The Senior Product Security Engineer will serve as a technical leader within the Product Security team, driving security assessments, threat modeling, and security architecture reviews across all products and services. This role requires deep expertise in offensive security techniques and the ability to collaborate cross-functionally with development, DevOps, Cyber Defense and architecture teams
+ ' ' +
- 4+ years of experience in Application Security, Product Security, or Penetration Testing roles.
- Hands-on experience with Active Directory attacks including Kerberoasting, Pass-the-Hash, DCSync, LDAP enumeration, and privilege escalation paths; proficiency with tools such as BloodHound, Impacket, Mimikatz, CrackMapExec, and Rubeus.
- Deep familiarity with OWASP API Security Top 10 and OWASP Mobile Security Testing Guide (MSTG) and strong hands-on experience with web application, mobile (iOS/Android), and API penetration testing, including complex attack vectors
- Hands-on experience with cloud security assessments across AWS, Azure, and/or GCP, including IAM policies, KMS, network controls, and misconfiguration detection.
- Ability to review system and application architectures and provide actionable security recommendations; experience performing threat modeling using STRIDE, PASTA, or similar methodologies.
- Understanding of AI/ML security risks and familiarity with the MITRE ATLAS framework and its application to AI system threat modeling.
- Experience with Red Team and Purple Team campaigns and familiarity with the MITRE ATT&CK and the Cyber Kill Chain.
- Proficiency with security tools including Burp Suite Pro, OWASP ZAP, Nmap, Metasploit, Frida, objection, and MobSF.
- Scripting proficiency in Python, Bash, or PowerShell for security automation tasks.
- Understanding of container and Kubernetes security concepts.
- Relevant certifications preferred: OSWE, OSEP, CAPE, OSCP, BSCP, CRTE, CRTO, AWS Security Specialty, or equivalent.
+ ' ' +
- Opportunities for professional growth and development.
- Competitive salary and bonuses.
- Comprehensive insurance coverage.
- Supportive work environment.
- Visa Premium salary card.
- Corporate discounts and events.
- Additional vacation days.
- Discounted education and employee loans.
+ ' ' +
- Lead application security assessments, threat modeling sessions, and architecture reviews for products and services.
- Perform comprehensive penetration testing across web, mobile, API, and infrastructure environments.
- Conduct SAST, DAST, and SCA analysis; fine-tune scanning tools and integrate findings into development workflows.
- Collaborate with development teams to embed security controls within CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins).
- Work with DevOps teams to assess and improve cloud security posture across AWS, GCP, and Azure.
- Investigate and respond to product security incidents and vulnerability reports.
- Define and enforce secure coding practices, security guidelines, and standards across engineering teams.
- Mentor mid and junior level security engineers and contribute to the growth of the Product Security team.
- Produce detailed security assessment reports and executive-level summaries.
Kapital Bank iş mühiti, əlavə fürsətlər və digər vakansiyaları görüntüləmək üçün Kapital Bank Life səhifəsinə keçid edin.
Vakansiyalardan daha tez xəbərdar olmaq üçün Telegram kanalımıza abunə olun!