SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: EUR 28,114 - 35,143 / annual
BloomReach is building an agentic platform for personalization, using AI agents to personalize the entire customer journey. The company powers personalization for over 1,400 global brands including American Eagle, Sonepar, and Pandora.
As a Product Security Engineer, you will serve as the designated security focus on a specific product domain, driving threat modeling, security assessments, and vulnerability management across BloomReach's platform.
Key responsibilities include:
- Supporting implementation and adoption of Secure Software Development Lifecycle (SSDLC) practices across engineering teams
- Performing security reviews of application designs, system architectures, and infrastructure components to identify risks and recommend mitigations
- Participating in threat modeling exercises using methodologies like STRIDE to identify threats and document security recommendations
- Providing security guidance to product and engineering teams by applying established security standards and best practices
- Conducting security assessments, penetration testing, and validation testing across applications and environments
- Triaging, validating, and assigning vulnerabilities from security tools and assessments, supporting timely remediation
- Collaborating with engineering, DevOps, compliance, and cross-functional teams to address security requirements
- Developing domain knowledge and serving as a security point of contact for routine security questions
In the first 30 days, you will develop foundational understanding of BloomReach's product portfolio, become familiar with internal SOPs and security policies, and establish working relationships with key partners. By 60 days, you will actively contribute to penetration tests, participate in threat modeling, and review vulnerability data. By 90 days, you will independently perform well-defined security assessments, engage directly with engineering teams on findings, and identify process improvements.
Requirements:
- 2+ years of hands-on experience in cybersecurity, application security, product security, or related security discipline
- Practical experience performing or supporting security assessments and penetration testing of web applications
- Familiarity with threat modeling concepts and methodologies such as STRIDE
- Understanding of vulnerability management fundamentals including validation, risk-based prioritization, remediation tracking, and retesting
- Exposure to AI and LLM technologies with interest in developing knowledge of associated security risks and controls
- Working knowledge of modern application architectures, APIs, authentication and authorization mechanisms, and common application security considerations
- Knowledge of OWASP standards and resources, including OWASP Top 10, Testing Guide, and secure development practices
- Hands-on experience with or familiarity with security testing tools such as Burp Suite, OWASP ZAP, Nmap, SAST/SCA tools, and other application security technologies
- Ability to analyze and validate security findings and prioritize vulnerabilities based on technical risk and business context
- Strong communication skills with ability to clearly document findings and communicate technical concepts to engineering and stakeholders
- Self-motivated and proactive with willingness to learn, take ownership, and contribute to process improvements
- Team-oriented mindset with ability to collaborate effectively across security, engineering, DevOps, and cross-functional teams
- Continuous learning mindset with strong interest in developing technical security expertise and staying current with emerging technologies and threats
- Excellent command of English language with strong listening, speaking, reading, and written communication skills