Unlock Full Resume Report

New offer - be the first one to apply!

September 22, 2026

Principal Product Security Engineer

Senior • Remote

322 - 410 PLN/yr

Poznań, Pl-30, Poland

Quick Facts

  • Role: Principal Product Security Engineer (hands-on product security within Engineering)
  • Focus: Deep manual security reviews and offensive testing; threat modeling; secure-by-default standards; systemic vulnerability elimination
  • Collaboration: Works closely with Engineering leads and the Security/GRC team
  • Work model: Primarily remote

Description

This is a new, hands-on Principal Product Security Engineer role focused on shaping how secure software is designed, built, and shipped. You will actively look for vulnerabilities (at least 30% of the time) and, for the rest, prevent future issues through threat modeling, secure-by-default patterns, and close collaboration with engineering teams—aiming to eliminate entire classes of security problems.

Responsibilities

  • Perform deep manual security reviews and offensive testing across services, APIs, and clients, with emphasis on authorization, multi-tenancy, and business logic
  • Threat model highest-risk product surfaces, including new AI functionality, and help teams build capability to run the practice themselves
  • Own the technical strategy for application security tooling (currently Aikido), focusing on actionable signal, developer experience, and low false-positive rates
  • Triage vulnerabilities from internal tooling, penetration tests, and external researchers; make defensible severity calls; verify fixes with teams
  • Identify patterns and root causes; drive systemic fixes and build secure-by-default libraries and paved paths
  • Develop secure development standards for day-to-day engineering use
  • Partner with the Security team on bug bounty program, pentest remediation, security champions network, and training
  • Act as a senior technical partner for product security incidents and when engineering controls are needed for security/privacy commitments
  • Shape and own the product security roadmap across Backend, Frontend, QA, DevOps, Product, and Security

Requirements

  • Strong deep hands-on application or product security experience (ideally spanning engineering and security)
  • Track record of vulnerabilities you personally identified, including explaining hypothesis, proof of impact, and remediation
  • Strong understanding of access control, multi-tenancy, authentication/authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse, and supply-chain risk
  • Hands-on engineering skills: comfortable reading/writing production code and reasoning about unfamiliar systems
  • Experience threat modeling real systems and translating findings into practical engineering work
  • Working knowledge of cloud security, containers, CI/CD, and infrastructure as code
  • Technology-agnostic mindset across languages and stacks
  • Excellent communication skills and ability to discuss trade-offs with senior stakeholders
  • Collaborative, low-ego approach; product security as an enabling function
  • Certifications welcome but not required (e.g., OSCP, CISSP, CISM, CSSLP)
  • AI and LLM application security experience and privacy engineering/identity systems are beneficial

Benefits

  • Primarily remote work with flexibility to connect with the team
  • International team environment
  • Annual learning budget (€1500) and wellness perks (Multisport, private healthcare via LuxMed)
  • 26 paid holiday days + 2 wellbeing days
  • Compensation range: 322,380–410,000 PLN/year (+ VAT where applicable)
  • Equipment and work-from-home support (Apple MacBook, displays, tools, €200 home office budget, work-from-home allowance)

Similar jobs you might like