Empleo / GoMining

GoMining

Product Security Engineer

Ubicación
Spain · Remoto
Publicada
hace 1 mes

La oferta

As our platform continues to scale, security becomes a core product capability rather than a separate function. We're looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up. This is a highly technical, hands-on role where you'll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle. Responsibilities Application Security - Review application architecture and new product features from a security perspective. - Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms. - Perform threat modeling and security design reviews. - Support internal and external penetration testing activities. Secure Development - Build and improve Secure SDLC across engineering teams. - Integrate security tooling into CI/CD pipelines. - Improve developer security practices and provide technical guidance. - Help engineering teams remediate vulnerabilities. Cloud & Infrastructure Security - Improve the security posture of our cloud infrastructure. - Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components. - Implement security monitoring and hardening best practices. - Work closely with Platform and DevOps teams. Security Automation - Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection. - Automate security checks and developer workflows. - Continuously improve security visibility across the engineering organization. Requirements - 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering. - Strong software engineering background. - Experience securing backend systems, REST APIs, and microservices. - Experience with cloud platforms (AWS, GCP, or Azure). - Strong understanding of Kubernetes, Docker, networking, and infrastructure security. - Experience with Secure SDLC and security automation. - Hands-on experience with SAST, DAST, dependency scanning, and secrets management. - Understanding of OWASP Top 10, common attack vectors, and secure coding practices. - Ability to work closely with software engineers and influence technical decisions. - Fluent English. Nice to have - Mobile application security experience. - Experience in fintech, crypto, payments, or blockchain. - Offensive security or penetration testing experience. - Security certifications are a plus but not required. Benefits - Professional growth: support for courses, conferences, and English learning (up to 100% coverage). - Work-life fit: remote or hybrid format with flexible hours across international teams. - Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year - Recognition programs: structured performance reviews and team awards. - Team culture: retreats in international locations (for example, company apartments in Cyprus).