wagey.ggwagey.gg
38,923  jobs38,923  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(38,923)/Security Engineer Role(514)/BeyondTrust (27) - Sr Product Security Engineer
Pro members applied to this job 36 hours before you saw itGet Pro ›
BeyondTrust

BeyondTrust - Sr Product Security Engineer

Remote - United States3d ago
RemoteSeniorNACloud ComputingArtificial IntelligenceSecurity EngineerTeam LeadershipClaudeAWSKubernetesPhoenixWagmi

Requirements

• 5+ years in Product Security, or Penetration Testing with direct hands-on testing and exploit development • Strong expertise in web application and API security: authentication/authorization, session management, input validation, cryptography, injection attacks, deserialization, SSRF, and privilege escalation • Proficiency with penetration testing tools and methodologies (Burp Suite, custom scripts, fuzzing frameworks) combined with manual exploit validation • Hands-on experience using LLM platforms (Claude, Codex, or similar) to build security testing workflows, generate test cases, analyze code, or develop exploits • Experience building custom security tooling: fuzzers, scanners, exploit frameworks, or automation that goes beyond configuring off-the-shelf products • Strong understanding of common vulnerability classes (OWASP Top Ten, API Security Top Ten, CWE) and how they manifest in real production applications • Experience collaborating with defensive security teams (SOC, Cyber Defense, IR) to translate offensive findings into detection and monitoring capabilities • Understanding of cloud security fundamentals (preferably AWS) and CI/CD pipeline security • Strong communication skills: you can explain a complex exploitation chain to an engineering team and deliver a clear risk narrative to leadership • Experience building AI-native security workflows, threat hunting agents, or automated fuzzing pipelines using LLM platforms • Background in securing endpoint technologies, identity systems, privileged access management, or enterprise security platforms • Experience with mobile application security testing and thick client assessments • Familiarity with container security, Kubernetes security, and infrastructure-as-code scanning • Experience working with bug bounty programs, vulnerability disclosure programs, or coordinated disclosure • Professional certifications such as OSWE, OSCP, GWAPT, GPEN, or equivalent hands-on credentials • Contributions to security research, open-source security tooling, or published vulnerability disclosures • How We'll Measure Success • Consistent discovery of meaningful vulnerabilities with validated PoC exploits that drive remediation across the product portfolio • AI-powered threat hunting skills and fuzz factory plugins actively finding vulnerability classes at scale that manual testing alone would miss • Validated findings include specific, implementable fix recommendations that engineering teams act on • Offensive findings translate into measurable defensive improvements through partnership with Cyber Defense and Research • Reusable skills, prompts, and plugins you build are adopted by the broader Product Security team • Engineering and security leadership trust your severity assessments and prioritization recommendations • Better Together • Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. • We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together. • BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. • BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. • Learn more at www.beyondtrust.com.

Responsibilities

• AI-Driven Security Testing & Vulnerability Discovery Perform deep, context-aware penetration testing of web applications, APIs, endpoint agents, thick clients, identity systems, and cloud-native services. Use Claude and Codex to analyze code paths, trace data flows, identify attack surfaces, and generate targeted test cases that reflect how the product works, not generic payloads against generic endpoints. • Threat Hunting Skills & Fuzz Factory Plugins Build AI-powered threat hunting skills and fuzz factory plugins using Claude and Codex. Develop custom fuzzers that understand product-specific protocols, input formats, and business logic. Create reusable skills and agent workflows that automate discovery of vulnerability classes across the product portfolio: injection paths, auth bypass patterns, privilege escalation chains, and cryptographic weaknesses. • Proof-of-Concept Exploit Development Develop working proof-of-concept exploits for discovered vulnerabilities that demonstrate real impact in the product's deployment context. Use Claude and Codex to accelerate exploit development, generate payloads, and validate exploitation chains. A validated PoC with clear impact drives remediation; an unvalidated scanner finding sits in a backlog. • Vulnerability Validation & Remediation Partnership Validate vulnerabilities from all sources: your own testing, SAST, SCA, third-party pen tests, bug bounty submissions, and security research. Confirm exploitability, assess severity in context, and deliver specific fix recommendations to engineering teams grounded in the codebase and deployment model. • Cyber Defense & Architect Partnership Partner with Cyber Defense and Security Architects to translate offensive findings into defensive capabilities. Turn validated exploitation paths into detection signatures, monitoring rules, WAF configurations, and runtime protections. Work with Security Architects to identify emerging attack techniques relevant to BeyondTrust's product surface and build proactive testing coverage for them. • Security Tooling & Automation Build and maintain AI-driven security testing tooling integrated into CI/CD pipelines. Develop custom SAST rules, and automated validation workflows using Claude and Codex. Contribute prompts, skills, plugins, and agent pipelines back to the Product Security team's shared tooling library. • Threat Modeling & Secure Design Participate in threat modeling exercises alongside Product Security Architects. Bring the attacker's perspective: identify abuse cases, map exploitation paths, and pressure-test design assumptions based on real testing experience across the product portfolio.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

Ethos LifeEthos Life - AI Red Team Security Engineer1w ago
·Remote - USA·$152k - $269k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerAWSDockerKubernetesGovernanceWagmiPhoenixRESTGCPAzureGraphQL
BeyondTrustBeyondTrust - Sr Product Security Engineer1w ago
·Remote - Canada | Remote United States
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerClaudeAWSKubernetesAzureDocumentationReporting
Life360Life360 - Senior Enterprise Security Engineer1mo ago
·Remote - USA·$152k - $224k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerClaudeCursorAWSTraining DevelopmentGoogle Workspace
GitLabGitLab - Staff Infrastructure Security Engineer (APAC, EMEA)1mo ago
·Remote - APAC; Remote, EMEA·Equity
RemoteNAStaffCloud ComputingSecurity EngineerAWSAzureGCPKubernetesTeam Leadership
autofiautofi - Senior Security Engineer1mo ago
·Remote - USA *·Equity
RemoteNASeniorCybersecurityCloud ComputingSecurity EngineerReportingNode.jsJavaScriptAWSPhoenix
TinesTines - Senior Security Operations Engineer2mo ago
·Remote - United States (Remote)
RemoteNASeniorCloud ComputingSecurity EngineerPerformance ReviewsAWSAzureDockerKubernetes
HuntressHuntress - Senior Offensive Security Engineer1mo ago
·Remote - US; United States of America·$170k - $185k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerReportingAWSAzureDocumentation
onticontic - Senior AI Security Engineer3w ago
·Remote - USA
RemoteNASeniorCybersecurityCloud ComputingSecurity EngineerRisk ManagementGovernanceClaudeAWSGeminiCursor
OpenAIOpenAI - Security Engineer, Insider Threat Detection & Response1mo ago
·San Francisco, California, United States·$230k - $385k/year
In OfficeNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerBashPythonIntellectual PropertyLinuxKubernetes

Browse more by category

Show 514 moreSecurity EngineerShow 2,870 moreTeam LeadershipShow 1,429 moreClaudeShow 3,747 moreAWSShow 1,860 moreKubernetesShow 111 morePhoenixShow 12 moreWagmi
Privacy·Terms··Contact·FAQ·Wagey on X