Staff Product Security Engineer

Remote in Irvine, CA, US β€’ Posted 22 hours ago β€’ Updated 22 hours ago
Contract W2
Contract Independent
12 Months
Occasional Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Scoreβ„’

πŸ”’ Crunching numbers...

Job Details

Skills

  • FDA
  • ISO 14971
  • IEC 62304
  • Product Security
  • Secure SDLC
  • medical devices
  • API security
  • SBOM
  • vulnerability
  • SAST
  • CISSP
  • CSSLP
  • Risk Management
  • Threat Modeling

Summary

Remote position only California based candidates.

Key Responsibilities:

  • Own Product Security Lifecycle – Security requirements, threat modeling, risk assessments, security testing, and security documentation.
  • Perform Threat Modeling – Analyze trust boundaries, data flows, attack surfaces, and abuse/misuse cases.
  • Security Architecture – Design security controls for devices, applications, APIs, and cloud environments.
  • Secure SDLC / DevSecOps – Implement SAST, SCA, secrets scanning, container/IaC scanning, and security gates.
  • AI Security & Development – Build/develop GenAI, Agentic AI skills, agents, and services and integrate them into product development.
  • Application/API Security – Hands-on with OAuth2/OIDC, authorization, IDOR, SSRF, session security, and API vulnerabilities.
  • Secure Code Review – Manually review production code and triage/tune SAST findings.
  • SBOM & Vulnerability Management – Manage SBOMs, VEX, dependency risks, vulnerabilities, and remediation SLAs.
  • Medical Device Compliance – Support FDA cybersecurity submissions, risk assessments, SBOMs, and audit documentation.

Required Qualifications:

  • 5+ years of cybersecurity/product security engineering experience.
  • Strong Product Security / Secure SDLC experience, including threat modeling, risk assessment, security requirements, and security design reviews.
  • Hands-on security experience across embedded/medical devices + cloud + application/API security.
  • Experience with AI/GenAI/Agentic AI, including building or developing AI agents, skills, or services.
  • Strong secure code review skills and ability to triage/tune SAST/SCA findings.
  • Deep web/API security knowledge β€” OAuth2/OIDC, authorization/IDOR, SSRF, session management, API security, etc.
  • SBOM & vulnerability management experience, preferably SPDX/CycloneDX and VEX/CSAF/OpenVEX.
  • Experience with DevSecOps/security tools such as SAST, SCA, secrets scanning, container and IaC scanning.
  • Experience in regulated product development, ideally medical devices/FDA.
  • Knowledge of FDA cybersecurity requirements, ISO 14971 and IEC 62304 is highly valuable.
Employers have access to artificial intelligence language tools (β€œAI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90806069
  • Position Id: 9069062
  • Posted 22 hours ago
Contact the job poster
SG

Subhajit Ghosh

Recruiter @ SOHO Square Solutions
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Huntington Beach, California

β€’

Today

Full-time

USD 150,000.00 - 175,000.00 per year

Irvine, California

β€’

Today

Full-time

USD 105,500.00 - 168,800.00 per year

El Segundo, California

β€’

Today

Full-time

USD 110,000.00 - 190,000.00 per year

Remote

β€’

Today

Full-time

USD 176,000.00 - 242,000.00 per year

Search all similar jobs