Summary
✨ AI‑Generated
A technology-driven organization is seeking a senior security engineer to embed security throughout the software development lifecycle. The role focuses on threat analysis, secure architecture reviews, automation, and improving engineering security practices.
Highlights
Hands-on security role with influence over engineering practices, secure development processes, and software protection strategies.
Description
Fancy helping to shape the future of FinTech?
We have always been innovators.
In 1996 we were the first company to share exchange rate information, free of charge on the internet.
Today, we are a world leading online trading group.
Join us to:
Help build the future of online tradingBe part of a culture driven by integrity and global impactBecome part of an award-winning company - check out our full list of awards here
We are only as good as our people.
Luckily, our people are the best.
Join us!
How do we work?
The Senior Product Security Engineer is a hands-on security expert with strong development experience who champions secure software development practices across OANDA.
You will work directly with engineering teams to embed security into the SDLC, lead threat modeling and design reviews, build security tooling and automation, and develop the secure coding standards that keep our platform secure.
This role is critical to pushing security left-making it a natural part of how we build rather than a gatekeeping function.
In this role, you will:
Lead threat modeling, design reviews, and code review for application security vulnerabilities across development teams.
Develop and maintain secure coding standards, practices, and guidelines specific to our tech stack (JS, Go, Python, C++, Java).Build and contribute directly to security-critical components and features.
Partner with engineers to identify, track, and remediate application security issues, from design to production.Implement and operationalize DevSecOps tooling across the development pipeline (SAST, DAST, composition analysis, fuzzing).
Automate security workflows to make security checks seamless for developers.Manage application security incident response and root cause analysis.
Conduct security testing, penetration assessments, and tabletop exercises to identify and remediate vulnerabilities before they reach production.Evaluate and mitigate supply chain risks by tracking third-party library vulnerabilities, security advisories, and dependency updates.
Maintain secure dependency management practices.Build and expose security metrics, monitoring, and alerting for application and infrastructure security.
Create transparency into security posture across the platform.Mentor developers in secure coding practices through hands-on engagement, training, and code reviews.
Foster a culture where security is owned by the entire engineering organization.Stay current with industry best practices, emerging threats, and new attack vectors.
Participate in security conferences and bring back learnings to OANDA.Work in both on-premise and cloud environments (GCP).
Harden application infrastructure, container security (Docker/Kubernetes), and cloud configurations.
Apply defense-in-depth across all layers.Support regulatory compliance and audit responses related to application and product security.
Advise on security requirements for SOC 2, ISO 27001, GDPR, and industry-specific standards.
What skillset you need, to be successful in this role:
Bachelor's degree in Computer Science, Computer Engineering, or related field.2-5 years of professional development experience with at least 1-2 years focused on application security, secure SDLC, or product security.Proficiency in at least 2-3 of our primary languages (Java, Python, Go, JavaScript, C++).
Strong understanding of secure coding practices and common vulnerabilities (OWASP Top 10).Hands-on experience with security testing tools and methodologies (SAST, DAST, code review, penetration testing).
Knowledge of threat modeling and secure design principles.Working knowledge of infrastructure concepts (networking, databases, container security, cloud platforms).
Experience with CI/CD pipelines and DevOps practices.Familiarity with security standards (SOC 2, ISO 27001, NIST) and privacy regulations (GDPR).
Experience with regulatory compliance and audit support is a plus.
___
At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills.
While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team.
You have the right to request a human review of your application.
OANDA Global Corporation is a diverse and global team with offices around the world.
We value the unique skills and experiences each individual brings to OANDA.
We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate.
We provide an inclusive and accessible environment for everyone.
Candidates selected for an interview will be contacted directly.
If you require accommodation during the recruitment and selection process, please let us know.
We will work with you to provide as seamless a recruitment experience as possible.
Learn more about our culture here.