Product Security Engineer
Posted 10 days ago · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
- In-depth knowledge of Secure Development Life Cycle (SDLC) processes, secure architecture, third-party tools, and security policies
- Threat modeling & secure design - Ability to review architectures, identify abuse cases, and guide developers on secure design decisions
- Expertise in identifying, analyzing, and mitigating security vulnerabilities, including familiarity with CVE and CVSS
- Hands-on experience with AppSec tooling - SAST, DAST, SCA (e.g., SonarQube, Snyk, JFrog Xray), including tuning, triaging results, and integrating into CI/CD pipelines
- Experience with vulnerability management and the ability to interpret and apply security standards, guidelines, and regulations
- Prior experience in software development
Extracted from the job description · kept up to date automatically
Who this suits
Full job description
Original listing · kept for referenceWhy Join Us?
We are looking for a Security Lead to join Check Point’s R&D organization, taking a central, cross-functional role in shaping the security posture of our products. This role combines deep hands-on expertise with cross-organizational leadership, working closely with senior leaders to shape and implement security strategy across all product lines. You will lead end-to-end security initiatives, influence engineering practices at scale, and play a critical role in ensuring our products meet the highest security standards.
Key Responsibilities
• Lead security in the R&D organization by professionalism and cooperation across Check Point
• Maintain and develop the Secure Development Life Cycle of all Check Point’s Products Organization, work with R&D, QA, Sales, Support, external researchers, and customers to make the cyber landscape a safer place.
• Conduct architectural security reviews and threat modeling for R&D
• Full triage for Check Point's VDP and BBP reports, including analyzing reports, calculating severities and communications with reporters.
• Define and develop security training to implement cross organization
• Be a first responder in security incidents, including leading and defining actions to resolution
• Manage and monitor Check Point's SCA, SAST, DAST tools
Qualifications
• Proven ability to lead and influence leaders across the organization.
• In-depth knowledge of Secure Development Life Cycle (SDLC) processes, secure architecture, third-party tools, and security policies.
• Threat modeling & secure design - Ability to review architectures, identify abuse cases, and guide developers on secure design decisions early in the lifecycle.
• Expertise in identifying, analyzing, and mitigating security vulnerabilities, including familiarity with Common Vulnerabilities and Exposures (CVE) and the Common Vulnerability Scoring System (CVSS).
• Hands-on experience with AppSec tooling - SAST, DAST, SCA (e.g., SonarQube, Snyk, JFrog Xray), including tuning, triaging results, and integrating into CI/CD pipelines.
• Experience with vulnerability management and the ability to interpret and apply security standards, guidelines, and regulations.
• Proficiency in secure coding practices and the ability to conduct code reviews for security vulnerabilities.
• Familiarity with incident response processes, security monitoring, and threat intelligence.
• Offensive mindset - Ability to think like an attacker (manual testing, basic exploitation techniques) to validate real impact and reduce false positives.
Advantage
• Prior experience in software development.
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- In-depth knowledge of Secure Development Life Cycle (SDLC) processes, secure architecture, third-party tools, and security policies, Threat modeling & secure design - Ability to review architectures, identify abuse cases, and guide developers on secure design decisions, Expertise in identifying, analyzing, and mitigating security vulnerabilities, including familiarity with CVE and CVSS, Hands-on experience with AppSec tooling - SAST, DAST, SCA (e.g., SonarQube, Snyk, JFrog Xray), including tuning, triaging results, and integrating into CI/CD pipelines, Experience with vulnerability management and the ability to interpret and apply security standards, guidelines, and regulations