Staff Product Security Engineer

UpGuard
Sydney, Brisbane, Melbourne
Workplace: RemoteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Ownership","Collaboration","Pragmatic trade-offs","Incident response"]

Own and scale product security at UpGuard as the first dedicated hire. Lead threat modeling and security reviews across products, cloud infrastructure, and SDLC workflows, building automation like policy-as-code and AI-driven tooling to shift security left. Harden secure-by-default configurations for GCP and Kubernetes using infrastructure-as-code, manage vulnerabilities end-to-end by real risk, and build detection/response capabilities in a cloud-native environment.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
UpGuard
UpGuard
3 days ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own and scale product security at UpGuard as the first dedicated hire. Lead threat modeling and security reviews across products, cloud infrastructure, and SDLC workflows, building automation like policy-as-code and AI-driven tooling to shift security left. Harden secure-by-default configurations for GCP and Kubernetes using infrastructure-as-code, manage vulnerabilities end-to-end by real risk, and build detection/response capabilities in a cloud-native environment.
Location: Sydney, Brisbane, Melbourne
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead threat modeling and security reviews across the product portfolio and cloud infrastructure, surfacing attack vectors and designing scalable mitigations.
  • •Build AI-driven security tooling, policy-as-code, and automation to embed security across the SDLC and support triage and coverage.
  • •Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure.
  • •Own vulnerability management end-to-end, triaging by real risk, driving remediation, and building preventative controls across the software supply chain.
  • •Build scalable detection and response systems to catch malicious activity, triage signals, and run incidents end-to-end.

Pay and Benefits

Equity and Bonus:Equity
Perks:Remote WorkLearning BudgetAnnual LeaveParental LeaveEquity

Key Requirements

  • •7+ years in security engineering and/or software engineering and/or security operations, working in cloud environments.
  • •Cloud security experience (GCP preferred; AWS or Azure acceptable).
  • •Expertise in cloud-native Kubernetes and container security principles.
  • •Experience leading technical security reviews, running threat modeling exercises, and turning findings into implementable controls.
  • •Hands-on knowledge of common web vulnerabilities (OWASP Top 10) and IaC tools (preferably Terraform/OpenTofu).
Experience:7+ yearsCloud securityKubernetesSecurity operationsAppSecSOC 2ISO 27001AI/LLM security
Skills:OwnershipCollaborationPragmatic trade-offsIncident response
Tech Stack:GCPKubernetesEKSGKEAKSIAMTerraformOpenTofuGoCI/CDSDLCAppSecOWASP Top 10Policy-as-codeInfrastructure-as-code

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

UpGuard
Provides cybersecurity solutions including risk ratings, third-party vendor risk management, and data breach detection to help organizations assess and reduce cyber risk across their digital supply chain.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Established Company
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn