Cutsforth Inc.

Truly innovative, quality products for the Power Generation Industry designed to solve problems like never before.

Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

California + 2 moreAll locations: California, Illinois, New York

Posted

31 days ago

Salary

$133K - $172K / year

Bachelor Degree7 yrs expEnglishAzureCloudCyber SecurityIo TJavaPythonSplunkGo

Job Description

• Embed security best practices, such as encryption and authentication, directly into new products as part of the architecture and design process. • Identify vulnerabilities and security gaps during the design phase to present exploitation. • Define and enforce secure device architecture, including secure boot, hardware root of trust, device identity, and certificate-based authentication. • Own firmware security, including signing, update mechanisms, rollback protection, and vulnerability remediation. • Design and govern end-to-end encryption strategies spanning device, edge, and cloud. • Establish security requirements for low-cost hardware, balancing risk, cost, and operational constraints. • Conduct threat modeling for embedded systems, IoT protocols, and physical attack surfaces. • Partner with hardware, firmware, and manufacturing vendors to ensure supply-chain security controls. • Own product security incident response, including vulnerability triage, remediation coordination, customer communication, and post-incident reviews. • Manage coordinated vulnerability disclosure and CVE processes where applicable. • Lead Product Lifecycle Management security initiatives from concept throughout development, release, and maintenance. • Conduct product security testing and oversee penetration testing, vulnerability scans, and code reviews. • Define the product security strategic roadmap, goals, priorities, features and align product security with business objectives.

Job Requirements

  • Successfully pass background check for cybersecurity site access.
  • 7-15 years of hands-on cyber security experience within the software development lifecycle, including implementation of security controls, vulnerability management, or cloud security
  • Hands on experience with programming languages like Python, Java, C++, or Go.
  • Mastery of security tools like Burp Suite, Checkmarx, or SonarQube.
  • Security Frameworks – solid understanding of OWASP Top 10, NIST and SOC2 compliance
  • Specific familiarity with the NIST SSDF (SP 800-218) standard and experience developing products to meet requirements in this standard
  • Experience with Azure
  • 7+ years of experience with scripting automation for security tasks using Python
  • Practical experience with at least one major SIEM – Splunk
  • Strong analytical and problem-solving skills
  • Ability to clearly communicate technical risks and recommendations to both technical and non-technical stakeholders.
  • Detail oriented with good documentation habits.
  • Bachelor’s degree in computer science or cyber security or related field

Benefits

  • Medical, Vision, Dental Insurance
  • Health Savings Account with Employer contributions
  • 401(k) with Employer match
  • Short-term & Long-term Disability Coverage
  • Accidental Death & Dismemberment Coverage
  • Life Insurance Coverage
  • 80 hours of Paid-Time-Off annually
  • Eight paid holidays per year

Related Categories

Related Job Pages

More Security Engineer Jobs

Workday HCM Consultant

CrossVue

CrossVue, a leading boutique consulting firm, connects the dots between technology, transformation, operations, and data analytics. Our team combines innovation with deep technical and industry expertise to solve complex business challenges. Leveraging our mastery of the Workday platform, we go beyond providing insights – we transform how enterprises view their operations. From human capital to financials, we deliver unparalleled transparency, empowering leaders with a clear, comprehensive view of their organization. Discover how we’re reshaping the future of business intelligence and how you can see clear across your enterprise at crossvue.com

Security Engineer31 days ago
Full TimeRemoteTeam 239

As a Workday HCM Consultant, you will lead client implementations, drive project management, and enhance client relationships while ensuring successful execution of Workday HCM solutions.

Workday HcmWorkday Pro Hcm Services Certification
United States
$80K - $185K / year
Security Engineer31 days ago
Full TimeRemoteTeam 1-10Since 2023H1B No Sponsor

Information Security Manager designing security programs for healthcare organization

CloudCyber Security
California
$133K - $157K / year

Principal Product Security Engineer

Red Hat

The leading provider of enterprise open source solutions.

Security Engineer31 days ago
Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

Principal Product Security Engineer leading cryptographic strategy at Red Hat

PythonGo
District of Columbia + 1 moreAll locations: District of Columbia, North Carolina
$164.9K - $271.9K / year

VP Product Marketing – Cloud Security

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Engineer31 days ago
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

VP Product Marketing driving cloud security strategy at CrowdStrike

AWSAzureCloudCyber SecurityGoogle Cloud Platform
United States
$300K - $340K / year