Back to jobs

PRODUCT SECURITY ENGINEER

GoMining
mid

Job description

As our platform continues to scale, security becomes a core product capability rather than a separate function. We're looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up. This is a highly technical, hands-on role where you'll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle. Responsibilities Application Security • Review application architecture and new product features from a security perspective. • Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms. • Perform threat modeling and security design reviews. • Support internal and external penetration testing activities. Secure Development • Build and improve Secure SDLC across engineering teams. • Integrate security tooling into CI/CD pipelines. • Improve developer security practices and provide technical guidance. • Help engineering teams remediate vulnerabilities. Cloud & Infrastructure Security • Improve the security posture of our cloud infrastructure. • Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components. • Implement security monitoring and hardening best practices. • Work closely with Platform and DevOps teams. Security Automation • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection. • Automate security checks and developer workflows. • Continuously improve security visibility across the engineering organization. • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering. • Strong software engineering background. • Experience securing backend systems, REST APIs, and microservices. • Experience with cloud platforms (AWS, GCP, or Azure). • Strong understanding of Kubernetes, Docker, networking, and infrastructure security. • Experience with Secure SDLC and security automation. • Hands-on experience with SAST, DAST, dependency scanning, and secrets management. • Understanding of OWASP Top 10, common attack vectors, and secure coding practices. • Ability to work closely with software engineers and influence technical decisions. • Fluent English. Nice to have • Mobile application security experience. • Experience in fintech, crypto, payments, or blockchain. • Offensive security or penetration testing experience. • Security certifications are a plus but not required. • Professional growth: support for courses, conferences, and English learning (up to 100% coverage). • Work-life fit: remote or hybrid format with flexible hours across international teams. • Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year • Recognition programs: structured performance reviews and team awards. • Team culture: retreats in international locations (for example, company apartments in Cyprus).

Skills

AWSGCPAzureKubernetesDockerSASTDASTdependency scanningcontainer scanningsecret detectionSecure SDLCCI/CDREST APIsmicroservicesIAM policiessecrets managementinfrastructure securitynetworkingOWASP Top 10threat modelingpenetration testing