Staff Product Security Engineer for SaaS platforms

ориентир по рынку
вакансия зп не указана
в среднем 254 966 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Altium Limited, part of the Renesas Group, is a global software company accelerating electronics innovation through a cloud-based platform that unites stakeholders and phases of electronics development. Its digital platforms support PCB designers, supply chains, and manufacturing organizations in collaborating more effectively.

задачи

  • Build and maintain security regression test suites for critical application flows;
  • Integrate security regression testing into CI/CD pipelines;
  • Define security coverage targets for authentication, access control, APIs, and data flows;
  • Lead threat modeling sessions for existing components, new features, and architectural changes;
  • Identify attack surfaces, abuse cases, and trust boundaries;
  • Translate threats into test cases, security requirements, and mitigation plans;
  • Establish threat modeling as a continuous lifecycle activity;
  • Perform manual and automated security testing simulating real attacker behavior;
  • Validate exploitability and business impact of vulnerabilities;
  • Partner with engineering teams to reproduce issues, prioritize fixes, and validate remediation;
  • Continuously assess the platform against OWASP Top 10 categories;
  • Discover context-specific vulnerabilities, logic flaws, and abuse paths beyond DAST/SAST tooling;
  • Review new features and changes for security risks;
  • Ensure product changes are threat-modeled and covered by regression tests;
  • Enable engineering teams with security guidance and tooling;
  • Contribute to secure-by-design practices and scale security through reusable patterns, automation, and guidance.

требования

  • 5+ Years of experience in Application / Product Security;
  • Bachelor’s Degree or equivalent of 12 years of work experience;
  • Hands-on experience with web application security testing, API security, and threat modeling methodologies;
  • Deep understanding of OWASP Top 10;
  • Experience with manual penetration testing, security regression testing, and CI/CD security integration;
  • Ability to identify business logic vulnerabilities;
  • Strong understanding of authentication, authorization, and session management;
  • Experience with multi-tenant architectures and cloud-native systems;
  • Nice to have: experience in SaaS / multi-tenant platforms, familiarity with bug bounty programs, red teaming, and security automation frameworks, knowledge of AWS, identity systems and federation including SSO and MFA, software engineering background with the ability to read and write code.

условия

  • Competitive benefits package alongside salary.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.