Principal Product Security Engineer
MYOBAccounting & company
Melbourne, AustraliaSenior
KKR
Software Engineering
About the role
TL;DR
Manage security for assigned business domains, embedding into the lifecycle of SaaS products.
- •Breaking things is fun.
- •Designing controls to avoid bugs
- •that's the real challenge.
- •If you've spent your career hunting bugs or triaging endless appsec backlogs, you've probably thought “If I could just get in earlier”.
- •Welcome to your next move! Key Responsibilities Own Your Domain: Partner directly with product and leadership teams to define practical security requirements throughout the software lifecycle.
- •Move Beyond the Checklist: Lead threat and security architecture reviews with direct product feedback and actionable outcomes for fast-moving cloud products.
- •Empower: Work side-by-side with product teams, improve processes and mentor teams on security best practices.
- •Make it count: You have the autonomy to experiment, create better workflows, build better tools, patterns and trial new technologies that scale without slowing things down.
- •Requirements The AppSec or Pentest: You have a deep understanding of application security.
- •You know your way around code, modern web apps, contemporary architectures and SaaS infrastructure.
- •You're ready to channel that "attacker mindset" into helping us build resilient software.
- •The change excites you: You are comfortable operating with vague requirements and diverse day-to-day.
- •Risk discussion with tech-leadership at 1:00pm, dive into security architecture review at 3pm.
- •The pragmatist: You understand that security does not exist in a vacuum.
- •You collaborate, build rapport, ask for help when you need it and design creative realistic solutions that balance risk with shipping features.
- •Autonomy: You are a self-starter with a give it a go attitude.
- •You are up to date with security trends, you are not afraid to make a call and own your decisions.
Required skills
OAuthJWTSAMLOWASPPenetration TestingSOC 2GDPRHIPAAVaultIAMSSOMFA
Domain expertise
cybersecurity
Tech stack
OAuthJWTSAMLOWASPPenetration TestingSOC 2GDPRHIPAAVaultIAMSSOMFA