Req ID: 133574
Remote Position: No
Region: Americas
Country: Mexico
State/Province: Actual Leon
City: Monterrey
GENERAL OVERVIEW
Functional Area: Information Technology (ITM)
Career Stream: IT Solutions (SOLN)
Role: Specialist (SPE)
Job Title: Specialist, IT Solutions
Job Code: SPE-ITM-SOLN
Job Level: Band 8
Direct/Indirect Indicator: Indirect
SUMMARY
A Software Product Security role (often called Product Security Engineer or
ProdSec) is the bridge between traditional cybersecurity and software
engineering. Unlike IT security, which focuses on protecting the company's
internal network, Product Security focuses on ensuring the software the company
sells or provides is resilient against attacks.
DETAILED DESCRIPTION
The Product Security Engineer works directly with DevOps and Engineering teams
to bake security into the Software Development Life Cycle (SDLC). The goal is to
move security "left"—finding and fixing vulnerabilities during the design and
coding phases rather than after the product has launched.
KNOWLEDGE/SKILLS/COMPETENCIES
* * Secure Design & Threat Modeling: Reviewing new features before a single
line of code is written. You’ll identify potential attack vectors and
suggest mitigations.
* Vulnerability Management: Triaging bugs found via automated scanners,
internal audits, or Bug Bounty programs.
* Security Tooling: Implementing and managing tools like SAST (Static
Analysis), DAST (Dynamic Analysis), and SCA (Software Composition Analysis)
to catch insecure dependencies.
* Code Reviews: Performing manual "deep dives" into critical codebases to
spot logic flaws that automated tools might miss.
* Incident Response: Acting as a subject matter expert when a security flaw
is exploited in production.
* Internal Red Teaming: Lead activities to find ways to bypass the logic to
alter "Recipe" files or production data.
Developer Training: Creating "Security Champions" programs to teach engineers
how to write defensive code.