Melbourne
1 week ago
Staff Product Security Engineer logo

Staff Product Security Engineer

UpGuard

Staff Product Security Engineer

UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, security reviews, vulnerability management, detection and response, and building secure-by-default infrastructure. Requires 7+ years of security/software engineering experience with strong cloud, Kubernetes, and IAM expertise.

Core AIRemoteFull-timePrincipalCloud SecurityGCP

Salary

Not specified

Work Location

Melbourne, Victoria, Australia, AU

Work Model

Fully remote; optional offices in Sydney and Hobart, no mandatory office attendance

Experience Required

7 years

Employment Type

Full-time

Experience Level

Staff-level individual contributor; 7+ years of experience

Core Qualifications

Technical (Must-have)
Cloud securityGCPAWSAzureKubernetesEKSGKEAKSContainer securityIAMThreat modellingSecurity reviewsVulnerability managementOWASP Top 10TerraformOpenTofuInfrastructure as CodeDetection and responseCI/CDSoftware supply chain security
Soft Skills
CollaborationAutonomyInfluenceNo-ego approachPragmatic trade-offsIterationSpeed

Preferred Qualifications

Technical (Nice-to-have)
AI/LLM securityOWASP LLM Top 10GoSOC 2ISO 27001Offensive securityPublic security researchCVEsOpen-source security toolingConference talks

Key Responsibilities

  • Lead threat modelling and security reviews across UpGuard's product portfolio and cloud infrastructure, proactively surfacing attack vectors and designing mitigation strategies that scale with growth.
  • Build automation, policy-as-code, and AI-driven security tooling that lets product engineering teams "shift left" and embeds security across the SDLC, leveraging agentic workflows to triage, review, and scale the reach of a lean security function.
  • Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure.
  • Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation with engineering teams, and building preventative controls across the software supply chain from development through production.
  • Build scalable detection and response systems that catch malicious activity, triage the noise, and run incidents end to end.
  • Build deep partnerships with our product engineering and platform teams, helping them deliver secure-by-design solutions.
  • Refresh threat modelling and security review as a standard part of how we ship.
  • Figure out where AI actually helps in AppSec (code review, triage, coverage) and build what works.
  • Harden our GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code.
Product SecurityCloud SecurityKubernetesGCPThreat ModellingVulnerability ManagementAI SecurityRemoteStaff LevelIT Services