Sr Product Security Engineer - Devices

Optimum - Bethpage, NY

Hiring: Sr Product Security Engineer - Devices Company: Optimum Location: Bethpage, NY Job Posted Time: 2026-09-12 07:42:40 Target Skills & Keywords : Android, C++, CI/CD, Embedded Systems, Firmware, Go, Java, Linux, Node.js, OWASP, PKI, Penetration Testing, Python, SBOM, SaaS, iOS About the job Experience: •5+ years of hands-on experience in software engineering and designing and delivering security-critical systems for internet-connected embedded devices. Required Skills: •Partner cross-functionally with engineering and product teams to integrate security and secure-by-default guardrails into the product lifecycle, ensuring that security is a core consideration in all design and development decisions. •Conduct Threat Modeling and Risk Assessments from the early stages of the product development lifecycle to identify, assess, and prioritize security risks, enabling proactive mitigation strategies. •Perform rigorous security testing and reviews to uncover and address security weaknesses. •Lead initiatives automating security processes from the developer workstation to cloud, SaaS, and datacenter environments. •Foster a security-first culture by educating and empowering engineering and product teams through training, awareness campaigns, and mentorship, cultivating a strong security mindset. •Stay updated on the latest security threats, vulnerabilities, and technology trends, and proactively implement improvements. •Contribute to incident response efforts, investigate root causes, and implement corrective actions to minimize impact and prevent future occurrences. •Conduct penetration testing, reverse engineering, and vulnerability research against firmware, hardware interfaces, and device software to surface real-world attack paths before adversaries do. Qualifications: •Bachelor’s degree in Computer Science, Electrical Engineering, or a related field. Master’s degree is a plus. •Proven expertise in embedded systems and product security, with a strong understanding of modern software development processes and methods, security best practices, threat modeling, and risk assessment. •Excellent communication skills, both written and verbal, and the ability to communicate complex security concepts to technical and non-technical audiences, including senior leadership. •Proven ability to establish credibility and build trust with engineers and operational staff. •Expertise in conducting comprehensive threat modeling, risk assessments, and code reviews to identify and mitigate vulnerabilities. •Proficiency in secure SDLC practices and practical experience with CI/CD pipelines and DevOps tools. •In-depth knowledge of cryptography and key management use cases. •In-depth knowledge of networking protocols, peripheral and firmware security, secure boot, embedded Linux security, Android or iOS security, and PKI. •Proficiency in C and C++ for embedded software development and one or more modern programming languages like Golang, Python, Node, and Java. •Applied hands-on capability in hardware-level security testing techniques, including JTAG/SWD, UART, SPI/I2C debug interfaces, firmware extraction, fault injection, and side-channel analysis. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!