Senior Product Security Engineer

2 days ago


Boston, United States CloudZero Full time

About the Role:
CloudZero is seeking our first Senior Product Security Engineer. In this pivotal role, you will shape the security framework of our market-leading cloud cost intelligence platform, addressing some of the most critical challenges cloud-driven businesses face today. You will establish and champion best-in-class security practices, ensuring our platform remains resilient and our customers’ sensitive data is always safeguarded.

Collaborating closely with our engineering teams, you will design and implement secure development processes, identify and address vulnerabilities, and foster a security-first mindset throughout our product lifecycle. This is a unique opportunity to make a foundational impact on the security of an innovative, fast-growing company by building scalable, proactive solutions that protect both our platform and the customers who trust us.

Responsibilities:

  • Drive Security By Design 
    • Drive and influence the inclusion of security in product design and development. 
    • Partner with the software engineering team to champion secure coding practices, ensuring automated code reviews identify and address risks early in development.
    • Develop and integrate security automation into the CI/CD pipeline to enable scalable and consistent security testing across the software development lifecycle.  
  • Training & Enablement
    • Develop application specific security training for our engineering organization. 
    • Build and drive adoption of security champions programs across the engineering organization. 
  • Vulnerability and Risk Management
    • Implement and enforce vulnerability and risk management policies. 
    • Lead threat modeling exercises to uncover potential risks and ensure mitigation strategies are integrated into the product design. 

Requirements

  • 3-5+ years of Python experience.
  • Knowledgeable with AWS, GCP, Azure and Snowflake. 
  • Proven expertise with application security testing tools, such as Burp Suite.
  • Strong understanding of OWASP Top 10.
  • Familiarity with SCA tools (e.g., Snyk, Dependency-Check) to manage open-source security risks.
  • Knowledge and experience securing CI/CD pipelines (Github Actions, Jenkins etc.) 
  • Strong understanding of secure coding practices, vulnerability management
  • Familiarity with threat modeling frameworks and experience applying them to real-world applications.
  • Exceptional communication skills, with the ability to explain technical concepts to developers, executives, and non-technical stakeholders.
  • A proactive mindset with a passion for enabling developers to adopt secure practices without friction.
  • Ability to participate in our incident response team on-call rotation.

About CloudZero
Cloud cost management is one of the biggest challenges organizations face today. As cloud adoption continues to accelerate, so do the complexities and costs associated with it — and macroeconomic conditions only increase pressure to prove cloud efficiency. That’s why we built CloudZero: a SaaS platform at the intersection of next-generation cloud cost management and FinOps. CloudZero ingests billing and usage data from all cloud, SaaS, and PaaS providers, organizes it in real time according to our customers’ business structures, lets customers view it at any level of time or resource granularity, and ultimately empowers them to make more informed business decisions.

Since our founding in 2016, our mission has been to make efficient innovation a reality for every cloud-driven organization. At CloudZero, we believe every engineering decision is a buying decision, yet the cost conversation often bypasses the engineers who drive those determinations. To solve this, we’ve built a dynamic, single-page application that answers the complex, data-heavy questions every cloud-based organization needs to ask if they want to grow their company profitably.

To date, we’ve raised over $52 million from leading venture capital firms across the country. We’re solving problems of massive scale, business importance, and complexity in a space that needs it more than ever. We’re growing rapidly and would love for you to be a part of it

Equal Opportunity Employer

CloudZero is an equal opportunity employer and values diversity. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status or disability status. All job offers are contingent upon the candidate passing background and reference checks.


**Applicants must be authorized to work for ANY employer in the United States. We are unable to sponsor or take over sponsorship of an employment Visa at this time.**



  • Boston, United States Snyk Full time

    Job DescriptionJob DescriptionEvery day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced "sneak") comes in. Snyk is a developer security platform that...


  • Boston, United States ZipRecruiter Full time

    Job DescriptionJob Description About the Role: CloudZero is seeking our first Senior Product Security Engineer. In this pivotal role, you will shape the security framework of our market-leading cloud cost intelligence platform, addressing some of the most critical challenges cloud-driven businesses face today. You will establish and champion best-in-class...


  • Boston, United States CloudZero Full time

    Job DescriptionJob DescriptionAbout the Role:CloudZero is seeking our first Senior Product Security Engineer. In this pivotal role, you will shape the security framework of our market-leading cloud cost intelligence platform, addressing some of the most critical challenges cloud-driven businesses face today. You will establish and champion best-in-class...


  • Boston, United States CloudZero Full time

    About the Role:CloudZero is seeking our first Senior Product Security Engineer. In this pivotal role, you will shape the security framework of our market-leading cloud cost intelligence platform, addressing some of the most critical challenges cloud-driven businesses face today. You will establish and champion best-in-class security practices, ensuring our...


  • Boston, MA, United States Snyk Full time

    Every day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced “sneak”) comes in. Snyk is a developer security platform that makes it easy for...


  • Boston, United States Red Hat Full time

    Senior Product Security Engineer - AI CVE Exploitability At Red Hat, we connect an innovative community of customers, partners, and contributors to deliver an open source stack of trusted, high-performing solutions. We offer cloud, Linux, middleware, storage, and virtualization technologies, together with award-winning global customer support, consulting,...


  • Boston, United States Amazon Full time

    Senior Security Engineer, Corporate Services SecurityJob ID: 2853174 | Amazon.com Services LLCCorporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal, and Global Communications and Community Impact (GCCI) business units.Our Mission is to protect and...


  • Boston, United States Amazon Full time

    Senior Security Engineer, Corporate Services SecurityJob ID: 2853174 | Amazon.com Services LLCCorporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal, and Global Communications and Community Impact (GCCI) business units.Our Mission is to protect and...


  • Boston, United States Semgrep Full time

    SemgrepFind bugs, run security scans in CI, and enforce security standards across your organization.Our mission is to make world-class software security available to everyone. This means building program analysis tools that are open source, easy to use, powerful, and fast. It also means building a team with security expertise and a passion for great...


  • Boston, United States Manulife Full time

    Manulife Senior Cloud Security Engineer Boston, Massachusetts Apply NowManulife is looking for a hands-on Senior Cloud Security Engineer with a passion for Cloud Security, Application Security, and DevSecOps. The senior engineer will be reporting to the Principal Engineer. The ideal applicant will produce an autonomous policy-driven security strategy to...


  • Boston, Massachusetts, United States Medtronic Full time

    Senior Principal Cybersecurity EngineerMedtronic seeks a seasoned Senior Principal Cybersecurity Engineer to lead its efforts in embedding security into the product development lifecycle. This individual will play a critical role in ensuring the robust security of our medical device products and solutions.Key Responsibilities:Product Security Strategy:...


  • Boston, United States Sea Machines Full time

    Job DescriptionJob DescriptionSea Machines is a fast-growing startup that is leading the new high-tech sector of autonomous technology for marine vessels. We are passionate about applying practical A.I. to the massive global ocean transportation market. Our products provide ships and workboats the intelligence to work remotely and give maritime operators the...


  • Boston, United States Sea Machines Full time

    Job DescriptionJob DescriptionSea Machines is a fast-growing startup that is leading the new high-tech sector of autonomous technology for marine vessels. We are passionate about applying practical A.I. to the massive global ocean transportation market. Our products provide ships and workboats the intelligence to work remotely and give maritime operators the...


  • Boston, United States Amazon Full time

    Senior Security Engineer, Corporate Services SecurityJob ID: 2853174 | Amazon.com Services LLCCorporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal, and Global Communications and Community Impact (GCCI) business units.Our Mission is to protect and...


  • Boston, United States Analog Devices, Inc. Full time

    Senior Director Product AI EngineeringAnalog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologies into solutions that help drive advancements in digitized factories, mobility, and digital healthcare,...


  • Boston, United States North Eastern Services Full time

    Sea Machines is a fast-growing startup that is leading the new high-tech sector of autonomous technology for marine vessels. We are passionate about applying practical A.I. to the massive global ocean transportation market. Our products provide ships and workboats the intelligence to work remotely and give maritime operators the tools to effectively...


  • Boston, United States Analog Devices Full time

    Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologies into solutions that help drive advancements in digitized factories, mobility, and digital healthcare, combat climate change, and reliably...


  • Boston, United States Boston Red Sox and Fenway Sports Management Full time

    DEPARTMENT OVERVIEW: The Information Technology department provides strategic direction and day-to-day IT operational, software and emerging technology supporting the Red Sox, Fenway Sports Management, the Red Sox Foundation, and FSG Real Estate. Responsibilities include support for corporate and ballpark infrastructure, systems architecture, networks,...

  • Senior Engineer

    10 hours ago


    Boston, United States PetsApp Full time

    About VendVend is an integrated software, payments, and operations company revolutionizing how real estate owners, tenants, and visitors interact with parking. By combining the latest technology with a modern business model, we deliver transparency, efficiency, and smarter operations that enhance the parking experience while driving significant value for...


  • Boston, Massachusetts, United States Medtronic Full time

    Senior Principal Product Security EngineerMEDTRONIC is searching for a seasoned Senior Principal Product Security Engineer to be part of its Surgical Operating Unit (OU) team. This key position will have a significant impact on the security of our medical device products and solutions.Job DescriptionThe Senior Principal Product Security Engineer is...