Principal Product Security Engineer
Job in
Bedford, Middlesex County, Massachusetts, 01730, USA
Listed on 2026-07-20
Listing for:
Jobtailor
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
Responsibilities
- Responsible for supporting the design, implementation, and oversight of Product Secure Development Lifecycle.
- Including aspects such as security requirements, secure architecture/design, risk assessment, threat models, security scanning, triage and vulnerability management, and product security validation/verification.
- Administers product security practices to product teams, technology, and security champions across the organization.
- Drive Product Security efforts to resolve challenges, enable automation, and impact organization security culture.
- Monitors information security best practices, standards, regulations, industry threats and risks for improvements to product security practices.
- Maintains a deep understanding of current issues in the realm of information security.
- Evaluates vulnerability impact and formulates and executes risk mitigation plans for product security.
- Member of the Aspen Tech Security Emergency Response Team (ASERT) providing expert analysis of security customer reported security incidents.
- Works with information resource owners during and after security incidents; work with product teams for analysis; recommends best practices and solutions.
- Bachelor’s degree (B.A./B.S.) or equivalent in computer science or technical equivalent discipline from an accredited college or university required.
- 8+ years of experience in IT required.
- 5+ years of experience in an information security role or experience with security and development teams.
- Knowledge of information security regulatory requirements for privacy, secure by design, and defense in depth.
- Maintains broad understanding of information security including ISO
27002, NIST and other information security frameworks and regulations. - Experience with Application/Product Security, Risk Assessment, Threat Models, Secure Architecture/Design, Security Scanning (SAST, DAST, SCA, cloud security configuration scanning).
- Experience with cloud solutions such as Azure and AWS.
- Experience with security policy, procedures, tools, services, and cloud security models.
- Demonstrated ability to plan, design, develop, deploy, and maintain application security best practices.
- Ability to assume high levels of responsibility and to work with a minimum of day-to-day supervision.
- Ability to cooperatively and effectively work with people from all organizational levels and build consensus through negotiation and diplomacy.
- Product Secure Development Lifecycle
- security requirements
- secure architecture
- risk assessment
- threat models
- security scanning
- vulnerability management
- application security
- cloud security configuration scanning
- ISO
27002
- responsibility
- negotiation
- diplomacy
- collaboration
- consensus building
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×