Seeking a Principal Product Security Engineer to ensure the security and integrity of global e-commerce services. This role involves leading security practices across the development lifecycle, implementing automation, and developing strategies to mitigate threats. Requires 10+ years of technical security leadership, extensive knowledge of security products, and proficiency in SDL within a DevOps environment.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
About The Company
iHerb is a leading global e-commerce platform dedicated to health and wellness. With a mission to make health products accessible to everyone, iHerb offers an extensive selection of vitamins, minerals, supplements, and other health-related products. Serving customers in over 180 countries, the company has built a trusted reputation for quality, affordability, and customer service. With a focus on innovation and excellence, iHerb continuously expands its product offerings and enhances its technological infrastructure to meet the evolving needs of its global customer base.
About The Role
We are seeking a highly skilled and experienced Principal Product Security Engineer to join our team. This role is pivotal in ensuring the security and integrity of our e-commerce services and applications that support millions of customers worldwide. The successful candidate will lead efforts to establish and maintain robust security practices across our development lifecycle, implement automation technologies, and develop strategies to harden our products against current and emerging threats. You will collaborate with cross-functional teams to embed security into every aspect of our product development process, ensuring compliance with industry standards and best practices. This position offers an exciting opportunity to influence the security posture of a rapidly growing organization, working on cutting-edge security solutions in a dynamic environment.
Qualifications
- Demonstrated technical foundation with a Computer Science or Engineering degree, or equivalent experience.
- 10+ years of technical security leadership experience at a top-tier software company.
- Extensive knowledge of security products, threat modeling, security design, architecture, cryptography, mobile security, and cloud computing technologies.
- Strong understanding of application and infrastructure security vulnerabilities and mitigation strategies (OWASP Top 10, CWE, etc.).
- Proficiency in implementing Secure Development Lifecycle (SDL) processes, automation, and security tools within a DevOps environment.
- Experience with large-scale web applications, microservices architecture, API security, access management, authentication, data protection, and encryption.
- Excellent problem-solving, critical thinking, collaboration, and communication skills.
- Ability to drive decision-making through data analysis and attention to detail.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
- Experience with Cloudflare security, AWS VPCs, EC2 instances, and Docker.
- Experience leading application security training, security champions, and awareness initiatives.
- Active contributions to the security community through research, open source projects, or publications.
- Lead cross-functional projects to establish and maintain cutting-edge security development lifecycle practices.
- Conduct security design reviews and threat modeling for new and existing services to identify and mitigate risks.
- Evaluate, prototype, implement, and operate security-focused tools and services to enhance our security posture.
- Create and maintain secure architecture standards, frameworks, and patterns across multiple layers of our technology stack.
- Discover emerging security threats, analyze their potential impact on iHerb, and implement centralized mitigation strategies proactively.
- Stay informed on current security threats and operational best practices to continuously improve security measures.
- Drive security assessments, penetration testing, and manage bug bounty programs to identify vulnerabilities.
- Participate actively in security incident response efforts, providing expertise and leadership during security incidents.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- Competitive salary package commensurate with experience and skills.
- Comprehensive medical, dental, and vision insurance plans for employees and their families.
- Participation in our 401(k) retirement savings plan with company matching.
- Paid time off, sick leave, and holiday benefits to support work-life balance.
- Eligibility for restricted stock units (RSUs) and annual performance-based bonuses.
- Opportunities for professional development and continuous learning.
- Flexible remote work policy, allowing you to work from anywhere within the United States.
iHerb is an equal-opportunity employer. We are committed to creating a diverse and inclusive workplace where all qualified applicants receive fair consideration for employment regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. Discrimination and harassment are not tolerated at iHerb, and we strive to foster an environment of respect and equality for all employees.
Similar Jobs
Explore other opportunities that match your interests