
Staff Product Security Engineer
UpGuard
Staff Product Security Engineer
UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, security reviews, vulnerability management, detection and response, and building secure-by-default infrastructure. Requires 7+ years of security/software engineering experience with strong cloud, Kubernetes, and IAM expertise.
Staff Product Security Engineer
UpGuard is hiring its first dedicated Staff Product Security Engineer to define and scale product security across its cloud-native platform. The role involves threat modelling, security reviews, vulnerability management, detection and response, and building secure-by-default infrastructure. Requires 7+ years of security/software engineering experience with strong cloud, Kubernetes, and IAM expertise.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Lead threat modelling and security reviews across UpGuard's product portfolio and cloud infrastructure, proactively surfacing attack vectors and designing mitigation strategies that scale with growth.
- Build automation, policy-as-code, and AI-driven security tooling that lets product engineering teams "shift left" and embeds security across the SDLC, leveraging agentic workflows to triage, review, and scale the reach of a lean security function.
- Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure.
- Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation with engineering teams, and building preventative controls across the software supply chain from development through production.
- Build scalable detection and response systems that catch malicious activity, triage the noise, and run incidents end to end.
- Build deep partnerships with our product engineering and platform teams, helping them deliver secure-by-design solutions.
- Refresh threat modelling and security review as a standard part of how we ship.
- Figure out where AI actually helps in AppSec (code review, triage, coverage) and build what works.
- Harden our GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code.