As a Product Security Engineer at Astranis, you are a software engineer with a passion for security, responsible for building and securing our web applications and services. Your role will involve embedding security into the software development lifecycle, from design to deployment. While your primary role is to build secure software in Python and modern web stacks, your expertise will be used to identify vulnerabilities, conduct security reviews, and help engineering teams raise the bar for security across the board.
- Perform security code reviews and penetration testing on our web applications and services.
- Contribute to security initiatives and serve as a security champion within software development teams.
- Provide guidance and support to developers on implementing security measures and secure coding best practices.
- Collaborate with vendors, partners, and other Astranis software engineers to implement effective remediation strategies.
- Perform risk assessments to identify and prioritize threats in our applications and infrastructure.
- Work with development teams during the design phase to build secure systems and ensure our products are implemented to a high security standard.
- Collaborate with software development teams to design and implement technical solutions that address identified risks.
- 2+ years of experience in software engineering with a focus on security.
- Strong investigative, analytical problem-solving skills and attention to detail.
- Experience with secure coding practices for web applications.
- Software development experience and security expertise in Python and modern web frameworks (e.g., Django, Flask, React).
- Proven experience in threat modeling and security assessments for web applications.
- Proficiency in software development, including auditing and writing secure code.
- Strong knowledge of security best practices, common vulnerabilities, and frameworks.
- Ability to work collaboratively within a team environment.