Sr. Staff Product Security Engineer

• Posted 7 hours ago • Updated 7 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

⭐ Evaluating experience...

Job Details

Skills

  • Distribution
  • FOCUS
  • Scalability
  • API
  • Threat Modeling
  • Authentication
  • Mentorship
  • Innovation
  • Continuous Improvement
  • Penetration Testing
  • Payment Systems
  • Finance
  • Fluency
  • Scripting
  • Python
  • JavaScript
  • Bash
  • Workflow
  • Burp Suite
  • Selenium
  • Metasploit
  • Payments
  • DirectShow
  • DS
  • ACH
  • Communication
  • OSCP
  • GPEN
  • Google Cloud Platform
  • Google Cloud
  • Banking
  • Payment Gateways
  • OWASP
  • PCI DSS
  • Financial Services
  • Testing
  • Real-time
  • Fraud
  • Adaptability
  • Emerging Technologies
  • Artificial Intelligence
  • Law
  • Life Insurance
  • Insurance
  • Genetics
  • Recruiting
  • Promotions
  • Training
  • LOS
  • Network

Summary

About Blackhawk Network:

Today, through BHN's single global platform, businesses of all kinds can tap into the world's largest network of branded payment solutions. BHN helps businesses grow revenue, increase loyalty, motivate and reward their teams, disburse funds and engage consumers. Branded payment solutions include the issuance and distribution of gift cards, egifts, corporate payouts and rewards, along with the technology to deliver these products in seamless, integrated ways. BHN's network spans the globe with more than 400,000 consumer touchpoints. Learn more at BHN.com.

Overview:

We're hiring a Sr Staff Product Security Engineer / Pen Tester to help defend our fintech platform against large-scale payment fraud, carding attacks, and other financially motivated threats. You'll lead offensive security assessments targeting our transaction systems, authentication flows, and APIs - with a heavy focus on automation and scalability. Your work will directly impact our fraud defenses, detection strategy, and customer trust.

This is a highly technical, hands-on role for someone who thrives in a fast-paced, high-stakes fintech environment.

Responsibilities:

  • Lead penetration testing engagements focused on payment abuse, transaction manipulation, and business logic exploitation.
  • Design and execute automated attack simulations to test our defenses against:
    • Carding and BIN attacks
    • Credential stuffing and account takeovers
    • Checkout and payment flow abuse
    • API-level enumeration and fraud
  • Build custom tooling and frameworks to mimic the behavior of real-world fraudsters and cybercriminals.
  • Partner with fraud engineering, product security, and risk teams to identify weak points in our controls, detection systems, and architecture.
  • Conduct threat modeling and red teaming exercises related to payments, authentication, and user account abuse.
  • Document findings in technical reports with clear risk impact, exploitability, and remediation guidance.
  • Mentor junior testers and contribute to a culture of security innovation and continuous improvement.

Qualifications:

  • 8+ years of experience in offensive security, penetration testing, or red teaming.
  • Strong background in payment systems, financial fraud tactics, and transaction-level attack surfaces.
  • Fluency in scripting and automation (e.g., Python, JavaScript, Go, Bash) to simulate attacker workflows at scale.
  • Familiarity with tools like Burp Suite Pro, Selenium, Scapy, ffuf, SQLMap, Metasploit, and bot automation frameworks.
  • In-depth knowledge of fintech technologies (e.g., tokenized payments, card vaulting, 3DS, ACH, real-time payment APIs).
  • Solid grasp of common attacker techniques: carding, fake identity generation, bypassing rate limits, evading fraud filters, and abusing web/app logic.
  • Strong communication skills for explaining findings to both technical and non-technical audiences.
  • Certifications: OSCP, OSEP, GWAPT, GPEN, Google Cloud PlatformN, GXPN, GX-PT, CPSA/CRSA by CREST, CHECK, or TIGER.
  • Prior experience in a fintech, digital banking, or payment gateway environment.
  • Familiarity with OWASP Automated Threats, PCI DSS, MITRE ATT&CK for Financial Services, or fraud detection systems.
  • Experience building or testing real-time risk scoring engines and fraud defense pipelines.

We seek candidates who not only demonstrate curiosity and adaptability in emerging technologies but have also successfully implemented and utilized AI tools to enhance their work, improve processes, or deliver measurable results. Our teams embrace continuous learning and the thoughtful integration of AI to create meaningful impact - for our employees and the future of work.

Benefits:

Pay is based on several factors including but not limited to education, work experience, certifications, etc. In addition to your salary, Blackhawk Network offers benefits including 401k with employer match, medical, dental, vision, 12 paid holidays throughout the year 2026, sick pay accrual according to state law, parental leave, life insurance, disability insurance, accident and illness insurance, health and dependent care flexible spending accounts, wellness benefits, and flexible time off for all full-time employees.

EEO Statement:

Blackhawk Network provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Blackhawk Network believes that diversity leads to strength. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Blackhawk Network encourages applicants with previous criminal records to apply to all positions and, pursuant to the San Francisco and Los Angeles Fair Chance Acts (and other "Fair Chance" laws), Blackhawk Network will consider for employment qualified applicants with arrest and conviction records. For Philadelphia applicants or jobs, please see a copy of Philadelphia's ordinance on this topic by clicking this link: _pa/0-0-0-280104.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90922487
  • Position Id: 23909248
  • Posted 7 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Berkeley, Missouri

Today

Full-time

USD 165,000.00 - 200,000.00 per year

Colorado Springs, Colorado

Today

Full-time

USD 164,900.00 - 223,100.00 per year

Huntsville, Alabama

Today

Full-time

USD 164,900.00 - 223,100.00 per year

Huntsville, Alabama

Today

Full-time

USD 164,900.00 - 223,100.00 per year

Search all similar jobs