
Staff Product Security Engineer
- Draper, UT
- Permanent
- Full-time
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.How We Work:
At Proofpoint, you’ll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values: Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact.Corporate OverviewProofpoint is a leading cybersecurity company protecting organizations’ greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. Leading organizations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions mitigating their most critical risks across email, the cloud, social media, and the web.We are singularly devoted to helping our customers protect their greatest assets and biggest security risk: their people. That’s why we’re a leader in next-generation cybersecurity. Protection Starts with People.The RoleWe are looking for a seasoned Staff Product Security Engineer to lead and advance our product and application security initiatives. This role demands deep technical expertise across all facets of product security and secure software development, including significant experience working in FedRAMP-compliant environments. The ideal candidate will be hands-on, strategic, and serve as a security champion across product engineering teams. Based in Draper Utah, this key role will drive key product and application security initiatives for Proofpoint Product portfolio.Key Responsibilities
- Product Security Leadership: Define and implement product and application security strategies throughout the SDLC.
- Security Architecture & Design: Collaborate with product and engineering teams to design secure architectures for web, mobile, and cloud-based applications.
- Secure Development: Integrate security best practices into CI/CD pipelines, promote secure coding practices, and conduct code reviews and threat modeling sessions.
- Security Assessments: Lead and perform penetration testing, static/dynamic code analysis, and security reviews for internally developed and third-party applications.
- FedRAMP Compliance: Ensure security controls align with FedRAMP Moderate or High baselines and provide security documentation and support for FedRAMP audits and continuous monitoring.
- Tooling & Automation: Develop and maintain automated security testing tools, workflows, and integrations to scale security across product teams.
- Security Incident Response: Assist in investigation and remediation of security incidents related to products and applications.
- Support Security Compliance Initiatives: Support various Compliance initiatives such as SOC2, ISO27001
- Mentorship & Advocacy: Educate engineers on secure development practices, influence engineering culture, and act as a liaison between security and engineering teams.
- Experience: 8+ years in Cloud security engineering with a focus on application/product security; experience in FedRAMP-authorized environments is required.
- Technical Expertise: Deep understanding of OWASP Top 10, secure coding, threat modeling, authentication/authorization, cryptography, and cloud-native application security.
- Compliance Knowledge: Strong grasp of FedRAMP, NIST 800-53, and other regulatory frameworks.
- Experience with Data Governance and Securing AI applications desirable.
- Certifications: CISSP, CSSLP, GWAPT, or equivalent are a plus.
- Tools & Languages: Experience with tools like SAST/DAST, SCA, container security, and languages like Python, Java, JavaScript, or Go.
- Soft Skills: Strong communication and collaboration skills with the ability to drive cross-functional initiatives.
- US Citizen required.
- Competitive compensation
- Comprehensive benefits
- Learning & Development: We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.
- Flexible work environment: [Remote options, hybrid schedules, flexible hours, etc.].
- Annual wellness and community outreach days
- Always on recognition for your contributions
- Global collaboration and networking opportunities