Senior Security Engineer, Product AppSec
veeamsoftware • Remote, United States
Posted: June 24, 2026
Job Description
#LI-REMOTE #LI-JC2
About the Role
We're looking for a Senior Product Security Engineer to advance the integration and operational maturity of enterprise application security tooling and vulnerability management across a modern software delivery environment. You'll serve as a senior technical contributor responsible for embedding security into the SDLC, improving developer security enablement, and driving scalable vulnerability management programs across cloud-native, enterprise, and AI-enabled products. This role works closely with Engineering, DevOps, Platform Engineering, Security Operations, and Compliance teams to improve visibility, automation, governance, and remediation workflows at scale.
What You’ll Do
- Evaluate, deploy, integrate, and optimize security tooling — including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing — across CI/CD pipelines and developer workflows
- Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools
- Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards
- Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments
- Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security
- Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience
- Mentor engineers and security practitioners on secure development and DevSecOps best practices
Technologies You’ll Work With
- CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
- Security tooling: SAST, DAST, SCA, IAST, CSPM tools, container scanning platforms
- Cloud providers: Azure (primary), AWS, or GCP
- IaC and containerization: Terraform, Kubernetes, Docker
- Supply chain security: SLSA, Sigstore, SBOM tooling
- Scripting and automation: Python, Bash, PowerShell
What You’ll Bring
- 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering
- 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines
- 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams
- Strong experience with Secure SDLC, threat modeling, and software supply chain security
- Experience building API integrations and workflow automation across security platforms
- Bachelor's degree in Computer Science, Engineering, or equivalent experience
Bonus Skills
- Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper
- Familiarity with AI/ML security risks and emerging AI application security practices
- Demonstrated experience leading cross-functional security initiatives and influencing without direct authority
- Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications
Additional Content
#LI-REMOTE #LI-JC2
About the Role
We're looking for a Senior Product Security Engineer to advance the integration and operational maturity of enterprise application security tooling and vulnerability management across a modern software delivery environment. You'll serve as a senior technical contributor responsible for embedding security into the SDLC, improving developer security enablement, and driving scalable vulnerability management programs across cloud-native, enterprise, and AI-enabled products. This role works closely with Engineering, DevOps, Platform Engineering, Security Operations, and Compliance teams to improve visibility, automation, governance, and remediation workflows at scale.
What You’ll Do
- Evaluate, deploy, integrate, and optimize security tooling — including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing — across CI/CD pipelines and developer workflows
- Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools
- Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards
- Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments
- Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security
- Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience
- Mentor engineers and security practitioners on secure development and DevSecOps best practices
Technologies You’ll Work With
- CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
- Security tooling: SAST, DAST, SCA, IAST, CSPM tools, container scanning platforms
- Cloud providers: Azure (primary), AWS, or GCP
- IaC and containerization: Terraform, Kubernetes, Docker
- Supply chain security: SLSA, Sigstore, SBOM tooling
- Scripting and automation: Python, Bash, PowerShell
What You’ll Bring
- 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering
- 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines
- 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams
- Strong experience with Secure SDLC, threat modeling, and software supply chain security
- Experience building API integrations and workflow automation across security platforms
- Bachelor's degree in Computer Science, Engineering, or equivalent experience
Bonus Skills
- Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper
- Familiarity with AI/ML security risks and emerging AI application security practices
- Demonstrated experience leading cross-functional security initiatives and influencing without direct authority
- Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications