop lightweight security automation, tooling, integrations, or test harnesses using technologies such as Python, Power Shell/Bash, APIs, YAML, and CI/CD systems. Hands-on experience with at least one major cloud platform such as Azure, AWS, or GCP is preferred. Working knowledge of emerging technologies and security risks affecting modern product development. Specialized Experience Candidates should bring deeper hands-on experience in one or more of the following areas: Web and API penetration testing DAST and automated application security testing Threat modeling and secure architecture Cloud-native and Kubernetes security AI/LLM and agentic application security Desktop/thick-client security COTS and third-party product security Dev Sec Ops and security tooling automation Software supply-chain security Experience with AI/LLM architectures such as RAG, model APIs, vector stores, agent/tool calling, or model-serving infrastructure is valuable but not required for every candidate. Education & Experience Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent professional experience, certifications, training, and demonstrated technical expertise. 5+ years of relevant cybersecurity, software engineering, platform engineering, or product/application security experience, or equivalent demonstrated expertise. Demonstrated hands-on application/product security experience and depth in at least one relevant specialization. Software development, security automation, Dev Sec Ops, or platform engineering experience is strongly preferred. Familiarity with relevant security guidance such as NIST SSDF, NIST AI RMF, OWASP application/API ßand GenAI security guidance, MITRE ATLAS, SLSA, and applicable cloud-native security guidance is beneficial.
Also on the board Same function, level within a rung
Level
Lead
Location
Denver, CO
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
2 days ago