GoMining
Posted 2w ago

Product Security Engineer

GoMining
Spain or Europe
RemoteFull Time
Responsibilities
  • securing systems
  • reviewing architecture
  • automating checks
Requirements
  • 4+ years in product/application/security engineering
  • Strong software engineering background
  • Experience with cloud platforms
  • Kubernetes/Docker
  • Secure SDLC
  • SAST/DAST, and fluent English
Technical tools mentioned
AWSGCPAzureKubernetesDockerSASTDASTCI/CDdependency scanningcontainer scanningsecret detectionOWASP Top 10

Job description

As our platform continues to scale, security becomes a core product capability rather than a separate function. We're looking for a Product Security Engineer who can partner directly with engineering teams to build secure systems from the ground up.

This is a highly technical, hands-on role where you'll improve the security of our applications, cloud infrastructure, APIs, and development lifecycle.

Responsibilities

Application Security

  • Review application architecture and new product features from a security perspective.
  • Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
  • Perform threat modeling and security design reviews.
  • Support internal and external penetration testing activities.

Secure Development

  • Build and improve Secure SDLC across engineering teams.
  • Integrate security tooling into CI/CD pipelines.
  • Improve developer security practices and provide technical guidance.
  • Help engineering teams remediate vulnerabilities.

Cloud & Infrastructure Security

  • Improve the security posture of our cloud infrastructure.
  • Secure Kubernetes environments, IAM policies, secrets management, and infrastructure components.
  • Implement security monitoring and hardening best practices.
  • Work closely with Platform and DevOps teams.

Security Automation

  • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection.
  • Automate security checks and developer workflows.
  • Continuously improve security visibility across the engineering organization.

Requirements

  • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
  • Strong software engineering background.
  • Experience securing backend systems, REST APIs, and microservices.
  • Experience with cloud platforms (AWS, GCP, or Azure).
  • Strong understanding of Kubernetes, Docker, networking, and infrastructure security.
  • Experience with Secure SDLC and security automation.
  • Hands-on experience with SAST, DAST, dependency scanning, and secrets management.
  • Understanding of OWASP Top 10, common attack vectors, and secure coding practices.
  • Ability to work closely with software engineers and influence technical decisions.
  • Fluent English.

Nice to have

  • Mobile application security experience.
  • Experience in fintech, crypto, payments, or blockchain.
  • Offensive security or penetration testing experience.
  • Security certifications are a plus but not required.

Benefits

  • Professional growth: support for courses, conferences, and English learning (up to 100% coverage).
  • Work-life fit: remote or hybrid format with flexible hours across international teams.
  • Paid leave: up to 20 vacation days +  8 company holidays + 5 personal days per year
  • Recognition programs: structured performance reviews and team awards.
  • Team culture: retreats in international locations (for example, company apartments in Cyprus).

About GoMining

Provides NFT-based access to Bitcoin mining hashrate.

Year founded
2017
Employees
300
Organization type
Private
Latest investment
Raised $3.00M Seed (2024) — led by Bitscale Capital
Headquarters
CZ

Similar jobs

Product Security Engineer roles
1w
Save
Mark Applied
Hide
Product Security Engineer — Mobile RASP
Spain
OnsiteFull Time
Ditto
Ditto: A digital trust providing identity, authentication, fraud prevention, and mobile threat defense solutions.
Hands-on software engineering with mobile SDKs, Python and Flask backend services, applied cryptography, code hardening, AWS, Docker, Git, CI/CD, RASP/MTD, OWASP standards, and professional English.
RASP, Python, Flask, REST, AWS, Docker, Git, GitHub Actions, GitLab CI, Jenkins, Jira, Swift, C, C++, Objective-C, Kotlin, Java, OWASP MASVS / MASTG, Frida, Xposed, Magisk, Claude Code, Copilot, Cursor, Promon, Bureau, Appdome, Guardsquare, Zimperium, Build38, SIEM, CI/CD, EMR
1w
Save
Mark Applied
Hide
Senior Product Security Engineer
Barcelona or Berlin or Vienna
HybridFull Time
N26
N26: Mobile-first digital banking services for personal and business accounts.
Advanced software engineering and application security expertise, including threat modeling, penetration testing, secure SDLC automation, cloud, web, mobile, AI, microservices, code analysis, fuzzing, and OWASP Top 10.
Python, Go, Generative AI (GenAI), Large Language Models (LLM), Secure Software Development Lifecycle (SSDLC), Software Development Lifecycle (SDLC), OWASP Top 10
3w
Save
Mark Applied
Hide
Staff Product Security Engineer, PSIRT
Barcelona, Catalonia, Spain
€74k-€101k/yr RemoteFull Time
Okta
OktaNASDAQ: OKTA: Provide secure identity management and authentication for enterprises.
6+ YOE6+ years in information/product security with experience in vulnerability management, incident response, application/product security, risk management, and technical communication.
4w
Save
Mark Applied
Hide
Product Security Engineer
Geneva or Paris or Barcelona
HybridFull Time
Proton
Proton: Providing end-to-end encrypted communication and storage tools.
10+ YOE10+ years in application security, leadership experience, hands-on code review and penetration testing, remediation execution, ability to communicate technical guidance to varied audiences.
Linux, Windows, macOS, iOS
1mo
Save
Mark Applied
Hide
Senior Product Security Engineer
Spain or Canada
€58k-€77k/yr RemoteFull Time
Mozilla
Mozilla: Developing open-source web browsers and digital privacy tools.
Experience building modern web applications, strong Python/Django backend skills, understanding of web security, collaboration in distributed teams, and working with cloud infrastructure.
React, TypeScript, Django, MySQL, Google Cloud
1mo
Save
Mark Applied
Hide
Principal Engineer, Product Security
Berlin or London or München or Valencia
HybridFull Time
commercetools
commercetools: SaaS platform for building enterprise headless commerce experiences.
5+ YOE5+ years hands-on product security, 2+ years leadership in product security, secure architecture and threat modeling, Linux, Kubernetes, Terraform, Vault, API security, DevSecOps, scripting in JavaScript or Go, strong communication.
Linux, Kubernetes, Terraform, Vault, API, JavaScript, Go, Static Analysis
1mo
Save
Mark Applied
Hide
Product Security Engineer
Spain or Europe
RemoteFull Time
Action1
Action1: Cloud-native platform for autonomous endpoint and patch management.
3+ YOE3+ years in product/application security or DevSecOps, strong software engineering background, cloud and API security, vulnerability management, SAST/SCA, threat modeling, and strong communication skills.
PSIRT, SAST, SCA, secrets scanning, SBOMs, AWS, C++, JavaScript, CI/CD, APIs
3w
Save
Mark Applied
Hide
Product Security Incident Response Engineer
Limerick or Valencia or Edinburgh
OnsiteFull Time
Analog Devices
Analog DevicesNASDAQ: ADI: Designs and manufactures semiconductors for signal processing and power management.
3+ YOE3+ years incident response experience, strong security fundamentals, ability to coordinate PSIRT activities, triage and remediate product vulnerabilities, communicate with researchers and stakeholders; bachelor’s degree preferred.