Senior Product Security Engineer
United Talent AgencyAbout the role
UTA seeks a Senior Product Security Engineer to help embed security into the design, development, and operation of our products and platforms. In this role, you will work closely with engineering, product, and security teams to design and implement security controls across our applications and services, safeguarding our brand, our people, and our digital assets. If you are passionate about building secure products from the ground up and enjoy operating at the intersection of software development and cybersecurity, this role offers the opportunity to meaningfully shape UTA’s product security posture.
The salary range for this role is $160,000 to $200,000 commensurate with experience and skills.
What You Will Do
Product security strategy & architecture
Lead security design and architecture reviews for new and existing products, including web, mobile, and cloud-based custom applications, and provide clear, actionable recommendations
Partner with product and engineering leadership to define product security requirements, risk tolerances, and security roadmaps across multiple teams and initiatives
Conduct and facilitate threat modeling workshops to proactively identify emerging risks and attack vectors and drive mitigations into product design
Conduct security reviews for products and services deployed across AWS, Azure, and GCP including cloud-native architectures, and platform-specific security controls
Secure development lifecycle & testing
Own and mature the application and product security lifecycle, including threat modeling, secure design, secure coding practices, testing, and release validation
Assess and secure early-stage product design, architecture and workflows, associated with rapid prototyping and deployment
Drive the adoption of automated security checks in CI/CD pipelines (SAST, DAST, SCA, secrets scanning, etc.) and ensure they are tuned to balance risk reduction with developer velocity
Lead and coordinate application security testing efforts, including tool-based and manual reviews, and work closely with development teams to prioritize and remediate findings
Establish and evangelize secure coding standards, patterns, and reusable frameworks that can be leveraged across engineering teams
Lead API security assessments, including authentication/authorization validation for REST/GraphQL APIs and API gateway configuration reviews
Operations, monitoring & incident response
Collaborate with security operations to ensure product-related logs, alerts, and events are captured, correlated, and integrated into monitoring and incident response workflows
Own vulnerability triage and management for product and application findings, including those surfaced through penetration tests and attack surface monitoring, covering risk assessment, remediation planning, and validation of fixes
Ensure products handle sensitive data appropriately, including data classification, storage, transit, and retention practices aligned with organizational security requirements
Tooling, enablement & leadership
Evaluate, select, and help implement product security focused tools and services, influencing build vs buy decisions
Develop documentation, playbooks, and training to raise the overall level of security awareness and capability across product and engineering teams
Provide best practices on the secure use of AI-assisted development tools, including risks around dependency integrity, code suggestions, and agent-driven changes
What You Will Need
Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field; or equivalent practical experience
5+ years of experience in security engineering, application security, or product aligned security roles, with a track record of owning and driving security initiatives
Deep understanding of common web, mobile, and API vulnerabilities (e.g., OWASP Top 10) and practical experience preventing and remediating them at scale
Strong experience securing applications and services in at least one major cloud provider (AWS preferred), including cloud native architectures
Hands on experience with application security tooling (SAST, DAST, SCA, secret scanning, WAF, or similar) and integrating these into CI/CD workflows
Familiarity with secure deployment practices, including Infrastructure-as-Code review of Terraform, CI/CD pipeline security (GitHub Actions), and secre
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s