Product Information Security Officer
hace 3 días
Sallent
You may have stumbled across our website during your work or studies while trying to edit a PDF document - . Does that ring a bell? iLovePDF is a SaaS company dedicated to helping individuals and businesses worldwide boost their document productivity. A continuación, encontrará un desglose completo de todo lo que se requiere de los posibles candidatos, así como la forma de presentar su candidatura. ¡Mucha suerte! Our constant growth encourages us to keep improving our products to become the favorite PDF software worldwide. Our powerful yet user-friendly software is accessible across web, mobile, and desktop platforms, catering to the needs of over 90 million users worldwide every month. About the Role For this position, we are looking for a Product Information Security Officer to build and scale our product security function from the ground up. This is not a traditional AppSec role, you will be responsible for embedding security across the entire software development lifecycle and making it part of how we design, build, test, release and operate our products. You will work closely with the development team (web, mobile, desktop), DevOps, QA and product teams, acting as a key partner to integrate security in a practical, scalable and developer-friendly way. This role is ideal for someone who combines technical depth with a broad product security mindset, enjoys building new capabilities, and can move comfortably between strategy and execution. The goal is to make product security a core capability of the organization through a strong shift-left approach and the progressive adoption of secure development practices. What we're looking for: We are looking for a hands-on Product Security professional who bridges strategy and execution and works closely with development teams. For this role, we will value someone who has the following skills: • 5+ years of experience in a similar role., • Strong understanding of end-to-end software development (web, APIs, cloud, mobile)., • Experience embedding security into the SDLC (design, development, testing, release, operations)., • Solid application security knowledge (OWASP Top 10, authentication, authorization, APIs, cryptography)., • Experience with secure code review and direct collaboration with developers., • Knowledge of DevSecOps practices (SAST, SCA, secrets scanning, CI/CD security)., • Experience in vulnerability management and risk-based prioritization., • Ability to perform threat modeling and security testing (e.g. DAST, pentesting, API security testing)., • Understanding of cloud and modern architectures (microservices, IAM, containers)., • Awareness of supply chain security and third-party risk., • Strong communication skills, with an adaptable, pragmatic, ownership-driven and curious mindset., • Experience working in SaaS or multi-platform product companies., • Experience with bug bounty programs, or coordinated vulnerability disclosure processes. Hybrid work, permanent contract. A company culture built on trust, autonomy, and independence. Your talent and opinions will really make a difference. Have an impact on millions of lives: The iLovePDF website is one of the top 100 most visited sites, and our services are used daily by millions of people. Beautiful, sunny office in one of the best areas of Barcelona. Our offices are much more than just a place to work. Team Retreats: Take part in fun team-building activities both locally and abroad. International environment: Our team has more than 12 nationalities. Flexible retribution with Cobee. Private medical insurance. xcskxlj Subsidized lunch, free snacks, and organic fruit.