Senior Product Security Engineer

Kandji Inc

  • Miami, FL
  • 1 day ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Access Authorizationunmatched
    • Access Controlunmatched
    • Amazon Web Services (AWS)unmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Programming Languagesunmatched
    • Authenticationunmatched
    • Automationunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cross-Functionalunmatched
    • Diversityunmatched
    • Endpoint Securityunmatched
    • Establish Prioritiesunmatched
    • Fitnessunmatched
    • GCP (Good Clinical Practices)unmatched
    • Injectionsunmatched
    • Machine Toolunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Microsoft Windows Azureunmatched
    • Mobile Applicationsunmatched
    • Model Reviewunmatched
    • Penetration Testingunmatched
    • Presentation/Verbal Skillsunmatched
    • Product Designunmatched
    • Product Developmentunmatched
    • Product Engineeringunmatched
    • Product Lifecycleunmatched
    • Product Managementunmatched
    • Product Reviewsunmatched
    • Product Testingunmatched
    • Risk Analysisunmatched
    • Sales/Support Engineering (SE)unmatched
    • Scripting (Scripting Languages)unmatched
    • Secure Codingunmatched
    • Security Architectureunmatched
    • Security Designunmatched
    • Security Infrastructureunmatched
    • Service Level Agreement (SLA)unmatched
    • ServiceNowunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Software Testingunmatched
    • Standards Developmentunmatched
    • Startupunmatched
    • Team Playerunmatched
    • Test Automationunmatched
    • Testingunmatched
    • Thick Clientunmatched
    • Threat Modelingunmatched
    • Writing Skillsunmatched

    Description

    Senior Product Security Engineer

    Miami

    G&A - Security and Trust /

    Full-Time /

    On-site

    apply for this job

    About Iru

    Iru is the AI-powered security & IT platform used by the world's fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation-collapsing the stack and giving IT & security time and control back.

    Iru is backed by some of the smartest investors in tech-General Catalyst, Tiger Global, Felicis, Greycroft, and First Round Capital. In July 2024, Iru raised $100 million from General Catalyst, valuing the company at $850 million. Customers include Cursor, Vercel, Lovable, Replit, and Mercor, and Iru partners with industry leaders such as ServiceNow and AWS. Iru was named to Forbes' America's Best Startup Employers 2025 list for employee engagement and satisfaction.

    The Opportunity

    We''re seeking a highly technical Senior Product Security Engineer to embed security into the product development lifecycle. This is a hands-on engineering role responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure-by-design products.

    This role will work closely with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to ensure security is integrated throughout the SDLC while enabling developer velocity.

    What You''ll Do

    Application Security

    • Perform security design and architecture reviews for new products and features.
    • Conduct threat modeling for applications, APIs, and AI-enabled services.
    • Review application security posture throughout the SDLC.
    • Partner with engineering teams to prioritize and remediate vulnerabilities.
    • Review authentication, authorization, and access control implementations.

    Security Testing

    • Perform manual web, API, thick-client, and mobile application penetration testing.
    • Validate findings from third-party penetration tests.
    • Conduct secure code reviews.
    • Verify remediation of security vulnerabilities.

    Secure Development

    • Drive adoption of secure coding practices.
    • Partner with developers to improve security throughout the SDLC.
    • Help define Product Security standards and engineering guardrails.
    • Develop reusable security patterns and reference architectures.

    Vulnerability Management

    • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
    • Work with engineering teams to prioritize remediation.
    • Track remediation SLAs and security metrics.

    AI Security

    • Assess AI-enabled products for security risks.
    • Review LLM integrations and AI workflows.
    • Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
    • Help define secure AI engineering standards.

    Security Automation

    • Improve automation of security testing throughout CI/CD.
    • Integrate security tooling into developer workflows.
    • Build scripts and tooling that reduce manual security work.

    Cross-functional Partnership

    • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
    • Support customer security questionnaires related to product security.
    • Assist Sales Engineering with security discussions when needed.

    Qualifications

    • 5+ years in Product Security or Application Security.

    • Strong understanding of modern application architectures.

    • Experience securing:

    • Web applications

    • APIs

    • Microservices

    • Cloud-native applications

    • Experience performing threat modeling.

    • Experience conducting penetration testing.

    • Strong understanding of:

    • OWASP Top 10

    • OWASP API Top 10

    • Authentication & Authorization

    • OAuth / OIDC

    • Secure SDLC

    • Experience with SAST, DAST, SCA, and container security.

    • Experience partnering directly with engineering teams.

    • Strong written and verbal communication skills.

    Preferred

    • Experience securing AI/LLM applications.

    • Experience with Kubernetes and containers.

    • Familiarity with cloud security (AWS, Azure, or GCP).

    • Experience with GitHub Actions or CI/CD security.

    • Experience using:

    • Snyk

    • Burp Suite Pro

    • Semgrep

    • Wiz

    • GitHub Advanced Security

    • Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus

    What Success Looks Like

    Within your first 12 months, you''ll:

    • Embed security into engineering workflows without slowing development.
    • Improve vulnerability remediation timelines.
    • Increase adoption of secure design reviews and threat modeling.
    • Expand automated security testing across products.
    • Help mature Iru''s AI Security program.
    • Strengthen Product Security standards and developer enablement.
    • Build strong partnerships with engineering teams and become a trusted security advisor.

    The ideal candidate should be engineering-first, comfortable reviewing architecture, threat modeling APIs and AI features, conducting hands-on testing, and partnering closely with developers-not someone focused primarily on governance or compliance. This profile will complement your broader security organization while helping scale Product Security as the platform grows.

    Benefits & Perks

    Competitive salary

    Hybrid work environment (3 days in office per week)

    100% individual and dependent medical + dental + vision coverage

    401(K) with a 4% company match

    20 days PTO

    Iru Wellness Week the first week in July

    Equity for full-time employees

    In-office lunch stipend provided

    Up to 16 weeks of paid leave for new parents

    Paid Family and Medical Leave

    Modern Health mental health benefits for individuals and dependents

    Fertility benefits

    Working Advantage employee discounts

    Onsite fitness center

    Free parking

    Exciting opportunities for career growth

    We are excited to be serving a significant need for a fast-growing market, and are proud of the high-performing team we have brought together so far. If you're someone who wants to engage in new, exciting projects that will challenge your skills in the best way possible, we would love to connect with you.

    At Iru, we believe in fostering an inclusive environment in which employees feel encouraged to share their unique perspectives, leverage their strengths, and act authentically. We know that diverse teams are strong teams, and welcome those from all backgrounds and varying experiences.

    Iru is proud to be an equal opportunity employer committed to diversity and inclusion in the workplace. Qualified applicants will be considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, physical or mental disability, protected veteran or military status or any other status protected by applicable law. #LI-Hybrid

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    apply for this job

    Numbers & Facts

    LocationMiami, FL

    Similar Jobs

    See more jobs