Senior Product Security Engineer

PointClickCare
Summary
Join PointClickCare as a Senior Product Security Engineer and proactively identify and mitigate product security issues. Collaborate with product teams to detect potential issues in production. This role involves engineering solutions, guiding best practices, performing reviews, conducting investigations, creating detection rules, monitoring alerts, and collaborating with other security teams. The ideal candidate possesses a strong technical background in software engineering and cybersecurity, excellent analytical skills, and a proactive approach to threat detection and response. PointClickCare offers a dynamic environment to advance your career while making a meaningful impact on healthcare. We offer a competitive salary and a comprehensive benefits package.
Requirements
- Hold a Bachelorβs degree in Cyber Security, Information Technology, Computer Science, or a related field
- Have a minimum of 10-15 years of experience in software engineering and/or cyber security, with a focus on product security, app security, threat hunting, security detection, incident response, or related areas
- Possess expert level understanding of software engineering skills with Java, C# or other OOO languages with focus on app security best practices
- Demonstrate proficiency in using security tools and technologies such as SIEM, IDS/IPS, EDR, network analysis tools, and OWASP Top 10 knowledge
- Possess excellent analytical and problem-solving skills, with the ability to think critically and creatively to identify and mitigate threats
- Have strong written and verbal communication skills, with the ability to convey complex technical information to both technical and non-technical stakeholders
- Be able to work effectively both independently and as part of a team in a fast-paced, dynamic environment
Responsibilities
- Create and maintain detection rules and signatures for various security tools (e.g., SIEM, IDS/IPS) to identify potential threats and anomalies
- Work with existing product teams to identify, remediate, and fix new or existing product deficiencies
- Collaborate with the incident response team to analyze and respond to security incidents, ensuring timely and effective mitigation
- Analyze security data from various sources, including logs, SIEM(s), network traffic, and endpoint data, to identify patterns, trends and anomalies indicative of potential threats
- Solution, develop, and maintain custom scripts, tools, and techniques to enhance threat detection and response capabilities. Manage and optimize security detection tools and platforms
- Integrate threat intelligence feeds and data into detection mechanisms to improve the accuracy and relevance of alerts
- Understand the nature of threats, potential impact, response actions taken, and recommended mitigation strategies
- Work closely with other cyber security professionals, product teams, and external partners to share threat intelligence and improve overall security posture
- Stay up-to-date with the latest cyber threats, trends, and technologies to continuously improve threat hunting and detection methodologies and tools
Preferred Qualifications
- Be a Certified Ethical Hacker
- Have strong scripting skills (e.g., Python, PowerShell)
Benefits
- Retirement Plan Matching
- Flexible Paid Time Off
- Wellness Support Programs and Resources
- Parental & Caregiver Leaves
- Fertility & Adoption Support
- Continuous Development Support Program
- Employee Assistance Program
- Allyship and Inclusion Communities