Product Security Specialist
Flare
Product Security Specialist
Remote position from Canada or the US
Life is short. Work somewhere awesome.
Flare is a breakout cybersecurity Software-as-a-Service (SaaS) company with a mission to empower organizations to take control of their data and protect their customers, employees and brand by shedding light on external threats. We enable cybersecurity teams to proactively detect high-risk external exposure across the dark and clear web, before threat actors have a chance to leverage it. We unify the core functionalities of cyber threat intelligence and external attack surface management into a single, intuitive platform.
TL;DR: We are a bunch of geeks who help protect our clients' data (and people in their network) by locating cyber risks.
As a Product Security Specialist at Flare, you will be responsible for securing the product that our customers rely on to protect themselves. You'll work closely with product and engineering teams to identify vulnerabilities, embed security into the development lifecycle, and help ensure that our platform, which collects and processes sensitive data from the dark web, illicit marketplaces, and other non-traditional sources, meets the high security bar our customers expect from a cybersecurity vendor.
Your purpose and impact:
Your mission, should you choose to accept it, is to own and drive product security at Flare, ensuring that our platform is built and maintained with security at its core. You will:
- Conduct threat modeling and security assessments of Flare's product, with particular attention to the unique risks associated with dark web data collection and processing
- Build and maintain product security monitoring use cases, ensure the right logs exist (working with engineering to create them where needed), and develop detection rules to surface abuse, misuse, and security issues
- Manage and evolve our AI-driven abuse detection capabilities, working with the product team to continuously improve accuracy and coverage
- Work with product and engineering teams to automate remediation workflows when abuse patterns or security issues are identified at scale
- Collaborate with product and engineering teams to embed security practices throughout the software development lifecycle, including secure coding guidelines, security reviews of new features, architecture changes, and third-party integrations
- Manage product vulnerability identification, triage, and remediation in coordination with engineering
- Participate in incident response efforts related to product security events
- Provide backup support for corporate security operations as needed
You’ll be a perfect fit if:
- You have hands-on experience in product security, application security, or a security role closely embedded with engineering teams
- You have a strong understanding of web application vulnerabilities (OWASP Top 10) and are comfortable performing threat modeling and security assessments
- You have experience building detection and monitoring use cases in a SIEM or log analytics platform
- You have a mindset geared toward automation and continuous improvement, you'd rather build a system than repeat a manual process
- You have working knowledge of cloud security fundamentals (AWS preferred)
- You can read and review code, proficiency in at least one common language (Python, Go, JavaScript, etc.)
- You communicate effectively with both technical and non-technical stakeholders
- You are autonomous and thrive in a small team where you own your domain
It be awesome if you have:
- Experience working at a cybersecurity company or with sensitive/non-traditional data sets
- Familiarity with compliance frameworks such as SOC 2 or GDPR
- Experience automating security detection and remediation workflows
What it’s like to be part of Flare:
- You will find a people-first company where work-life balance is valued. You’ll receive:
- Competitive salary
- Stock options
- Health coverage/insurance
- Flexible, work from anywhere
- Unlimited vacation
- Fun company events; “Flamping”, curling, rock climbing and many others
- You will join a high-growth, innovative start up where you’ll see your impact immediately and be empowered to take on challenges for your personal and professional growth
- You will work with an inspiring and award-winning team who are passionate about what they do and the clients we serve, whose work has been referenced in leading academic journals and international media
Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Flare we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.