Senior Product Security Engineer

3 days ago


Dublin, Ireland Merative Full time

Senior Product Security Engineer

Senior Product Security Engineer

Apply locations Dublin time type Full time posted on Posted 3 Days Ago job requisition id JR01129

Join a team dedicated to supporting the crucial mission of improving health outcomes.

At Merative, you can apply your skills – and grow new ones – with colleagues who have deep expertise in health and technology. Merative provides data, analytics and software for the health industry. Our clients include providers, health plans, employers, life sciences companies and governments around the world. With industry-leading products and focused innovation, we help customers improve decision-making and performance so that together, we drive real progress in health. Learn more at merative.com

Overview: We are looking for a skilled Senior Product Security Engineer to join our Cúram Security Team, which is essential to ensuring the security and compliance of our health and human services (HHS) IT solutions. This role will work closely with Product Development, CISO, and other security functions to assess, implement, and manage critical security controls, regulatory requirements, and incident response protocols. This position is vital to maintaining a proactive security posture for our products, going beyond daily developer security considerations to encompass a broad range of security practices.

Key Responsibilities:

1. Define, review and validate application security requirements with Product Development teams, ensuring alignment with security standards.
2. Integrate security features for authentication and authorization, using technologies such as OIDC, SAML SSO and JAAS.
3. Implement controls to address vulnerabilities, including OWASP Top 10 risks like CSRF, XSS and XXE.
4. Collaborate with development teams to validate security fixes and promote best practices.
5. Review codebases for vulnerabilities and assess issues flagged by security scanning tools.
6. Serve as a primary responder to security issues identified by the Product Security Response Team (PSRT), coordinating efforts for timely remediation.
7. Interpret and communicate PSRT advisory reports to development teams, providing guidance to address identified vulnerabilities.
8. Conduct Open Source Software (OSS) vulnerability assessments to maintain secure software dependencies.
9. Perform SAST and DAST testing with tools like SonarQube and Burp Suite Pro to proactively identify security risks.
10. Configure and manage security scanning tools to meet project needs.
11. Conduct internal penetration tests and support external pen testers in assessments of on-premises and Kubernetes-based applications.
12. Document, assess and address security risks and any deviations from security standards.
13. Serve as a primary contact for security incidents, handling security-related customer cases and incident responses.
14. Coordinate with the CISO team for security sign-offs on product releases.
15. Support ISO 27001 and other certification efforts to ensure compliance with industry standards.

Basic Qualifications:

1. Security Expertise: Deep knowledge of security vulnerabilities, risks, and mitigation techniques, with experience in vulnerability management frameworks such as CVE and CVSS.
2. Technical Skills:
3. Proficiency in SAST, DAST and IAST security scanning tools (e.g., SonarQube, Burp Suite, etc.) and vulnerability scanning tools like JFrog Xray.
4. Expertise in integrating and managing security tools within CI/CD pipelines using GitHub Advanced Security and Jenkins.
5. Strong skills in Java, JavaScript, XML, and YAML for application security, configuration management, and security automation.
6. Solid understanding of Kubernetes security and cloud environment configurations.
7. Understanding of security requirements for deployments on application servers, including IBM WebSphere Liberty, IBM WebSphere Application Server and Oracle WebLogicServer.
8. Proficiency in cryptographic algorithms, including encryption, hashing, digital signatures, and secret key management ensuring secure data transmission and storage.
9. Risk Management Knowledge: Experience managing security risks and ensuring compliance within regulated industries, ideally in HHS.
10. Collaboration and Communication Skills: Proven ability to work cross-functionally and communicate security requirements with both technical and non-technical stakeholders.
11. Problem-Solving Skills: Strong analytical abilities to identify, evaluate, and resolve complex security issues.

About Us

Merative is a place to grow. We offer opportunities to apply your skills — and develop new ones — with colleagues who have deep expertise in health and technology. At Merative we’re driven and professional, but treat each other with compassion and respect. Roles at Merative include product design and development, technology innovation, product and account management, sales and consulting, communications and marketing, management, operations and more.

#J-18808-Ljbffr



  • Dublin, Ireland 2107 Merative Healthcare Ireland Ltd. Full time

    Senior Product Security Engineer Join a team dedicated to supporting the crucial mission of improving health outcomes. At Merative, you can apply your skills – and grow new ones – with colleagues who have deep expertise in health and technology. Merative provides data, analytics and software for the health industry. Our clients include providers,...


  • Dublin, Ireland The Product Folks Full time

    Squarespace (NYSE: SQSP) is a design-driven platform helping entrepreneurs build brands and businesses online. We empower millions of customers in more than 200 countries and territories with all the tools they need to create an online presence, build an audience, monetize, and scale their business. Our suite of products range from websites, domains,...


  • Dublin, Ireland Amazon Full time

    Senior Security Engineer, Corporate Services Security Job ID: 2874213 | Amazon Data Services Ireland Limited Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal and Global Communications and Community Impact (GCCI) business units. Our Mission is...


  • Dublin, Ireland Amazon Full time

    Come and build innovative services that protect our cloud from advanced security threats! As a Senior Security Engineer on our team, you’ll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon’s infrastructure, including advanced persistent threats. You’ll work with data scientists, software...


  • Dublin, Ireland ENGINEERINGUK Full time

    You will need to login before you can apply for a job. DESCRIPTION Come and build innovative services that protect our cloud from advanced security threats! As a Senior Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced...


  • Dublin, Ireland SOLAS IT RECRUITMENT Full time

    Senior Network Security Engineer We are seeking a skilled Network Security Engineer to manage and secure our network infrastructure. The ideal candidate will have extensive experience with Cisco Networks and a deep understanding of network security principles and practices. Responsibilities: - Manage the security of Cisco routers, switches, networking...


  • Dublin, Ireland Amazon Full time

    Job ID: 2834809 | Amazon Data Services Ireland Limited Come and build innovative services that protect our cloud from advanced security threats! As a Senior Security Engineer on our team, you’ll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon’s infrastructure, including advanced persistent...


  • Dublin, Ireland Intercom Full time

    What’s the opportunity? As a Senior Cloud Security Engineer you will have experience in investigating advanced threats, detecting cloud-native attacker techniques, and securing AWS environments, with a focus on technical controls, incident response, and detection engineering. You will be working with other engineering teams to identify & mitigate risks...


  • Dublin, Ireland Google Inc. Full time

    Senior Software Engineer, Endpoint Security Agents corporate_fare Google place Dublin, Ireland Apply Minimum Qualifications: - Bachelor's degree or equivalent practical experience. - 5 years of experience coding in one or more of the following languages: C, C++, Java, or Python. - 4 years of experience in software development. - 3 years of experience...


  • Dublin, Ireland Chubb Fire and Security Ltd Full time

    Security Service Engineer Apply to locations: Chubb Dublin, Unit 3/4, Deansgrange Business Park, Deansgrange, Dublin, A94 D954 Time type: Full time Posted on: 30+ Days Ago Job requisition id: JR40000185 It's fun to work in a company where people truly BELIEVE in what they're doing! Think you know Chubb? We might just surprise you! Chubb is so much more...


  • Dublin, Ireland Intercom Full time

    What's the opportunity? At Intercom, you will be a product engineer - someone who solves real customer problems through a smart and efficient application of your technical knowledge. You’ll be part of one of our multidisciplinary product teams, where you will build both back-end and front-end systems, and work closely with designers, product managers,...


  • Dublin, Ireland HubSpot Full time

    POS-26030 The HubSpot Threats and Vulnerabilities team protects our customers by systematically reducing HubSpot’s attack surface and improving the maturity of HubSpot’s Product Security. We create this path forward by mapping out HubSpot’s defences, identifying and prioritizing improvements based on threat intelligence, and testing our applications...


  • Dublin, Ireland Hubspot Full time

    Thanks to our employees' feedback, HubSpot has been named the #5 Best Leadership Team in 2024 by Comparably! However you identify or whatever your path here, please apply if you see a position that makes your heart skip a beat. Come join us and help us build a global company where we're all proud to belong. Senior Security Analyst (Detection Engineering &...


  • Dublin, Ireland Embecta Full time

    embecta is a global diabetes care company that is leveraging its 100-year legacy in insulin delivery to empower people with diabetes to live their best life through innovative solutions, partnerships and the passion of more than 2,000 employees around the globe. Why join us? A career at embecta means being part of a team that values your opinions and...


  • Dublin, Ireland Google Full time

    Senior Software Engineer, Endpoint Security Agents corporate_fare Google place Dublin, Ireland Apply Minimum Qualifications: - Bachelor's degree or equivalent practical experience. - 5 years of experience coding in one or more of the following languages: C, C++, Java, or Python. - 4 years of experience in software development. - 3 years of experience...


  • Dublin, Ireland Tbwa ChiatDay Inc Full time

    Gong transforms revenue organizations by harnessing customer interactions to increase business efficiency, improve decision-making and accelerate revenue growth. The Revenue Intelligence Platform uses proprietary artificial intelligence technology to enable teams to capture, understand and act on all customer interactions in a single, integrated platform....

  • Site Supervisor

    3 days ago


    Dublin, Ireland Securitas Security Service Full time

    Securitas Technology Ireland are currently recruiting for a Site Supervisor based in the Dublin region. Role Purpose: Reporting to the Site Project Manager the Site Supervisor oversees and takes responsibility of the successful role out of security projects across the Ireland region. This role will sit as part of the Irish Securitas Technologies team and...

  • Site Supervisor

    19 hours ago


    Dublin, Ireland Securitas Security Service Full time

    Securitas Technology Ireland are currently recruiting for a Site Supervisor based in the Dublin region. Role Purpose: Reporting to the Site Project Manager the Site Supervisor oversees and takes responsibility of the successful role out of security projects across the Ireland region. This role will sit as part of the Irish Securitas Technologies team and...


  • Dublin, Ireland Amazon Full time

    Senior Software Development Engineer, AWS Security Job ID: 2813770 | Amazon Data Services Ireland Limited Come and build innovative services that protect our cloud from advanced security threats! As a Senior Software Development Engineer on our team, you’ll help build and manage services that detect and automate the mitigation of cybersecurity threats...


  • Dublin, Ireland Trust In SODA Full time

    Cloud Security Engineer Had a brilliant new role just come in today with a client of mine in the cyber security space. It's a new AWS cloud security engineering role with one of their Dublin city centre based customers. It's a chance for someone to join an established cloud team at a senior level and have a lot of influence on how they operate from a...