Why This Role Stands Out
This remote Staff Product Security Engineer role at SOHO Square Solutions offers an exceptional opportunity to shape product security across a diverse technology landscape, including cutting-edge AI development. You'll thrive here if you are a proactive engineer eager to own the security lifecycle and contribute to a reputable company, leveraging your expertise in threat modeling and secure SDLC practices. Apply now to make a significant impact and grow your career in a flexible, remote setting.
Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
Irvine, CA, United States
Posted
2 weeks ago
Job Description
Remote position only California based candidates.
Key Responsibilities:
- Own Product Security Lifecycle – Security requirements, threat modeling, risk assessments, security testing, and security documentation.
- Perform Threat Modeling – Analyze trust boundaries, data flows, attack surfaces, and abuse/misuse cases.
- Security Architecture – Design security controls for devices, applications, APIs, and cloud environments.
- Secure SDLC / DevSecOps – Implement SAST, SCA, secrets scanning, container/IaC scanning, and security gates.
- AI Security & Development – Build/develop GenAI, Agentic AI skills, agents, and services and integrate them into product development.
- Application/API Security – Hands-on with OAuth2/OIDC, authorization, IDOR, SSRF, session security, and API vulnerabilities.
- Secure Code Review – Manually review production code and triage/tune SAST findings.
- SBOM & Vulnerability Management – Manage SBOMs, VEX, dependency risks, vulnerabilities, and remediation SLAs.
- Medical Device Compliance – Support FDA cybersecurity submissions, risk assessments, SBOMs, and audit documentation.
Required Qualifications:
- 5+ years of cybersecurity/product security engineering experience.
- Strong Product Security / Secure SDLC experience, including threat modeling, risk assessment, security requirements, and security design reviews.
- Hands-on security experience across embedded/medical devices + cloud + application/API security.
- Experience with AI/GenAI/Agentic AI, including building or developing AI agents, skills, or services.
- Strong secure code review skills and ability to triage/tune SAST/SCA findings.
- Deep web/API security knowledge — OAuth2/OIDC, authorization/IDOR, SSRF, session management, API security, etc.
- SBOM & vulnerability management experience, preferably SPDX/CycloneDX and VEX/CSAF/OpenVEX.
- Experience with DevSecOps/security tools such as SAST, SCA, secrets scanning, container and IaC scanning.
- Experience in regulated product development, ideally medical devices/FDA.
- Knowledge of FDA cybersecurity requirements, ISO 14971 and IEC 62304 is highly valuable.
Similar jobs
- RT
Chief Information Security Officer (CISO)
Ryde Technologies
Phoenix, AZ🇺🇸Remote6 weeks agoStakeholder ManagementAdministrative - NS
Firewall Engineer
Novul Solutions
Alexandria, VA🇺🇸Hybrid6 weeks agoEngineering - NG
Information Security Engineer (Security Engineering & Data Protection) - W2 Requirement(Remote)
NewNGTalentTech Group LLC
United States🇺🇸RemoteYesterdaySSOJavaScriptPowerShell+1Technology - AS
Senior Security Control Assessor
NewApex Systems
Washington, DC🇺🇸On-siteYesterdayAdministrative - MT
Lead Security Engineer
NewMicrogreen Technologies LLC
United States🇺🇸RemoteYesterdayAWSOWASPAzure+2Technology - ER
Cybersecurity Analyst
NewEmployees Retirement System Of Texas
Austin, TX🇺🇸On-siteYesterdayTDDHIPAATechnology