SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Product Security Engineer – Taiwan 

Obsidian Security - Taipei, Taiwan - In-office - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Obsidian Security, a leading SaaS security platform trusted by 200+ global enterprises including Snowflake, T-Mobile, and Algolia, is seeking a Senior Product Security Engineer to join its Taiwan engineering office. The role focuses on strengthening the security of Obsidian's products, software supply chain, development pipelines, and cloud infrastructure across the complete product lifecycle. You will perform security architecture and design reviews for new products, services, APIs, data pipelines, and infrastructure components. You'll identify security risks early in development and help engineering teams design practical mitigations. You will lead end-to-end CVE management, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation. Rather than relying exclusively on severity scores, you'll evaluate real-world exploitability and customer impact. You'll strengthen CI/CD pipelines with automated security controls including dependency scanning, static analysis, container scanning, infrastructure-as-code scanning, secrets detection, and policy enforcement. You'll develop and maintain software supply chain security controls covering source code, open-source dependencies, build systems, artifacts, containers, and deployment workflows. You'll design and build security features for Obsidian's products, backend services, APIs, and cloud infrastructure, and develop reusable security libraries, services, automation, policies, and developer tools. Additional responsibilities include conducting threat modeling for product capabilities, reviewing application code and infrastructure configurations for vulnerabilities, investigating security incidents, defining security requirements and standards, and mentoring engineers on product security and secure architecture. You'll collaborate closely with Product Engineering, Platform Engineering, SRE, Security Research, and Infrastructure teams across Taiwan, the US, the UK, and Australia. REQUIREMENTS: - Significant experience in product security, application security, security engineering, cloud security, or closely related discipline - Deep knowledge of secure software development and common application security risks (authentication flaws, authorization issues, injection vulnerabilities, insecure deserialization, secrets exposure, data leakage) - Strong hands-on software engineering skills in Python, Go, Java, Kotlin, TypeScript, or comparable language - Experience securing cloud-native SaaS products, distributed systems, APIs, microservices, and data-processing platforms - Practical experience managing vulnerabilities and CVEs across application dependencies, containers, operating systems, cloud services, and infrastructure - Ability to assess vulnerability exploitability, exposure, business impact, remediation options, and deployment risk - Experience implementing security controls in CI/CD and software development workflows - Familiarity with application security testing technologies (SAST, DAST, software composition analysis, container scanning, secrets detection, infrastructure-as-code scanning) - Strong understanding of cloud security, containers, Kubernetes, infrastructure as code, identity and access management, networking, encryption, and secrets management - Experience conducting architecture reviews, threat modeling, secure code reviews, and security testing - Ability to build security automation and product capabilities, not only identify or report issues - Strong troubleshooting skills across product, pipeline, dependency, container, and infrastructure layers - Ability to communicate security risks clearly and help teams make informed, practical decisions - Strong written and verbal communication skills in English - Ability to collaborate effectively across regions, time zones, functions, and cultures NICE TO HAVE: - Experience building cybersecurity, identity security, SaaS security, or enterprise security products - Experience securing large-scale data ingestion, stream-processing, or batch-processing pipelines - Experience with software supply chain security, SBOM management, artifact signing, provenance, and dependency governance - Familiarity with security standards and frameworks (OWASP, CWE, CVSS, EPSS, NIST SSDF, SLSA) - Experience building policy-as-code, automated remediation, security guardrails, or developer security tooling - Experience with penetration testing, vulnerability research, or responsible vulnerability disclosure - Knowledge of multi-tenant SaaS security, tenant isolation, data privacy, and enterprise access controls - Experience supporting security incident response and post-incident remediation - Experience working with globally distributed engineering teams - Mandarin proficiency

Similar roles