Sydney
1 week ago
Staff Product Security Engineer logo

Staff Product Security Engineer

UpGuard

Staff Product Security Engineer

UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, vulnerability management, detection and response, and embedding security into CI/CD and infrastructure-as-code. Requires 7+ years in security/software engineering with strong cloud, Kubernetes, and IAM expertise.

Core AIRemoteFull-timePrincipalCloud SecurityGCP

Salary

Not specified

Work Location

Sydney, New South Wales, Australia, AU

Work Model

Fully remote with optional offices in Sydney and Hobart, no mandatory office attendance

Experience Required

7 years

Employment Type

Full-time

Experience Level

Staff-level individual contributor, 7+ years

Core Qualifications

Technical (Must-have)
Cloud securityGCPAWSAzureKubernetesEKSGKEAKSContainer securityIAMThreat modellingSecurity reviewsVulnerability managementOWASP Top 10TerraformOpenTofuInfrastructure-as-CodeDetection and responseCI/CDSoftware supply chain security
Soft Skills
CollaborationAutonomyInfluenceNo-ego approachPragmatic trade-offsPartnership building

Preferred Qualifications

Technical (Nice-to-have)
AI/LLM securityOWASP LLM Top 10GoSOC 2ISO 27001Offensive securityPublic security researchCVEsOpen-source security tooling

Key Responsibilities

  • Lead threat modelling and security reviews across product portfolio and cloud infrastructure
  • Build automation, policy-as-code, and AI-driven security tooling to shift left and embed security across the SDLC
  • Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure
  • Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation, and building preventative controls
  • Build scalable detection and response systems, triage noise, and run incidents end to end
  • Build deep partnerships with product engineering and platform teams to deliver secure-by-design solutions
  • Refresh threat modelling and security review as standard practice within first 6-12 months
  • Figure out where AI helps in AppSec and build what works
  • Harden GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code
Product SecurityCloud SecurityKubernetesGCPThreat ModellingVulnerability ManagementAppSecAI SecurityRemoteStaff Level