Senior Product Security Engineer
Listed on 2026-06-29
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer
Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.
Job SummaryJoin the Exposure Defense & Monitoring team within Navy Federal’s Product Security Group. In this role you will drive security testing, continuous threat discovery, and exposure management of Navy Federal cloud workloads. You will embed security into the product development lifecycle, work with development teams to secure cloud infrastructure and workloads, and support continuous security monitoring and incident response practices.
Responsibilities- Provide subject‑matter expertise on secure architecture, design, and coding practices for all major cloud architectures (IaaS, PaaS, SaaS).
- Secure business applications and computing environments across public, private, or hybrid cloud infrastructures.
- Collaborate with dependent teams to develop cloud security standards, AI security guardrails, and integrate controls for hardening infrastructure, infrastructure as code, CI/CD pipelines, containers, applications, and agentic AI.
- Translate security policies and standards into machine‑readable guardrails using cloud‑native, open‑source, custom scripting, and commercial security tools.
- Design and implement continuous monitoring practices to verify security properties at runtime and provide continuous feedback to triage and remediation teams.
- Serve as the security consultant in technical project and implementation meetings and guide secure application and infrastructure configurations.
- Implement cloud security automation (CSPM, CWPP, SSPM) and partner with TPRM to ensure SaaS onboarding includes required security and AI security assessments.
- Develop and implement monitoring and incident‑response alerting patterns for cloud infrastructure, SaaS applications, AI telemetry, and runtime assets.
- Manage remediation efforts and provide reporting metrics on security compliance and health to senior leadership.
- Support the definition of a Secure SDLC standard that includes security architecture, design, and coding requirements for infrastructure, application, and data.
- Lead security innovation and best practices in product development through collaboration and industry engagement.
- Perform other duties as assigned.
- Bachelor’s Degree in Information Technology or an equivalent combination of education, training, or experience.
- Six or more years of experience in cybersecurity and/or application security.
- Experience implementing cloud security posture management, workload protection, cloud‑native application protection platforms, and SaaS security posture management tools (e.g., Defender for Cloud, Obsidian Security, Adaptive Shield, App Omni, Prisma Cloud, Orca Security, Wiz.io).
- Experience with cloud security analysis, design techniques, risk assessment, authentication technologies, security monitoring, runtime defenses, and attack patterns.
- Experience evaluating and deploying AI security tooling.
- Advanced knowledge of security best practices, principles, and common frameworks such as OWASP, NIST, and ISO.
- Experience building secure software based on frameworks such as OWASP ASVS, BSIMM, or NIST SSDF.
- Programming experience in Java, Python, .NET, and scripting languages.
- Advanced knowledge of secure architecture and design patterns for Web, Mobile, Microservices, and AI.
- Advanced knowledge of current and emerging threats and exploitation techniques.
- Working knowledge of AI/ML security frameworks and standards (e.g., OWASP LLM Top 10, OWASP ML Top 10, MITRE ATLAS, NIST AI RMF).
- Experience with threat analysis methodologies and tools for static, dynamic analysis, fuzzing, and penetration testing.
- Advanced organizational, planning, and time‑management skills.
- Advanced communication, presentation, and analytical skills.
- Monday - Friday, 8:00 AM - 4:30 PM
- 820 Follin Lane, Vienna, VA 22180
- 5550 Heritage Oaks Drive, Pensacola, FL 32526
- 141 Security Dr., Winchester, VA 22602
All qualified applicants will receive consideration for employment without regard to age, race, sex, color, religion, national origin, disability, veteran status, pregnancy, sexual orientation, genetic information, gender identity or any other basis protected by applicable law.
AccommodationsIf you need accommodation or assistance for a qualifying condition to complete the online application (or during any stage of the hiring process), you can contact Navy Federal's Medical Accommodations team at medical accommodations or call This team cannot provide any information on job postings or application status.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).