- Company Name
- Omilia
- Job Title
- Senior Product Security Analyst
- Job Description
-
Job title: Senior Product Security Analyst
Role Summary: Independent senior security contributor responsible for end‑to‑end ownership of product and application security across design, development, release, and incident response. Provides risk‑based guidance, approves or blocks releases, and drives continuous improvement of security practices in a fast‑growing environment.
Expactations: • Lead security reviews for assigned products and services. • Actively assess and mitigate risks before release. • Collaborate with engineering, product, cloud, and platform teams to embed secure‑by‑design principles. • Ensure compliance with PCI DSS, GDPR, and internal security standards. • Maintain up‑to‑date knowledge of threat landscape, vulnerability trends, and industry best practices. • Communicate risk, trade‑offs, and remediation options clearly to technical and non‑technical stakeholders.
Key Responsibilities: • Conduct architecture reviews, threat modeling, and secure design validation for APIs, microservices, and SaaS platforms. • Own vulnerability triage and prioritization; translate SAST, DAST, SCA, and manual findings into actionable remediation. • Monitor external threat feeds and assess relevance to products. • Investigate and support remediation of security incidents. • Partner with SDLC teams to enforce secure‑by‑design controls and evolve application security guardrails. • Coordinate penetration testing, bug bounty, and third‑party assessments, ensuring timely closure. • Translate compliance requirements into engineering controls and support audit evidence collection. • Build relationships across product, engineering, cloud, platform, and CGRC functions; influence security maturity and best practices.
Required Skills: • 5+ years application/product security experience. • Deep understanding of secure SDLC, OWASP Top 10, threat modeling, and vulnerability management. • Experience with SAST, DAST, SCA, and manual security testing. • Practical knowledge of cloud‑native SaaS (AWS preferred) and microservice architectures. • PCI DSS and GDPR familiarity; ability to operationalize compliance. • Strong analytic, judgment, and decision‑making skills. • Excellent verbal and written English communication; ability to engage engineers and business stakeholders. • Agile/iterative development experience; cross‑team collaboration.
Required Education & Certifications: • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field (preferred). • Relevant security certifications (e.g., CISSP, CEH, OSCP, CGCS) considered an advantage.