jobs in Selby Jennings

Selby Jennings Hiring! Full Time Product Security Engineering Lead (Shift-Left) in Hong Kong - Ricebowl

Product Security Engineering Lead (Shift-Left)

Selby Jennings

Undisclosed

Hong Kong

Share
Save

Working Location

  • Hong Kong Hong Kong Hong Kong

Job Description

Responsibilities

  • Define, implement, and validate security controls, architecture patterns, and reference designs across cloud, on-premises, and colocation environments.
  • Review infrastructure, platforms, applications, and technical configurations against internal security baselines, industry standards, and relevant regulatory requirements.
  • Conduct threat-modelling exercises and technical risk assessments for new and existing products, platforms, and technology initiatives.
  • Identify attack paths, design weaknesses, vulnerabilities, and control gaps, and recommend proportionate mitigation strategies.
  • Perform secure code reviews and work with engineering teams to address security issues before applications and services are released into production.
  • Review technical designs, functional requirements, and solution architectures to identify potential security weaknesses at an early stage.
  • Embed security controls, tools, and processes throughout the software development lifecycle.
  • Assess security vulnerabilities across AWS services, on-premises systems, data stores, APIs, enterprise applications, and supporting infrastructure.
  • Support the integration and improvement of security testing capabilities, including static analysis, dynamic testing, dependency scanning, container scanning, and infrastructure security assessments.
  • Contribute to the development of security tooling, automation, internal frameworks, and engineering-led security capabilities.

Requirements

  • Between five and ten years of experience in product security, application security, security architecture, security engineering, or security research.
  • Strong understanding of software and product security principles, attack techniques, defensive controls, and secure development practices.
  • Proven experience conducting threat modelling, technical risk assessments, and security design reviews.
  • Experience developing practical mitigation strategies for complex technical and architectural risks.
  • Strong technical foundation in software development, engineering, or computer science.
  • Proficiency in one or more programming or scripting languages, together with experience using relevant security tools.
  • In‑depth knowledge of common vulnerabilities affecting applications, APIs, networks, cloud environments, infrastructure, containers, and platforms.
  • Strong experience reviewing technical designs, architecture diagrams, and functional requirements to identify security weaknesses.
  • Experience conducting source-code reviews and explaining security vulnerabilities clearly to software engineers.
  • Good understanding of cloud security, particularly within AWS environments.
  • Familiarity with secure software development lifecycle practices and modern DevSecOps tooling.
#J-18808-Ljbffr

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More