BeyondTrust
Sr Product Security Engineer
Remote United States · Senior
Sponsorship not specifiedDetected 29 days ago
AWSKubernetesCI/CDLLMsCybersecurityPenetration TestingManual TestingResearchLeadershipCommunication
About the role
- We're hiring a Sr Product Security Engineer to do deep, hands-on security testing across BeyondTrust's product portfolio using AI as a force multiplier.
- Our Product Security organization operates AI-first.
Responsibilities
- AI-Driven Security Testing & Vulnerability Discovery Perform deep, context-aware penetration testing of web applications, APIs, endpoint agents, thick clients, identity systems, and cloud-native services.
- Threat Hunting Skills & Fuzz Factory Plugins Build AI-powered threat hunting skills and fuzz factory plugins using Claude and Codex.
- Develop custom fuzzers that understand product-specific protocols, input formats, and business logic.
- Create reusable skills and agent workflows that automate discovery of vulnerability classes across the product portfolio: injection paths, auth bypass patterns, privilege escalation chains, and cryptographic weaknesses.
- Proof-of-Concept Exploit Development Develop working proof-of-concept exploits for discovered vulnerabilities that demonstrate real impact in the product's deployment context.
- Use Claude and Codex to accelerate exploit development, generate payloads, and validate exploitation chains.
- A validated PoC with clear impact drives remediation
- Vulnerability Validation & Remediation Partnership Validate vulnerabilities from all sources: your own testing, SAST, SCA, third-party pen tests, bug bounty submissions, and security research.
- Confirm exploitability, assess severity in context, and deliver specific fix recommendations to engineering teams grounded in the codebase and deployment model.
- Security Tooling & Automation Build and maintain AI-driven security testing tooling integrated into CI/CD pipelines.
Requirements
- 5+ years in Product Security, or Penetration Testing with direct hands-on testing and exploit development
- Proficiency with penetration testing tools and methodologies (Burp Suite, custom scripts, fuzzing frameworks) combined with manual exploit validation
Skills
- Background in securing endpoint technologies, identity systems, privileged access management, or enterprise security platforms
- Experience with mobile application security testing and thick client assessments
- Familiarity with container security, Kubernetes security, and infrastructure-as-code scanning
- Experience working with bug bounty programs, vulnerability disclosure programs, or coordinated disclosure
- Professional certifications such as OSWE, OSCP, GWAPT, GPEN, or equivalent hands-on credentials
- Contributions to security research, open-source security tooling, or published vulnerability disclosures
- Validated findings include specific, implementable fix recommendations that engineering teams act on
- Offensive findings translate into measurable defensive improvements through partnership with Cyber Defense and Research
- Engineering and security leadership trust your severity assessments and prioritization recommendations
Benefits
- Work with Security Architects to identify emerging attack techniques relevant to BeyondTrust's product surface and build proactive testing coverage for them.
Company info
- BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
- Learn more at www.beyondtrust.com.
- BeyondTrust is the global identity security leader protecting Paths to Privilege™.
- Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies.
- We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
Apply directly at BeyondTrust →Create a free account for alerts like thisView BeyondTrust immigration profile
This listing is sourced directly from BeyondTrust's careers page and normalized into a canonical job model.