Skip to content

Open nowPosted 8 days ago

Sr Product Security Engineer

BeyondTrust48 open roles

Where
Remote Canada
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr Product Security EngineerBeyondTrust · Remote Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on BeyondTrust's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. BeyondTrust postings stay open a median of 31 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 8 days ago

BeyondTrust median: 31 days open

The posting

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

We're hiring a Senior Product Security Engineer to build and operate the modern security tooling pipeline that underpins everything our Product Security team does. You'll establish and maintain the SDLC security infrastructure using Claude Code Security, Codex Security, GitHub Advanced Security, Wiz CLI, and integrated tooling that gives engineering teams fast, reliable security feedback on every commit, every PR, and every release. You bring an automation-first mindset. When you see a manual security review process, your instinct is to build a workflow that handles the repeatable parts and surfaces only the decisions that need a human. You'll design and operate product security reviews with human-in-the-loop checkpoints, ensuring coverage scales with the engineering organization without becoming a bottleneck.

You'll be a trusted partner to engineers. That means your tooling works reliably, your findings are accurate, your integrations respect their workflow, and when something breaks or creates noise, you fix it fast. You'll partner closely with Security Testers, Architects, the TPM, and engineering teams across the product portfolio. You'll also support product incident response when security issues arise, working alongside the broader Product Security team to investigate, scope, and remediate.

What You’ll Do

  • SDLC Security Pipeline: Build and maintain the product security tooling pipeline integrated across the software development lifecycle. Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot), and Wiz CLI across repositories and CI/CD pipelines. Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development.
  • Automated Security Reviews Design: and operate automated product security review workflows with human-in-the-loop checkpoints. Use Claude and LLM platforms to automate initial review triage, risk classification, and recommendation generation, escalating to Security Architects or senior engineers for decisions that require judgment. The goal is every change gets appropriate security review coverage without manual review becoming the bottleneck.
  • Tooling Integration & Engineering Experience: Ensure security tooling integrates cleanly into engineering workflows: GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards. Reduce false positives, tune rulesets to the product's actual risk profile, and build feedback loops so findings improve over time. You own the engineering experience of security tooling. When a developer interacts with a security gate, it should be clear, fast, and useful.
  • AI-First Automation: Leverage Claude Code Security, Codex Security, and LLM platforms to build automation that scales security engineering. This includes automated code review triage, vulnerability pattern detection, fix suggestion generation, policy-as-code enforcement, and security review summarization. Contribute reusable prompts, skills, and plugins back to the Product Security team's shared library.
  • Product Incident Response Support: Support product incident response alongside the Product Security team. Help investigate security incidents affecting products, scope impact, coordinate with engineering on emergency fixes, and contribute to root cause analysis and post-incident improvements.
  • Cross-Team Partnership: Work closely with Security Testers to ensure scanning and automated tooling feed validated findings into their workflow. Partner with Architects on translating secure design standards into enforceable pipeline policies. Coordinate with the TPM on tracking and reporting for tooling-generated findings. Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting.

What You’ll Bring

  • 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent)
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms
  • Strong understanding of CI/CD pipeline architecture and how security controls integrate without disrupting developer velocity
  • Experience building automation workflows: scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration
  • Familiarity with container security scanning tools (Wiz CLI, Trivy, Snyk Container, or equivalent) and cloud security fundamentals (AWS preferred)
  • You understand common vulnerability classes well enough to tune tooling, triage findings, and have credible conversations with engineers about severity and remediation
  • Strong collaboration skills. You'll work across Security Testers, Architects, TPM, and engineering teams daily and need to communicate effectively with all of them
  • Automation-first mindset. You default to building repeatable, scalable workflows and reach for manual processes only when automation genuinely falls short

Nice To Have

  • Experience with GitHub Advanced Security at scale: CodeQL custom queries, secret scanning custom patterns, and organization-wide rollout
  • Background operating Wiz CLI or similar cloud/container security scanning integrated into CI/CD
  • Experience supporting product incident response or security incident investigation
  • Familiarity with policy-as-code frameworks (OPA/Rego, Kyverno, or similar)
  • Background in securing endpoint technologies, identity systems, or enterprise security platforms
  • Experience building developer enablement programs, security documentation, or self-service security tooling
  • Cloud security experience across AWS, Azure, or Kubernetes environments

How We'll Measure Success

  • Security tooling coverage across repositories and pipelines is comprehensive and consistently maintained
  • Automated security review workflows handle the majority of reviews with human-in-the-loop escalation for high-risk changes
  • False positive rates decrease over time through tuning and feedback loops you build
  • Engineering teams experience security tooling as fast, accurate, and integrated into their existing workflow
  • Reusable automation, prompts, and plugins you build are adopted across the Product Security team
  • You're the person engineering teams reach out to for security tooling support because they trust your responsiveness and expertise

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-BS1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against BeyondTrust's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on BeyondTrust's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    BeyondTrust's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.