AppSec Jobs
← Back to all jobs

BeyondTrust

Sr Product Security Engineer- Remote

Remote
United StatesPosted 4 days agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureKubernetesCI/CDIncident ResponseSAST

About This Role

We're hiring a Senior Product Security Engineer to build and operate the modern security tooling pipeline that underpins everything our Product Security team does. You'll establish and maintain the SDLC security infrastructure using Claude Code Security, Codex Security, GitHub Advanced Security, Wiz CLI, and integrated tooling that gives engineering teams fast, reliable security feedback on every commit, every PR, and every release. You bring an automation-first mindset. When you see a manual security review process, your instinct is to build a workflow that handles the repeatable parts and surfaces only the decisions that need a human. You'll design and operate product security reviews with human-in-the-loop checkpoints, ensuring coverage scales with the engineering organization without becoming a bottleneck. You'll be a trusted partner to engineers. That means your tooling works reliably, your findings are accurate, your integrations respect their workflow, and when something breaks or creates noise, you fix it fast. You'll partner closely with Security Testers, Architects, the TPM, and engineering teams across the product portfolio. You'll also support product incident response when security issues arise, working alongside the broader Product Security team to investigate, scope, and remediate.

Responsibilities

  • Build and maintain the product security tooling pipeline integrated across the software development lifecycle. Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot), and Wiz CLI across repositories and CI/CD pipelines. Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development.
  • Design and operate automated product security review workflows with human-in-the-loop checkpoints. Use Claude and LLM platforms to automate initial review triage, risk classification, and recommendation generation, escalating to Security Architects or senior engineers for decisions that require judgment. The goal is every change gets appropriate security review coverage without manual review becoming the bottleneck.
  • Ensure security tooling integrates cleanly into engineering workflows: GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards. Reduce false positives, tune rulesets to the product's actual risk profile, and build feedback loops so findings improve over time. You own the engineering experience of security tooling. When a developer interacts with a security gate, it should be clear, fast, and useful.
  • Leverage Claude Code Security, Codex Security, and LLM platforms to build automation that scales security engineering. This includes automated code review triage, vulnerability pattern detection, fix suggestion generation, policy-as-code enforcement, and security review summarization. Contribute reusable prompts, skills, and plugins back to the Product Security team's shared library.
  • Support product incident response alongside the Product Security team. Help investigate security incidents affecting products, scope impact, coordinate with engineering on emergency fixes, and contribute to root cause analysis and post-incident improvements.
  • Work closely with Security Testers to ensure scanning and automated tooling feed validated findings into their workflow. Partner with Architects on translating secure design standards into enforceable pipeline policies. Coordinate with the TPM on tracking and reporting for tooling-generated findings. Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting.

Requirements

DevSecOpsCI/CDSASTDASTSCASnykAWSAzureKubernetes
  • 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent)
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms
  • Strong understanding of CI/CD pipeline architecture and how security controls integrate without disrupting developer velocity
  • Experience building automation workflows: scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration
  • Familiarity with container security scanning tools (Wiz CLI, Trivy, Snyk Container, or equivalent) and cloud security fundamentals (AWS preferred)
  • Understanding of common vulnerability classes well enough to tune tooling, triage findings, and have credible conversations with engineers about severity and remediation
  • Strong collaboration skills. Work across Security Testers, Architects, TPM, and engineering teams daily with effective communication
  • Automation-first mindset. Default to building repeatable, scalable workflows and reach for manual processes only when automation genuinely falls short
  • Experience with GitHub Advanced Security at scale: CodeQL custom queries, secret scanning custom patterns, and organization-wide rollout
  • Background operating Wiz CLI or similar cloud/container security scanning integrated into CI/CD
  • Experience supporting product incident response or security incident investigation
  • Familiarity with policy-as-code frameworks (OPA/Rego, Kyverno, or similar)
  • Background in securing endpoint technologies, identity systems, or enterprise security platforms
  • Experience building developer enablement programs, security documentation, or self-service security tooling
  • Cloud security experience across AWS, Azure, or Kubernetes environments

About BeyondTrust

BeyondTrust is a global leader in identity-centric security solutions, focusing on Privileged Access Management (PAM), vulnerability management, and remote support. The company aims to secure identities, remediate threats, and manage access across various environments, including endpoints, servers, IoT, cloud, and networks. Founded over 30 years ago, BeyondTrust has evolved through key acquisitions and rebranding, with its headquarters in Atlanta, GA. The company emphasizes teamwork, integrity, and a customer-first commitment under CEO Janine Seebeck. BeyondTrust has been recognized as a Leader in the Gartner Magic Quadrant for PAM and has received high scores in the Forrester Wave for Privileged Identity Management. BeyondTrust offers a unified platform that integrates PAM, vulnerability management, and remote support, providing visibility, centralized management, and threat remediation. Its key offerings include securing privileged credentials, identifying system vulnerabilities, enabling secure remote access, and managing identity threats. With over 19,000 customers worldwide, BeyondTrust targets organizations that require scalable privilege security and effective threat defense.

Industry

information technology & services

Employees

1,700

562 engineers

Revenue

$400M

Website

Visit →

Security at BeyondTrust

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • BeyondTrust follows a 'security and privacy by design' philosophy, adhering to the OWASP Top 10 standards.
  • Their approach emphasizes developer enablement over gatekeeping, with security tooling integrated directly into engineering workflows like GitHub PRs and CI/CD pipelines.
  • They prioritize automation with 'human-in-the-loop' escalation to reduce false positives and manual overhead.

Security Team

BeyondTrust maintains a dedicated Application Security team that manages vulnerability intake and remediation. The team is currently expanding, as evidenced by active recruitment for a Senior Product Security Engineer (Job ID 7966643). Specific organizational reporting lines and the names of top leaders are not publicly disclosed on the vendor's primary web pages.

Key Initiatives

  • Active initiatives include the generation of SBOMs for software products and the implementation of AI-assisted security automation (PathfinderAI).
  • The vulnerability management process relies on an email-based intake (secure@beyondtrust.com) with no financial rewards for discovery.
  • Recent efforts focus on securing AI agents and integrating security tools into developer dashboards.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn