Product Security Engineer

Smarsh, Inc.
Belfast
2 weeks ago
Create job alert

Who are we?

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

We are looking for an experienced Product Security Engineer to partner with engineering teams and proactively identify, assess, and remediate security risks across our product portfolio. This role will focus on secure development practices, vulnerability management, threat modelling, and driving a shift-left security culture.

The ideal candidate is a pragmatic problem solver with strong technical expertise in application security, cloud security, and DevSecOps. You will work closely with product owners, software engineers, and platform teams to implement security controls that balance risk with business objectives.

How will you contribute?

  • Secure SDLC Integration: Embed security within the software development lifecycle, ensuring security is considered at every phase—from design to deployment.
  • Threat Modeling & Security Design Reviews: Conduct structured threat modelling and security assessments for new features, architectures, and services.
  • Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans.
  • Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process.
  • Automation & Tooling: Enhance security automation capabilities by integrating security testing tools into CI/CD pipelines.
  • Penetration Testing & Red Teaming: Facilitate internal and external penetration testing activities, helping to triage and remediate findings.
  • Security Champion Enablement: Collaborate with engineering teams to build security awareness and develop a network of Security Champions.
  • Incident & Response Readiness: Support Smarsh SOC and security incident response, including root cause analysis and post-mortem reviews for your product(s).
  • Security Compliance & Governance: Ensure alignment with regulatory requirements (SOC 2, ISO 27001, etc.) and support audit activities.

What will you bring?

  • 7+ years of experience in Product Security, Application Security, or a related security engineering role.
  • Deep expertise in secure software development, secure coding practices, and OWASP Top 10 / CWE 25.
  • Strong technical proficiency in modern programming languages (e.g., Python, Java, JavaScript, Go, or C#).
  • Experience with cloud-native security (AWS, Azure, GCP) and securing containerized environments (Docker, Kubernetes).
  • Proficiency in security testing tools such as Burp Suite, Endor, Semgrep, etc.
  • Strong background in network security, including firewalls, IDS/IPS, VPNs, and secure network design.
  • Hands-on experience with CI/CD security automation (GitHub Actions, Jenkins, GitLab CI, etc.).
  • Familiarity with infrastructure-as-code security (Terraform, CloudFormation) and cloud security posture management.
  • Strong understanding of identity & access management (OAuth, OIDC, SAML, JWT) and API security.
  • Knowledge of industry frameworks like NIST, ISO 27001, and SOC 2.
  • Experience driving developer enablement and security training initiatives.
  • Excellent communication and collaboration skills to engage with engineering, product, and leadership teams.

Preferred Qualifications

  • Security certifications such as OSCP, GIAC (GWEB, GWAPT, GCSA), CISSP, or CSSLP.
  • Experience working in SaaS, and multi-tenant cloud environments.
  • Knowledge of machine learning security (AI/ML model risks, LLM security best practices).
  • Familiarity with attack surface management and threat intelligence.

What do we offer?

  • We value our people and offer a competitive salary along with company bonus.
  • Strong maternity and paternity scheme.
  • A workplace pension scheme.
  • Take what you need holiday package.
  • Private medical insurance.
  • Dental plan.
  • Group life assurance.
  • Group income protection.
  • Employee assistance programme.
  • A monthly wellness allowance.
  • Adoption assistance.
  • Stock options.

Don't meet every requirement? Apply anyway! We value diverse candidates and encourage applications, even if you don't perfectly match the job description. Studies have shown that some strong candidates may self-select out of the interview process prematurely, at Smarsh we encourage an inclusive, high-performing environment.

Smarsh is an equal opportunity and affirmative action employer. Qualified applicants will receive consideration without regard to their race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Smarsh invites all qualified interested applicants to apply for career opportunities. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.

About our culture

Smarsh hires lifelong learners with a passion for innovating with purpose, humility, and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

#J-18808-Ljbffr

Related Jobs

View all jobs

Product Security Engineer

Chief Product Security Engineer

Lead Security Engineer

Lead Software Security Engineer

Lead Software Security Engineer

Security Engineering Director - Detection & Response - Remote Across Anz

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.

Cyber Security vs. Ethical Hacking vs. Security Analysis Jobs: Which Path Should You Choose?

In an era where data breaches, ransomware attacks, and sophisticated digital threats dominate headlines, the demand for skilled cyber security professionals has never been higher. From global corporations to small businesses, organisations are scrambling to protect their systems, networks, and data from malicious actors. If you’ve been exploring cyber security jobs on www.cybersecurityjobs.tech, you’ve likely encountered various specialised roles—Ethical Hacking (often termed Penetration Testing), Security Analysis, Security Architecture, Incident Response, and more. Yet many job seekers and technology enthusiasts are unsure how these fields overlap or which one is right for them. In this in-depth guide, we’ll demystify three core disciplines—Cyber Security, Ethical Hacking, and Security Analysis—outlining the skills each requires, the responsibilities you can expect, salary ranges in the UK, and typical day-to-day activities. By the end, you’ll have a clearer understanding of these roles, helping you decide which path to pursue in this fast-growing industry. And when you’re ready to take the next step, head over to www.cybersecurityjobs.tech to explore the latest openings and find your perfect match.