---
title: "Senior Product Security Engineer"
company: "Tessera Labs"
company_url: "https://www.remjobs.works/companies/tessera-labs"
url: "https://www.remjobs.works/job/tessera-labs-senior-product-security-engineer-f889cb9b-8dd2-4ed4-82eb-05b4602835ad"
apply_url: "https://jobs.ashbyhq.com/tessera-labs/3a6fe2e0-68da-4d37-922d-47bd1801128c"
workplace: remote
location: "Brazil"
remote_scope: "Brazil"
employment_type: contract
seniority: senior
role: devops-infrastructure
region: latin-america
skills: ["aws", "azure", "gcp", "kubernetes"]
salary: "$50,000–$60,000 per year"
date_posted: 2026-09-01T19:25:47.907Z
first_seen_by_remjobs: 2026-09-05T08:27:41.869Z
---

# Senior Product Security Engineer

**Tessera Labs** · Brazil

Salary: $50,000–$60,000 per year

Apply: https://jobs.ashbyhq.com/tessera-labs/3a6fe2e0-68da-4d37-922d-47bd1801128c

## About the role

**Senior Product Security Engineer**

**The Role**

We're hiring a **Senior** **Product Security Engineer** to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.

This role partners closely with product engineering and platform engineering teams.

**What You'll Do**

- Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.

- Lead security design and architecture reviews, and run threat modeling on new features and services.

- Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.

- Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.

- Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.

- Help engineers understand the "why" behind findings so the same class of issue doesn't recur.

- Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).**What You'll Need (Required)**

- A strong track record in product or application security — you've measurably made real products more secure.

- Hands-on penetration testing experience against web applications and APIs.

- Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).

- Experience running security design reviews and threat modeling.

- Solid understanding of the SDLC and how to embed security into it.

- Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.**Nice to Have**

- Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).

- A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).

- Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.

- Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.

- Background in enterprise or regulated environments where deployment security is non-negotiable.**What Success Looks Like (First 90 Days)**

- You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.

- A repeatable, lightweight process exists for security design reviews on new work.

- Security findings have a clear triage-to-remediation path, and developers know how to engage you early.**Location and Work Model**

Remote in Brazil

---

Source: Tessera Labs's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/tessera-labs-senior-product-security-engineer-f889cb9b-8dd2-4ed4-82eb-05b4602835ad
