About the job
Join Redgate Software as a Product Security Engineer!
At Redgate, we develop innovative, user-friendly software solutions that empower data professionals to maximize the value of their databases. Our products address intricate database management issues throughout the DevOps lifecycle, enhancing efficiency, minimizing errors, and safeguarding critical business data. The data community places its trust in Redgate to effectively balance speed to market, teamwork, and data security.
Explore more about our vibrant culture and commitments:
Your Role
As a vital member of our team, you will integrate security into the software development lifecycle across various product teams. Your responsibilities will include defining security requirements, enhancing detection and prevention mechanisms (SAST/DAST), guiding teams on application security governance, and conducting threat modeling.
Your Contributions at Redgate
- Collaborate with engineering and product teams to define and operationalize security requirements throughout the SDLC, from design to deployment.
- Conduct audits of application code to identify weaknesses and vulnerabilities.
- Lead or co-lead application security governance practices, including secure-by-default standards, patterns, guardrails, and risk acceptance processes.
- Promote SAST/DAST adoption and ensure high-quality outcomes through tool tuning, triage workflows, severity calibration, and fix-forward practices.
- Facilitate the implementation of threat modeling for new features, architectural changes, and high-risk services, transforming findings into actionable engineering tasks.
- Offer guidance on product security within cloud-native environments (AWS and containerized workloads), focusing on secure service design.

