This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Product Security Engineer at Ema, you sit at the intersection of backend engineering and Cloud Security, building systems that bake security directly into Ema’s platform. You’ll design internal tools, influence architecture, and scale application security programs that protect real production workloads. The job demands strong engineering judgment, and InfoSec mindset.
Job Responsibility:
Design, build, and maintain internal security tools and platforms to improve Ema’s overall security posture
Implement and improve security controls directly into product and platform workflows
Influence engineering architecture and ensure secure-by-design implementations
Own and scale application security programs including SAST, SCA, dependency risk, and custom detection logic
Support penetration testing efforts by validating findings and engineering durable fixes
Perform threat modeling for new features and systems, translating risks into concrete engineering solutions
Develop automation to reduce manual security effort across vulnerability management, access reviews, and incident response
Conduct secure design and code reviews with a strong focus on exploitable logic flaws and systemic risks
Build tooling to surface security signals from production systems and dev workflows
Requirements:
4–7 years of experience building scalable software systems, with a strong emphasis on security engineering
Excellent programming skills (Python required
Go or similar strongly preferred)
Proven experience building internal tools, and frameworks used by engineering teams
Proven ability to build security platforms from zero to production scale
Strong judgment translating abstract risk into concrete engineering controls
Track record of influencing architecture across product, infra, and reliability teams
Comfortable owning ambiguous, high-impact security problems end to end
Experience integrating security into CI/CD pipelines and developer workflows
Comfortable operating cross-functionally with Product, Engineering, and Infra teams