Job description
As a Product Security Engineer, you will be a key member of the team responsible for ensuring the security of Qualgo's products throughout their entire lifecycle. You will work closely with product managers, engineers, and the security team to integrate security into the design, development, testing, and deployment of our products. You will be a hands-on security expert, conducting threat modeling, security reviews, and providing guidance on secure coding practices. You will be a champion for "security by design" and help build a culture of security within the product development organization.
Key responsibilities
- Threat Modeling:
- Conduct threat modeling sessions with product and engineering teams to identify potential security vulnerabilities in new and existing features.
- Develop and maintain threat models for all products.
- Security Requirements Definition:
- Translate security best practices and regulatory requirements (e.g., Vietnamese cybersecurity laws, data privacy regulations) into concrete, actionable security requirements for product teams.
- Ensure that security requirements are incorporated into product specifications and user stories.
- Security Design Reviews:
- Review product designs and architectures to identify potential security flaws.
- Provide guidance to engineers on secure design principles.
- Ensure that security is considered at every stage of the design process.
- Code Reviews (Security Focus):
- Conduct security-focused code reviews to identify vulnerabilities and ensure adherence to secure coding practices.
- Focus on areas of code relevant to security, such as authentication, authorization, encryption, data validation, and network communication.
- Security Testing:
- Work with QA and engineering teams to develop and execute security tests, including penetration testing, vulnerability scanning, and fuzzing.
- Coordinate with external security researchers or penetration testing firms as needed.
- Secure Development Lifecycle (SDL):
- Promote and implement secure development lifecycle (SDL) practices throughout the organization.
- Develop and deliver security training to engineers.
- Develop and maintain secure coding guidelines.
- Vulnerability Management:
- Track and manage security vulnerabilities identified in our products.
- Work with engineering teams to prioritize and remediate vulnerabilities.
- Incident Response (Product Focus):
- Participate in incident response activities related to product security vulnerabilities.
- Contribute to post-incident analysis and lessons learned.
- Collaboration:
- Work closely with product managers, engineers, designers, and security team.
- Communicate effectively with both technical and non-technical stakeholders.
Qualifications
- Education: Bachelor's degree in Computer Science, Information Security, or a related field. Master's degree preferred.
- Experience:
- Minimum of 5+ years of experience in software engineering, with at least 3 years focused on product security.
- Strong understanding of security principles and best practices.
- Experience with threat modeling methodologies (e.g., STRIDE, DREAD).
- Experience with secure coding practices and common security vulnerabilities (e.g., OWASP Top 10).
- Experience with security testing tools and techniques.
- Experience with VPN technologies (WireGuard, OpenVPN) is a strong plus
- Experience with end-to-end encryption (E2EE) and messaging protocols (e.g., Signal Protocol, MLS) is a strong plus.
- Experience with mobile application security (iOS and Android) is a plus.
- Experience with cloud security (AWS, GCP, Azure) is a plus.
- Experience working in an Agile environment.
- Experience working in Vietnam or Southeast Asia is a plus.
- Skills:
- Strong technical skills in software security.
- Excellent communication and collaboration skills.
- Ability to explain complex security concepts to non-technical audiences.
- Ability to work independently and as part of a team.
- Passion for building secure and trustworthy products.
- Fluency in English; Vietnamese proficiency is a plus.
- Certifications (Desirable):
- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP)
- Other relevant security certifications