veeamsoftware logo

Senior Security Engineer, Product AppSec

veeamsoftware Remote, United States


No Relocation

Posted: June 24, 2026

Job Description

#LI-REMOTE #LI-JC2

About the Role

We're looking for a Senior Product Security Engineer to advance the integration and operational maturity of enterprise application security tooling and vulnerability management across a modern software delivery environment. You'll serve as a senior technical contributor responsible for embedding security into the SDLC, improving developer security enablement, and driving scalable vulnerability management programs across cloud-native, enterprise, and AI-enabled products. This role works closely with Engineering, DevOps, Platform Engineering, Security Operations, and Compliance teams to improve visibility, automation, governance, and remediation workflows at scale.

What You’ll Do

  • Evaluate, deploy, integrate, and optimize security tooling — including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing — across CI/CD pipelines and developer workflows
  • Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools
  • Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards
  • Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments
  • Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security
  • Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience
  • Mentor engineers and security practitioners on secure development and DevSecOps best practices 

Technologies You’ll Work With

  • CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
  • Security tooling: SAST, DAST, SCA, IAST, CSPM tools, container scanning platforms
  • Cloud providers: Azure (primary), AWS, or GCP
  • IaC and containerization: Terraform, Kubernetes, Docker
  • Supply chain security: SLSA, Sigstore, SBOM tooling
  • Scripting and automation: Python, Bash, PowerShell 

What You’ll Bring

  • 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering
  • 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines
  • 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams
  • Strong experience with Secure SDLC, threat modeling, and software supply chain security
  • Experience building API integrations and workflow automation across security platforms
  • Bachelor's degree in Computer Science, Engineering, or equivalent experience 

Bonus Skills

  • Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper
  • Familiarity with AI/ML security risks and emerging AI application security practices
  • Demonstrated experience leading cross-functional security initiatives and influencing without direct authority
  • Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications 

Additional Content

#LI-REMOTE #LI-JC2

About the Role

We're looking for a Senior Product Security Engineer to advance the integration and operational maturity of enterprise application security tooling and vulnerability management across a modern software delivery environment. You'll serve as a senior technical contributor responsible for embedding security into the SDLC, improving developer security enablement, and driving scalable vulnerability management programs across cloud-native, enterprise, and AI-enabled products. This role works closely with Engineering, DevOps, Platform Engineering, Security Operations, and Compliance teams to improve visibility, automation, governance, and remediation workflows at scale.

What You’ll Do

  • Evaluate, deploy, integrate, and optimize security tooling — including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing — across CI/CD pipelines and developer workflows
  • Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools
  • Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards
  • Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments
  • Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security
  • Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience
  • Mentor engineers and security practitioners on secure development and DevSecOps best practices 

Technologies You’ll Work With

  • CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
  • Security tooling: SAST, DAST, SCA, IAST, CSPM tools, container scanning platforms
  • Cloud providers: Azure (primary), AWS, or GCP
  • IaC and containerization: Terraform, Kubernetes, Docker
  • Supply chain security: SLSA, Sigstore, SBOM tooling
  • Scripting and automation: Python, Bash, PowerShell 

What You’ll Bring

  • 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering
  • 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines
  • 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams
  • Strong experience with Secure SDLC, threat modeling, and software supply chain security
  • Experience building API integrations and workflow automation across security platforms
  • Bachelor's degree in Computer Science, Engineering, or equivalent experience 

Bonus Skills

  • Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper
  • Familiarity with AI/ML security risks and emerging AI application security practices
  • Demonstrated experience leading cross-functional security initiatives and influencing without direct authority
  • Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications