What are the responsibilities and job description for the Product Security Engineer position at IBOTIX US Inc.?
Software Product Security Engineer
Location: Dearborn, MI (4 days onsite, 1 remote)
Duration: Ongoing long term
Visa: No H-1bs, OPT is fine
W2 Role No C2C
Additional Information:
Overall, we are looking for someone who can understand the developer's perspective while also bringing a strong cybersecurity and risk-management mindset. The ideal candidate is someone who can sit in the middle, understand the technical details, work through the grey areas, and help the development/business teams arrive at the right security decision
Software Product Security Engineer
Position Description:
- Guide development teams to triage and remediate findings from SAST, DAST, SCA, and bug bounty/vulnerability reports.
- Serve as a trusted liaison between engineering and security stakeholders, translating risk into practical, prioritized action.
- Consult on secure architecture, API security, IAM, logging, and secure coding practices across cloud platforms (Azure, Google Cloud Platform, AWS). Integrate and automate security testing within CI/CD pipelines alongside platform and DevOps teams.
- Help teams manage technical debt, upgrade paths, and software supply chain/SBOM risks. Communicate complex technical risk clearly to both engineers and business stakeholders without creating panic or friction.
- This position will leverage broad experience and a jack of all trades in IT maybe an ideal candidate. The team handles compliance activities for cybersecurity so experience there is a plus.
Skills Required:
- Scripting, User Stories, Troubleshooting (Problem Solving), Data/Analytics dashboards, Software Development Lifecycle, Software Development, Web Development, TCP/IP, Data Integrity, Microsoft Office, Web Applications, Web Technologies, Cyber Security, Data Modeling, Developer, SharePoint, Web Design & Development
Skills Preferred:
- Tooling, Disaster Recovery, Risk Management, Spring Security, Solution Architecture, Software Development Lifecycle, AIPGEE, Coding, JavaScript, KANBAN, Linux, Network Protocols & Standards, Penetration Testing, J2EE, Salesforce, Spring Boot, Change control , Cloud Computing, Dynatrace, Apache Tomcat, Application Development, Cloud Infrastructure, Computer Security, Google Cloud Platform, ISO 27001, Pega, Problem Solving, React, Application Architect, Burp Suite, Configuration Management, JQuery, Network Security, Java, Analytical skills, Application Design, Business Risk Mgt, IAM, Information Security, JSON, Python, Risk Assessment
Experience Preferred:
- Certifications are highly valued (CISSP, CISA, CISM, etc.)
Education Required:
- Bachelor's Degree