SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tessera Labs is seeking a Senior Product Security Engineer to embed security throughout the product development lifecycle. You'll work collaboratively with product and platform engineering teams to make the platform defensible through proactive security practices rather than reactive gatekeeping.
You'll lead security design and architecture reviews, conduct threat modeling on new features and services, and perform hands-on penetration testing of web applications and APIs. Your findings will be translated into clear, prioritized, actionable work for developers. You'll conduct secure code reviews, help define secure-coding standards, and establish security acceptance criteria.
You'll operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency/supply-chain scanning tools, triaging results and helping engineers understand the reasoning behind findings to prevent recurring issues. You'll contribute security evidence and rigor to compliance programs including SOC 2, ISO 27001, and similar frameworks.
Success requires a strong track record in product or application security with measurable impact on real products. You need hands-on penetration testing experience against web applications and APIs, deep understanding of modern web application architecture (single-page frontends, APIs, authentication/authorization mechanisms like OAuth 2.0/OpenID Connect), and knowledge of common attack vectors including OWASP Top 10. Experience running security design reviews and threat modeling is essential, as is solid understanding of the SDLC and how to embed security practices throughout.
Strong communication skills are critical—you'll work directly with developers and explain security risk in terms they'll act on. Nice-to-have qualifications include familiarity with open-source security tools (OWASP ZAP, Burp Suite, Semgrep, Trivy, Grype, Nuclei), offensive-security certifications (OSCP), cloud security experience (AWS, Azure, GCP), container/Kubernetes security knowledge, and background supporting compliance programs in enterprise or regulated environments.