iHerb is seeking a Product Security Engineer to enhance their Secure Development Lifecycle and security automation. This role involves driving security hardening strategies and responding to emerging threats. The engineer will collaborate with global development teams and organizational leaders to implement security initiatives.
Role Involves:
Driving cross-functional projects and establishing security development lifecycle practices.
Leading security design reviews and threat modeling.
Evaluating, prototyping, and implementing security tools and services (DAST, SAST, SCA...).
Developing secure architecture standards and frameworks.
Analyzing emerging security threats and implementing mitigations.
Participating in security assessments, penetration testing, and bug bounty programs.
Contributing to security incident response.
Requirements:
Solid understanding of application and infrastructure security vulnerabilities (OWASP Top 10, CWE 25…).
Proficiency in SDL implementation and automation in a DevOps environment.
Experience with web applications and microservices, including API security.
Excellent problem-solving, critical thinking, and communication skills.
Experience driving application security training and awareness campaigns.
Knowledge of programming languages and frameworks (Python, C# .NET, JavaScript, node.js, Java...).
Three (3) plus years of technical security experience.
Computer Science / Engineering degree or equivalent experience.
iHerb offers:
Medical, dental, and vision insurance programs.
Basic life insurance.
401(k) plan.
Time Off and Paid Sick Leave.
Paid holidays.
Potential Restrict Stock Units and annual bonuses.
iHerb is a global eCommerce platform committed to making health and wellness accessible worldwide. As the world's largest online retailer dedicated to vitamins, minerals, supplements, and other health products, iHerb offers a curated selection of over 50,000 products from 1,800+ brands. With over 25 years of experience, iHerb ships directly to customers in over 180 countries. The company strives to provide the best value and most convenient experience, driven by a vision to be the #1 destination for health and wellness.