← Sottava, jobs the hour they open
1 mo agofound 4 h ago
Staff Product Security Engineer
What the posting is about
Extend our Product Security capability with a focus on continuous vulnerability discovery and prevention. Build and execute security regression testing, drive threat modeling, and conduct offensive security activities. Collaborate with engineering teams to ensure security in existing and new functionality.
Read out of the posting
Levelmid
Experience asked5+ years
EmploymentFull time
LocationLisbon, Portugal
RemoteNot stated
Visa sponsorshipNot stated
SalaryNot published, and most postings do not
Posted2026-08-25
Found viasmartrecruiters, direct from their system
We saw it 1 month after it went up.
The posting, as the company wrote it
Employment: Full-time
Experience level: Mid-Senior Level
Job Description
Why A365 Software Engineering?
Build the cloud platform that’s transforming electronics design. Altium 365 for cloud lets design engineers communicate, collaborate and bring their ideas to market more efficiently than any platform in the industry.
 
We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention.
This role is responsible for:
Building and executing security regression testing
Driving threat modeling across existing and new functionality
Conducting targeted offensive security activities (Red Team–style testing)
Identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks
The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.
 
Key Responsibilities
Security Regression Testing Design and maintain security regression test suites covering critical application flows
Ensure vulnerabilities, once fixed, are permanently prevented from recurring
Integrate security regression into CI/CD pipelines
Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
Threat Modeling Lead structured threat modeling sessions for: Existing system components
New features and architectural changes
Identify attack surfaces, abuse cases, and trust boundaries
Translate threats into: Test cases
Security requirements
Mitigation plans
Ensure threat modeling becomes a continuous lifecycle activity
Offensive Security / Red Team Activities Perform manual and automated security testing simulating real attacker behavior
Focus on high-impact vulnerabilities, not theoretical findings
Validate exploitability and business impact
Partner with engineering teams to: Reproduce issues
Prioritize fixes
Validate remediation
OWASP Top 10–Driven Vulnerability Discovery Continuously assess the platform against OWASP Top 10 categories
Use deep product knowledge to find non-obvious, context-specific vulnerabilities
Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
Security Assurance for Product Changes Review new features and changes for security risks
Ensure all changes are: Threat-modeled
Covered by regression tests
Act as a security gatekeeper without becoming a bottleneck: Enable teams with guidance and tooling
Avoid heavy process overhead
Collaboration & Enablement Work closely with: Engineering teams
Architecture
SRE / Platform teams
Contribute to secure-by-design practices
Support developers in understanding and fixing vulnerabilities
Help scale security through: Reusable patterns
Automation
Security guidance
Qualifications
Required Qualifications
5+ years in Application / Product Security
Bachelor's Degree or equivalent of 12 years of work experience 
Strong hands-on experience in: Web application security testing
API security
Threat modeling methodologies
Deep understanding of OWASP Top 10
Experience with: Manual penetration testing
Security regression testing
CI/CD security integration
Ability to identify business logic vulnerabilities
Strong understanding of: Authentication, authorization, and session management
Multi-tenant architectures
Cloud-native systems
Preferred Qualifications
Experience in SaaS / multi-tenant platforms
Familiarity with: Bug bounty programs
Red teaming
Security automation frameworks
Knowledge of: AWS
Identity systems and federation (SSO, MFA)
Background in software engineering (ability to read/write code)
 
Additional Information
Altium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software-defined world with our industry-first cloud-based platform that unites every stakeholder and phase of electronics development.
From startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.
We believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process.
Copied from Renesas’s own board, not rewritten. Original ↗
Also open at Renesas
Why this page exists
We read companies’ own hiring systems every hour, 1,182 of them, and show a job the hour it opens instead of when a job board gets around to indexing it. We saw it 1 month after it went up.
The feed is free. No card, no trial to expire.