Jobs and Careers
UN

Senior Product Security Engineer

United Talent Agency
Beverly Hills, United Statesfull_timeVerifiedPosted 17 Jul 2026
💰 $200,000/yr($160,000/yr$200,000/yr)

About the role

UTA seeks a Senior Product Security Engineer to help embed security into the design, development, and operation of our products and platforms. In this role, you will work closely with engineering, product, and security teams to design and implement security controls across our applications and services, safeguarding our brand, our people, and our digital assets. If you are passionate about building secure products from the ground up and enjoy operating at the intersection of software development and cybersecurity, this role offers the opportunity to meaningfully shape UTA’s product security posture.

 

The salary range for this role is $160,000 to $200,000 commensurate with experience and skills.

 

What You Will Do

 

Product security strategy & architecture

  • Lead security design and architecture reviews for new and existing products, including web, mobile, and cloud-based custom applications, and provide clear, actionable recommendations

  • Partner with product and engineering leadership to define product security requirements, risk tolerances, and security roadmaps across multiple teams and initiatives

  • Conduct and facilitate threat modeling workshops to proactively identify emerging risks and attack vectors and drive mitigations into product design

  • Conduct security reviews for products and services deployed across AWS, Azure, and GCP including cloud-native architectures, and platform-specific security controls

 

Secure development lifecycle & testing

  • Own and mature the application and product security lifecycle, including threat modeling, secure design, secure coding practices, testing, and release validation

  • Assess and secure early-stage product design, architecture and workflows, associated with rapid prototyping and deployment

  • Drive the adoption of automated security checks in CI/CD pipelines (SAST, DAST, SCA, secrets scanning, etc.) and ensure they are tuned to balance risk reduction with developer velocity

  • Lead and coordinate application security testing efforts, including tool-based and manual reviews, and work closely with development teams to prioritize and remediate findings

  • Establish and evangelize secure coding standards, patterns, and reusable frameworks that can be leveraged across engineering teams

  • Lead API security assessments, including authentication/authorization validation for REST/GraphQL APIs and API gateway configuration reviews

 

Operations, monitoring & incident response

  • Collaborate with security operations to ensure product-related logs, alerts, and events are captured, correlated, and integrated into monitoring and incident response workflows

  • Own vulnerability triage and management for product and application findings, including those surfaced through penetration tests and attack surface monitoring, covering risk assessment, remediation planning, and validation of fixes

  • Ensure products handle sensitive data appropriately, including data classification, storage, transit, and retention practices aligned with organizational security requirements

 

Tooling, enablement & leadership

  • Evaluate, select, and help implement product security focused tools and services, influencing build vs buy decisions

  • Develop documentation, playbooks, and training to raise the overall level of security awareness and capability across product and engineering teams

  • Provide best practices on the secure use of AI-assisted development tools, including risks around dependency integrity, code suggestions, and agent-driven changes

 

What You Will Need

 
  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field; or equivalent practical experience

  • 5+ years of experience in security engineering, application security, or product aligned security roles, with a track record of owning and driving security initiatives

  • Deep understanding of common web, mobile, and API vulnerabilities (e.g., OWASP Top 10) and practical experience preventing and remediating them at scale

  • Strong experience securing applications and services in at least one major cloud provider (AWS preferred), including cloud native architectures

  • Hands on experience with application security tooling (SAST, DAST, SCA, secret scanning, WAF, or similar) and integrating these into CI/CD workflows

  • Familiarity with secure deployment practices, including Infrastructure-as-Code review of Terraform, CI/CD pipeline security (GitHub Actions), and secre

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

United Talent Agency

View company profile →