Product Security Analyst/Engineer
Noblesoft Technologies
Location: Bay Area, CA (Hybrid)
Contract
Additional Details.
Our client is looking for a team to create a Search Engineering Pod (HC - 6). The Pod will act as the operational bridge between automated security scanning/remediation systems and product code owners. Their mission is to streamline threat modeling, eliminate triage noise, validate exploitability, verify automated patches, and drive open security issues to verified resolution.
Domain: Product / Application Security Engineering - specifically vulnerability management and secure code remediation (an AppSec / Product Security Engineering pod, not SOC/infra security). Adjacent domain needed: software engineering (the pod writes PoCs and reviews patches), plus light GRC for policy/exception handling.
Skill set required:
Bucket
What to hire for
Security fundamentals
CWE / CVE / OWASP Top 10, CVSS-style scoring, remediation SLAs, secure coding standards (input validation, boundary checks, memory safety)
Threat modeling
STRIDE / PASTA, trust boundaries, data flows, attack surface mapping for distributed / microservice systems
Hands-on coding
Working proficiency in at least two of C++, Go, Java, Python - read and write, not just read
Reproduction / PoC
Building minimal test harnesses, mocking dependencies, sandbox execution, cross-service runtime debugging; fuzzing and unit-test frameworks a plus
Code review / QA
Very high attention to detail - catching LLM hallucinations, regressions, off-by-one errors in agent-generated diffs; differential/patch validation
Tooling
SAST/DAST scanners, bug trackers, CI pipelines, Git-based code review flows
AI-adjacent
Experience debugging and prompt-tuning automated code-generation / agentic fixer tools
Soft skills
Stakeholder management with product code owners, driving fixes to closure, documentation discipline, judgment on when to escalate to FTE security leads
Sourcing profiles that fit:
- Product Security / AppSec Engineer (3 6 yrs) - covers threat modeling, triage, policy
- Security-minded SDE / SDET (2 5 yrs) - covers reproduction, PoC building, patch QA
- Vulnerability Management Analyst (2 4 yrs) - covers queue hygiene, severity assignment, exception reviews, SLA tracking
Overview:
The pod will act as the operational bridge between automated security scanning/remediation systems and product code owners. Their mission is to streamline threat modeling, eliminate triage noise, validate exploitability, verify automated patches, and drive open security issues to verified resolution.
Core Workstreams & Responsibilities
| # | Workstream | Key Responsibilities | Primary Deliverables |
| 1 | Threat Modeling & Asset Profiling | Document trust boundaries, data flows, and architectural entry points for high-priority services. Maintain up-to-date threat profiles in centralized repositories. | Standardized threat model documentation. Service risk classification tags. |
| 2 | Vulnerability Triage & Policy Management | Review and filter findings generated by automated source and endpoint scanners. Classify severity and evaluate exception requests against security compliance policies. | Bug tracking queue hygiene. Policy-compliant severity assignments. Documented exception reviews. |
| 3 | Reproduction & PoC Validation | Construct minimal test environments and reproduction harnesses. Validate whether reported findings represent viable vulnerabilities vs. false positives. | Confirmed reproduction steps/notes attached to issue tickets. Fast-closed false positives. |
| 4 | Automated / Agentic Fixer Oversight & QA | Supervise and validate code patches generated by automated remediation agents. Execute unit and integration tests, inspect diffs for unintended regressions, and verify fix efficacy. | QA-approved, tested patch changelists ready for code owner review. |
| 5 | Product Team Coordination & Closure | Route validated patches to designated product team code owners. Shepherd fixes through code review and verify end-to-end deployment to production. | SLA-compliant issue closures. Production fix verification notes. |
Skill Breakdown by Operational Workstream:
| Workstream | Must-Have Technical Skills | Nice-to-Have / Advanced Skills |
| 1. Threat Modeling | Understanding of architectural trust boundaries, attack surfaces, and data flows. Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA). | Experience conducting threat model reviews for large distributed / microservice systems. Ability to translate abstract system designs into concrete threat scenarios. |
| 2. Triage & Policy Management | Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10). Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs. | Experience managing vulnerability queues and reviewing compliance exception requests. Familiarity with automated static/dynamic scanning tools. |
| 3. Vulnerability Reproduction | Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python). Ability to set up local test harnesses, mock dependencies, and build minimal PoCs. | Practical experience with fuzz testing, unit test frameworks, and sandbox execution. Debugging complex runtime or logic errors across service boundaries. |
| 4. Automated / Agentic Fixer QA | High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one errors). Understanding of secure coding standards (input validation, boundary checking, safe memory access). | Experience debugging and prompt-tuning automated code generation tools. Familiarity with automated patch validation and differential testing. |
Escalation & Governance Model:
Standard Operations (XWF): Day-to-day triage, vulnerability reproduction, policy-standard severity tags, agentic patch QA, and standard remediation tracking.
Escalations to FTE Security Leads:
Ambiguous or out-of-policy exception requests.
Architectural or multi-service redesigns required to resolve complex root causes.
Disputed severity classifications between product teams and policy rubrics.
Key Performance Indicators (KPIs)
Triage Turnaround Time: Initial triage and false-positive filtering completed within 24 48 hours of report ingestion.
Patch Quality Rate: High acceptance rate of QA-verified automated patches submitted to product owners (target: 90% landing without major revision).
Remediation Cycle Time: Reduction in overall time from initial finding to production deployment.
- ...Job Description Job Description Exciting Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid) Requirements ~3 plus years of experience in cyber security or related discipline. ~ SIEM, Cortex XSIAM, correlation, and threat monitoring ~ Understands the...Suggested
$95k - $115k
...possible, with the ultimate goal of enabling human life on Mars.SECURITY ANALYST (DETECTION AND INCIDENT RESPONSE)As a Security Analyst at... ...Assist in evidence collection and collaboration with SpaceX engineering teams to proactively improve and secure systems from future...SuggestedPermanent employmentTemporary workRemote workWeekend work- ...worldwide System Integrator, Software and Product Development, IT Outsourcing and... ...innovation, ERP and CRM counselling, Product Engineering, Business Intelligence, Data... ...and business keenness.Job DescriptionIT Security Analyst - EAD or GC or USC ONLYLos Angeles, CA...SuggestedContract workWorldwide
$30.47 - $56.35 per hour
Job Title:Game Security Analyst - Ricochet Anti-Cheat (Call of Duty)Requisition ID:R028045Job Description... .... Working closely with anti-cheat engineers, data scientists, and operations teams,... ...of interactive entertainment and products, our “press start” is simple: delight hundreds...SuggestedHourly payFull timeTemporary workPart timeLocal areaWorldwideRelocation package$103k - $154k
...several prestigious awards, such as Best Engineering Team, Best Company for Diversity,... ...Work WithYou will join our Operational Security team, a group of dedicated professionals... ...environment, you will work closely with senior analysts to monitor security alerts across our enterprise...SuggestedLocal areaFlexible hours$20k
...actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.INDUSTRIAL SECURITY ANALYST (PERSEC)SpaceX is looking for a multidisciplinary Industrial Security Officer (PERSEC) to serve as a Personnel Security Analyst...Permanent employmentTemporary workWork at officeRemote workWeekend work- ...optimization, we help states deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create practical, real-... ...the place for you. About The Role: As a Security Analyst, you will be a crucial member of our Security Operations Center...
$117.2k - $176.7k
...in the right place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day work with Enterprise business unit...Full time$129k - $171k
...TEAMAnduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense... ...incorporate key detection feedback loops with the detection engineering team. As a Senior SecOps Analyst, you will serve as an incident...Full timeWork experience placementImmediate start$95k - $115k
...InformationSecurity Analystto join our Information Security team. This role is the operational... ...gradually take on more complex security engineering work.RESPONSIBILITIES: Manage and triage... ...AND BENEFITS: Pay range: Security Analyst/Level I: $95,000.00 - $115,000.00/per year...Permanent employmentTemporary workRemote workWeekend work- ...analysis to support our client’s daily facility operations, planning, and compliance programs. We are looking for an Information Security Analyst in San Diego, California . Contingent Upon Contract Award Summary Implements and monitors cybersecurity controls,...Contract workFor contractorsFor subcontractor
- ...Reports To: Manager, Security Trust The Information Security Analyst, Security Trust supports security assurance... ...Alteryx Security, Legal, Privacy, Product, and Compliance positions Translate... ..., Procurement, Legal, Privacy, Engineering, Product Security, Security Operations...
- Providence St. Joseph Health and Services is seeking an Epic Security Analyst to administer, maintain, and support Epic security, user, and provider records. You will ensure caregivers have appropriate access while complying with privacy and regulatory requirements. Work...
- ...pm on: 10/2/2026, 10/16/2026 (Final) Under general supervision, leads, plans, schedules, and oversees the work of Information Security Analysts Level I/II (ISA I/II) while performing the same and/or more difficult duties as those being led; ensures completion of tasks in...Full timePart timeWork at officeLocal areaWeekend work
$118.68k - $175.8k
...experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a... ...offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...Work experience placementWork at officeLocal area- ...accessible over time. That’s where we come in.We combine deep engineering expertise with global-scale manufacturing to deliver the... ...***Please note, this is NOT an InfoSec role. The Physical Security Systems Analyst is responsible for the day-to-day administration, support,...Temporary workImmediate startRemote workWorldwideFlexible hoursShift work
$105k - $125k
GFT is seeking a Physical Security & Risk Analyst to join our Security and Safety Team in Roseville, CA! This role follows a hybrid work model... ...Risk Management, Emergency Management, Criminal Justice, Engineering, Homeland Security, Public Administration, Infrastructure...Full timeWork at officeRemote work- ...Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets – resolve actual security incident tickets Qualifications: Bachelor's degree in...Contract workWork at office
- ...Information Security Analyst Sacramento, CA 12+ months Consultant\'s primary duty is to ensure that the organization\'s digital assets are secure and protected from unauthorized access. This includes protection of both the cloud and on-premises infrastructures, monitoring...
$129k - $171k
...THE TEAMThe Counterintelligence (CI) and Security Investigations Team’s safeguards Anduril... ...The Counterintelligence & Security Risk Analyst Lead is responsible for analyzing... ...across internal stakeholders, including product, supply chain, legal, HR, and InfoSec teams...Full timeContract workFor contractorsWork experience placementImmediate start$94.2k - $176.3k
...are not only part of history, they're making history. Northrop Grumman Mission Systems is seeking a Sr. Principal Industrial Security Analyst (4) or Principal Industrial Security Analyst (3) in Sunnyvale, CA. This is a multi-faceted security position, for the support...Full timeWork experience placementWork at officeRelocation packageShift work$117.2k - $176.7k
...information needed to make strategic, risk-based decisions. The GCC team is a division within the Product Security Organization, and you'll play a pivotal role in partnering with engineering to translate complex mandates into actionable controls — driving continuous risk...Full time- Join the Clean Energy RevolutionBecome an Enterprise Security Business Operations Senior Analyst at Southern California Edison (SCE) and build a better tomorrow. In this job, you’ll play a key role in supporting the people, financial, and operational processes that keep...For contractorsRemote workRelocation
$115k - $150k
...electrical devices for communication products and systems. The company develops... ...has to offer you!We are seeking a Security & Compliance Operations Analyst to join our Information Technology... ...Science, Information Technology, Engineering, Life Sciences, Environmental...Full timeWork experience placementFlexible hours- ...ROLE: ORACLE FUSION CLOUD SECURITY ANALYST / ADMINISTRATOR LOCATION: WATSONVILLE, CA (HYBRID ) Job Overview We are seeking an experienced... ...within SLA. · Collaborate with Security, Development, Product, and Business teams. Required Skills · Bachelor's...Temporary work
- ...nation’s vital interests. Requisition #: 1567 Job Title: Security Analyst Location: China Lake, CA Clearance Level: Must Have... ...mitigation strategies. Ensure the completion of all necessary RMF products and reporting in accordance with policy and in collaboration...Work at office
- ...Job Description Job Description Seeking a Sr Security Analyst Consultant to lead staff in the implementation & execution of technical aspects of the client’s enterprise security plan. Will be the SME on security issues & projects so that ESEC team members can increase...Contract work
- ...Job Description Job Description Job Summary: As a Security Analyst you will utilize your skill and knowledge set to protect the organization... ...emerging vulnerabilities, misconfigurations, and social engineering you will lower the amount of risk facing the organization...Work experience placementWork at officeLocal area
$90k - $100k
...or CEH At least 5 years of experience in cybersecurity or IT security, with a solid grasp of security frameworks and standards such... ...leadership, corporate support teams, cross-functional peers, and product or service providers at the appropriate technical level...Full timeWork at office1 day per week$75.8k - $113.8k
...only part of history, they're making history. Northrop Grumman’s Aeronautics Systems sector is seeking a dedicated Industrial Security Analyst (Level 2) to join our team of qualified, diverse professionals. In this role, you will contribute to safeguarding critical...For contractorsRelocationShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Analyst/Engineer. Be the first to apply!
- senior information security analyst California
- network security consultant California
- security systems specialist California
- security coordinator California
- security consultant California
- security advisor California
- security specialist California
- data center design engineer California
- senior product design engineer California
- senior manager product engineering California


