Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.
We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving tooling, and supporting vulnerability remediation. You'll work closely with senior security engineers and cross-functional teams to build security into our software development lifecycle.
This is a great opportunity for a security-minded engineer who wants to grow their technical breadth while making meaningful impact in a cloud-first, DevOps-centric environment. You must be comfortable working as part of a global team in a dynamic, fast-paced environment. Collaboration across time zones and geographies is a key part of our culture and success.
How will you contribute?
Secure SDLC Integration: Embed security within the software development lifecycle, ensuring security is considered at every phase—from design to deployment.
Threat Modeling & Security Design Reviews: Conduct structured threat modeling and security assessments for new features, architectures, and services.
Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans.
Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process.
Automation & Tooling: Enhance security automation capabilities by integrating security testing tools into CI/CD pipelines.
Penetration Testing & Red Teaming: Facilitate internal and external penetration testing activities, helping to triage and remediate findings.
Security Champion Enablement: Collaborate with engineering teams to build security awareness and develop a network of Security Champions.
Incident & Response Readiness: Support Smarsh SOC and security incident response, including root cause analysis and post-mortem reviews for your product(s).
Security Compliance & Governance: Ensure alignment with regulatory requirements (SOC 2, ISO 27001, etc.) and support audit activities.
What will you bring?
7+ years of experience in Product Security, Application Security, or a related security engineering role.
Deep expertise in secure software development, secure coding practices, and OWASP Top 10 / CWE 25.
Strong technical proficiency in modern programming languages (e.g., Python, Java, JavaScript, Go, or C#).
Experience with cloud-native security (AWS, Azure, GCP) and securing containerized environments (Docker, Kubernetes).
Proficiency in security testing tools such as Burp Suite, Endor, Semgrep, etc.
Strong background in network security, including firewalls, IDS/IPS, VPNs, and secure network design.
Familiarity with infrastructure-as-code security (Terraform, CloudFormation) and cloud security posture management.
Strong understanding of identity & access management (OAuth, OIDC, SAML, JWT) and API security.
Knowledge of industry frameworks like NIST, ISO 27001, and SOC 2.
Experience driving developer enablement and security training initiatives.
Excellent communication and collaboration skills to engage with engineering, product, and leadership teams.
Preferred Qualifications
Security certifications such as OSCP, GIAC (GWEB, GWAPT, GCSA), CISSP, or CSSLP.
Experience working in SaaS, multi-tenant cloud environments.
Knowledge of machine learning security (AI/ML model risks, LLM security best practices).
Familiarity with attack surface management and threat intelligence.
What do we offer?
We value our people and offer a competitive salary along with company bonus
Strong maternity and paternity scheme
A workplace pension scheme
Take what you need holiday package
Private medical insurance
Dental plan
Group life assurance
Group income protection
Employee assistance programme
A monthly wellness allowance
Adoption assistance
Stock options
Don't meet every requirement? Apply anyway! We value diverse candidates and encourage applications, even if you don't perfectly match the job description. Studies have shown that some strong candidates may self-select out of the interview process prematurely, at Smarsh we encourage an inclusive, high-performing environment.
Smarsh is an equal opportunity and affirmative action employer. Qualified applicants will receive consideration without regard to their race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Smarsh invites all qualified interested applicants to apply for career opportunities. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. Including frequency of functions.
About our culture
Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.
These cookies are necessary for the website to function and cannot be turned off in our systems. You can set your browser to block these cookies, but then some parts of the website might not work.
Security
User experience
Target group oriented cookies
These cookies are set through our website by our advertising partners. They may be used by these companies to profile your interests and show you relevant advertising elsewhere.
Google Analytics
Google Ads
We use cookies
🍪
Our website uses cookies and similar technologies to personalize content, optimize the user experience and to indvidualize and evaluate advertising. By clicking Okay or activating an option in the cookie settings, you agree to this.
The best remote jobs via email
Join 5'000+ people getting weekly alerts with remote jobs!