Software Product Security Engineer
W2 CONTRACT ONLY
Dearborn, MI | Accepting Local and Non-local
We are seeking a Software Product Security Engineer to serve as a trusted advisor between cybersecurity and software engineering teams. This role supports a portfolio of cloud-based applications, APIs, SaaS platforms, and modern web applications, helping development teams build secure solutions while balancing business objectives, delivery timelines, and risk management requirements.
The ideal candidate understands both software development and cybersecurity and can effectively communicate with engineers, DevOps teams, and business stakeholders. Rather than acting as a security enforcer, this individual serves as a consultative partner who helps teams make practical, risk-based security decisions throughout the Secure Software Development Lifecycle (SDLC).
Responsibilities
- Serve as the liaison between cybersecurity organizations and product/application development teams.
- Guide software teams through security findings, vulnerability remediation efforts, and risk mitigation strategies.
- Help development teams understand and implement security requirements, standards, and best practices.
- Evaluate security findings and determine true business risk based on impact, likelihood, and context.
- Facilitate risk acceptance discussions and help define compensating controls and remediation plans.
- Consult on application security, API security, cloud security, identity and access management (IAM), and secure development practices.
- Partner with engineering, DevOps, and business stakeholders to integrate security throughout the software development lifecycle.
- Support threat modeling activities, security reviews, and security requirements definition.
- Assist teams in modernizing applications while maintaining secure architectures and practices.
- Educate stakeholders on security risks, mitigations, and best practices.
- Build collaborative relationships across multiple teams and influence security outcomes through partnership rather than authority.
- Manage multiple initiatives and priorities in a dynamic, fast-paced environment.
Requirements
Required Qualifications
- Experience in Software Assurance, Product Security, Application Security, DevSecOps, Technical Risk Management, or a related field.
- Strong understanding of software development principles and modern application architectures.
- Ability to read and understand code and effectively communicate with software engineering teams.
- Strong understanding of secure SDLC methodologies and secure software development practices.
- Experience with threat modeling, vulnerability remediation, security requirements, and risk management.
- Knowledge of application security, cloud security, API security, and IAM concepts.
- Experience assessing and prioritizing risk using business context, likelihood, and impact.
- Strong communication, consulting, and stakeholder management skills.
- Ability to influence technical and business teams without direct authority.
- Self-starter capable of working independently with minimal direction.
- Proven ability to work effectively in ambiguous situations and solve complex problems.
- Ability to manage multiple workstreams and balance competing priorities.
Preferred Qualifications
- Experience supporting cloud-native applications, SaaS platforms, and modern web applications.
- Familiarity with Java, Spring Boot, React, JavaScript, and API-based architectures.
- Experience working with Azure, AWS, and/or Google Cloud Platform (GCP).
- Background in software engineering, cloud engineering, systems administration, security consulting, or DevSecOps.
- Experience partnering directly with development teams to drive secure design and remediation efforts.
#LI-WH1
#INDOEM
