Confirmed on the employer's own hiring board on Oct 11, 2026. First seen by Alion on May 24, 2026. Candid Health scores B on the Alion truth index.
Join our team as a Product Security Engineer, where you will be a champion for security within our product engineering organization. You will work closely with development squads to perform threat modeling, guide secure architecture decisions, and automate security gates in our CI/CD pipelines. Your responsibilities will include leading threat modeling sessions, driving the adoption of secure development practices, managing vulnerabilities, building and maintaining security automation tools, developing secure coding standards, supporting incident response, and ensuring supply chain security. The ideal candidate will have 5+ years of experience in software engineering or security engineering, proficiency in programming languages, and a deep understanding of modern web/cloud architecture.
Missions
- Lead threat modeling sessions during the architectural design phase of new features to identify potential risk vectors early.
- Drive the adoption of "Shift Left" security practices, integrating security tooling (SAST, DAST, SCA) directly into developer workflows.
- Triage, prioritize, and partner with engineering teams to remediate vulnerabilities found in code, third-party libraries, and cloud infrastructure.
Profil recherché
- Technical Skills:- Familiarity with the OWASP Top 10 and common exploitation techniques
- Problem Solving: Strong analytical skills to evaluate complex systems and design innovative, practical security solutions
- Proficiency in one or more programming languages (e.g., Python, Go, Java, or JavaScript)
- Deep understanding of modern web/cloud architecture (e.g., APIs, Microservices, Kubernetes, AWS/GCP/Azure)
- Collaboration: Proven ability to influence and collaborate with engineering teams without hindering development velocity
- Experience: 5+ years of experience in software engineering or security engineering, specifically focusing on product security or application security
- Experience with Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation)
- Experience in designing cryptographic implementations or secure authentication/authorization flows (e.g., OAuth, OIDC, JWT)
- Knowledge of compliance frameworks relevant to our industry (e.g., SOC2, ISO27001, HIPAA)

