/#jobs
#Platform#About Us#Employers#AI Jobs
Get Started
Sydney
1 week ago
Staff Product Security Engineer logo

Staff Product Security Engineer

UpGuard

Sydney
1 week ago
Apply

Staff Product Security Engineer

UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, vulnerability management, detection and response, and embedding security into CI/CD and infrastructure-as-code. Requires 7+ years in security/software engineering with strong cloud, Kubernetes, and IAM expertise.

Core AIRemoteFull-timePrincipalCloud SecurityGCP

Staff Product Security Engineer

UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, vulnerability management, detection and response, and embedding security into CI/CD and infrastructure-as-code. Requires 7+ years in security/software engineering with strong cloud, Kubernetes, and IAM expertise.

Apply
Core AIRemoteFull-timePrincipalCloud Security

Salary

Not specified

Work Location

Sydney, New South Wales, Australia, AU

Work Model

Fully remote with optional offices in Sydney and Hobart, no mandatory office attendance

Experience Required

7 years

Employment Type

Full-time

Experience Level

Staff-level individual contributor, 7+ years

Core Qualifications

Technical (Must-have)
Cloud securityGCPAWSAzureKubernetesEKSGKEAKSContainer securityIAMThreat modellingSecurity reviewsVulnerability managementOWASP Top 10TerraformOpenTofuInfrastructure-as-CodeDetection and responseCI/CDSoftware supply chain security
Soft Skills
CollaborationAutonomyInfluenceNo-ego approachPragmatic trade-offsPartnership building

Preferred Qualifications

Technical (Nice-to-have)
AI/LLM securityOWASP LLM Top 10GoSOC 2ISO 27001Offensive securityPublic security researchCVEsOpen-source security tooling

Key Responsibilities

  • •Lead threat modelling and security reviews across product portfolio and cloud infrastructure
  • •Build automation, policy-as-code, and AI-driven security tooling to shift left and embed security across the SDLC
  • •Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure
  • •Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation, and building preventative controls
  • •Build scalable detection and response systems, triage noise, and run incidents end to end
  • •Build deep partnerships with product engineering and platform teams to deliver secure-by-design solutions
  • •Refresh threat modelling and security review as standard practice within first 6-12 months
  • •Figure out where AI helps in AppSec and build what works
  • •Harden GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code
Product SecurityCloud SecurityKubernetesGCPThreat ModellingVulnerability ManagementAppSecAI SecurityRemoteStaff Level
/#jobs

Your gateway to a successful career. Show your growth. Be ready for your next step. Capture and seize the best opportunities.

  • Data
  • FAQ
  • Articles
  • AI Jobs
  • Platform
  • Employers
  • About Us
  • Legal
© 2026/#jobsAll rights reserved.

For queries/support, email jobs.support@slashhash.ai