Confirmed on the employer's own hiring board on Oct 9, 2026. First seen by Alion on Sep 26, 2026.
Join Tellent as a Principal Product Security Engineer, where you'll play a crucial role in shaping the security of our software products. This hands-on position will involve actively seeking vulnerabilities in our products, threat modeling, and collaborating closely with our engineering teams. You'll have a significant impact on our product security roadmap and will work alongside our engineering leads and existing Security and GRC team.
Missions
- Actively seek out vulnerabilities in products and implement strategies to prevent future vulnerabilities.
- Collaborate closely with engineering teams to integrate secure development practices and standards.
- Shape and own the product security roadmap, working across various teams to ensure security is prioritized.
Profil recherché
- Strong understanding of areas such as access control and multi-tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse and supply-chain risk- A collaborative, low-ego approach. You see product security as an enabling function and build relationships that make teams want to involve you early
- Hands-on engineering skills. You're comfortable reading and writing production code and reasoning about unfamiliar systems and technologies
- A technology-agnostic mindset. You're comfortable moving between different languages, stacks and environments depending on the problem you're solving
- Excellent communication skills. You can explain a subtle vulnerability to the engineer who wrote the code and discuss the resulting trade-offs with senior stakeholders
- Strong examples of vulnerabilities you've personally identified and can walk us through, from forming the hypothesis and proving the impact to getting the issue fixed
- Working knowledge of cloud security, containers, CI/CD and infrastructure as code
- Experience threat modelling real systems and translating findings into practical engineering work
- The profile that will likely thrive in this role is someone with a strong engineering foundation who moved deeper into security and is still comfortable working directly with code
- Deep hands-on application or product security experience, ideally built across both engineering and security roles
- Familiarity with technologies already used across Tellent is helpful, but we don't expect you to arrive knowing our entire stack. We'd rather hire a strong, adaptable security engineer who can learn our systems than someone tied to one particular technology
- Certifications such as OSCP, CISSP, CISM or CSSLP are welcome, but not required. Practical experience matters more to us than certifications
- Experience with AI and LLM application security, including prompt injection, excessive agency and data leakage through model context or RAG, would be particularly valuable. Experience with privacy engineering, identity systems such as OAuth 2.0, OIDC and SAML, offensive security, company or platform integrations, or building a product security practice from an early stage would also be a plus

