Description
We're looking for a Principal Product Security Engineer to shape how we design, build, and ship secure software at Tellent. This is a new, hands-on role sitting directly within Engineering.
At least 30% of your time will be spent actively looking for vulnerabilities in our own products. The rest will focus on making sure the next vulnerability doesn't get written in the first place - through threat modelling, secure-by-default patterns, and close collaboration with our engineering teams.
Your goal won't simply be to find and fix individual vulnerabilities. You'll help us understand their root causes and eliminate whole classes of security issues across our products.
Responsibilities
- Perform deep manual security reviews and offensive testing across our services, APIs and clients, with particular attention to authorization, multi-tenancy, business logic and other high-risk areas.
- Threat model our highest-risk product surfaces, including new AI functionality, and help teams develop the skills to eventually run this practice themselves.
- Own the technical strategy for our application security tooling, currently Aikido, focusing on actionable signal, developer experience and low false-positive rates.
- Triage vulnerabilities from internal tooling, penetration tests and external researchers, make severity calls you can defend, and partner with teams to verify that fixes work.
- Identify patterns and root causes across findings and build systemic fixes, secure-by-default libraries and paved paths that prevent vulnerabilities from recurring.
- Develop secure development standards that engineers can use in their day-to-day work.
- Partner with our Security team on our bug bounty programme, pentest remediation, security champions network and training based on real findings.
- Act as a senior technical partner for product security incidents and when security or privacy commitments require engineering controls.
- Shape and own our product security roadmap, working across Backend, Frontend, QA, DevOps, Product and Security.
Requirements
- Deep hands-on application or product security experience, ideally built across both engineering and security roles.
- Strong examples of vulnerabilities you've personally identified and can walk us through, from forming the hypothesis and proving the impact to getting the issue fixed.
- Strong understanding of areas such as access control and multi-tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse and supply-chain risk.
- Hands-on engineering skills. You're comfortable reading and writing production code and reasoning about unfamiliar systems and technologies.
- Experience threat modelling real systems and translating findings into practical engineering work.
- Working knowledge of cloud security, containers, CI/CD and infrastructure as code.
- A technology-agnostic mindset. You're comfortable moving between different languages, stacks and environments depending on the problem you're solving.
- Excellent communication skills. You can explain a subtle vulnerability to the engineer who wrote the code and discuss the resulting trade-offs with senior stakeholders.
- A collaborative, low-ego approach. You see product security as an enabling function and build relationships that make teams want to involve you early.
What We Offer
- Hybrid or remote working setup across the Netherlands, Germany and Poland.
- The opportunity to establish and shape product security within our Engineering organisation from the ground up.
- Significant autonomy and direct collaboration with our VP of Engineering and engineering leadership.
- A diverse, multicultural and remote-friendly environment.
- €1,500 annual training budget + 2 dedicated learning days.
- Dedicated tooling budget and opportunities to stay connected to the wider security community through conferences and research.
- Pension plan, travel reimbursement and wellness perks.
- 28 paid holiday days + 2 additional days to relax.
- Work from anywhere for 4 weeks per year.
- Apple MacBook and top-tier tooling.
- €200 home office budget.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://careers.tellent.com/o/principal-product-security-engineer