As our platform continues to scale, security becomes a core product capability rather than a separate function. We’re looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up.
This is a highly technical, hands-on role where you’ll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle.
Responsibilities
Application Security
•
Review application architecture and new product features from a security perspective.
•
Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
•
Perform threat modeling and security design reviews.
•
Support internal and external penetration testing activities.
Secure Development
•
Build and improve Secure SDLC across engineering teams.
•
Integrate security tooling into CI/CD pipelines.
•
Improve developer security practices and provide technical guidance.
•
Help engineering teams remediate vulnerabilities.
Cloud & Infrastructure Security
•
Improve the security posture of our cloud infrastructure.
•
Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components.
•
Implement security monitoring and hardening best practices.
•
Work closely with Platform and DevOps teams.
Security Automation
•
Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection.
•
Automate security checks and developer workflows.
•
Continuously improve security visibility across the engineering organization.
Requirements
•
4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
•
Strong software engineering background.
•
Experience securing backend systems, REST APIs, and microservices.
•
Experience with cloud platforms (AWS, GCP, or Azure).
•
Strong understanding of Kubernetes, Docker, networking, and infrastructure security.
•
Experience with Secure SDLC and security automation.
•
Hands-on experience with SAST, DAST, dependency scanning, and secrets management.
•
Understanding of OWASP Top 10, common attack vectors, and secure coding practices.
•
Ability to work closely with software engineers and influence technical decisions.
•
Fluent English.
Nice to have
•
Mobile application security experience.
•
Experience in fintech, crypto, payments, or blockchain.
•
Offensive security or penetration testing experience.
•
Security certifications are a plus but not required.
Benefits
•
Professional growth: support for courses, conferences, and English learning (up to 100% coverage).
•
Work-life fit: remote or hybrid format with flexible hours across international teams.
•
Paid leave: up to 20 vacation days + 8 company holidays + 5 personal days per year
•
Recognition programs: structured performance reviews and team awards.
•
Team culture: retreats in international locations (for example, company apartments in Cyprus).