Senior Security Engineer - Product Security
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Work Location & Schedule
Senior Security Engineer Product Security Augusta Ga
This is a hybrid position based in our Augusta GA office Team members are expected to work on site two days per week in our Augusta office and remotely three days per week This schedule supports collaboration while offering flexibility and work life balance For the right candidate this position may also be considered as a fully remote opportunity for individuals residing in Georgia South Carolina North Carolina Florida or Tennessee only
Who we areAt Tax Slayer were more than just a tax software development company; were empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease
As a leading innovator in tax prep software Tax Slayer LLC has been revolutionizing the way people file their taxes since 1965
Our user friendly platform offers an intuitive interface that guides customers through the tax filing process step by step ensuring accuracy and maximum refunds
Tax Slayer is headquartered in Augusta GA with a satellite office in Charlotte NC
Tax Slayer proudly employs nearly 200 individuals year round plus 300 additional in season support agents
Our employees are among the brightest most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season
About the RoleThe Senior Security Engineer Product Security serves as the primary security partner to software development teams helping ensure security is embedded throughout the software development lifecycle
Core Responsibilities- Serve as the primary security point of contact for assigned Development teams participating in sprint planning architecture discussions and design reviews
- Review product features system designs APIs authentication mechanisms and third party integrations to identify and mitigate security risks
- Partner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practices
- Conduct secure code reviews threat modeling activities architecture risk assessments and security testing for applications and product releases
- Perform hands on penetration testing and coordinate third party testing efforts when appropriate
- Manage and optimize SAST DAST and CICD security tooling and processes
- Track identified vulnerabilities through remediation and collaborate with engineering teams to address findings
- Own day to day administration of the companys bug bounty program including researcher engagement submission triage validation and remediation coordination
- Monitor and report bug bounty program performance metrics and recommend process improvements
- Support governance risk and compliance initiatives including audits and assessments related to PCI DSS SOC 2 IRS security requirements and other applicable regulations
- Contribute to enterprise risk management activities and maintain product level security risk documentation
- Assist with security incident response activities including investigation root cause analysis and remediation tracking
- Mentor engineering teams on secure coding practices threat modeling and product security best practices
- Other duties as assigned
- Reduction in application and product security vulnerabilities identified in production environments
- Timely completion of security reviews threat models and vulnerability remediation activities
- Effective integration of security controls within the software development lifecycle
- Successful management and continuous improvement of the bug bounty program including response and remediation timelines
- Positive audit and compliance assessment outcomes related to product security controls
- Increased adoption of secure coding practices and security standards across development teams
- Clear communication of technical risks and effective collaboration with engineering and business stakeholders
Bachelors degree in Cybersecurity Computer Science Information Technology or a related field or equivalent combination of education and experience
Minimum of 5 years of experience in application security product security security engineering or a related field
Experience partnering closely with software development teams to integrate security into the development lifecycle
Experience identifying and validating vulnerabilities in web applications APIs and cloud based environments
Skills & CompetenciesStrong knowledge of secure software development lifecycle SDLC practices
Experience with threat modeling methodologies such as STRIDE PASTA or similar frameworks
Knowledge of common vulnerability frameworks including OWASP Top 10 and CWESANS Top 25
Experience with SAST DAST penetration testing code review and CICD security tools
Strong understanding of web application API and cloud security principles
Ability to assess and communicate technical security risks to technical and non technical audiences
Strong problem solving collaboration and relationship…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).