← Back to results

Product Security Engineer

Join Bloomreach as a Product Security Engineer to enhance security practices across their innovative AI-driven platform.

Location
Slovakia
Compensation
€28.1k–€35.1k/yr
Level
mid
Type
full time · Hybrid

Posted by employer 17 hours ago

First seen on Joblaze 8 hours ago

Last verified on the company career page 8 hours ago

Apply at BloomReach → Save job Scanned from bloomreach.com

What you'll build

  • Support implementation of Secure Software Development Lifecycle practices
  • Perform security reviews of application designs and architectures
  • Participate in threat modeling exercises
  • Conduct security assessments and penetration testing
  • Collaborate with cross-functional teams on security requirements

Must have

  • 2+ years of hands-on experience in cybersecurity
  • Practical experience performing security assessments
  • Familiarity with threat modeling concepts
  • Understanding of vulnerability management fundamentals
  • Knowledge of OWASP standards

Nice to have

  • Exposure to AI and LLM technologies
  • Hands-on experience with security testing tools
  • Strong communication skills
  • Self-motivated and proactive
  • Team-oriented mindset

AI in the day-to-day

Bloomreach is building AI agents to personalize the customer journey.

Requirements

Experience
2+ years

Not disclosed in this posting: visa sponsorship.

Benefits

Education Budget Professional Development Workshops Employee Assistance Program Remote Work Flexible Working Hours Parental Leave

Joblaze summary

In this role, the Product Security Engineer at Bloomreach focuses on enhancing security across the company's product offerings by conducting threat modeling, security assessments, and vulnerability management. Key skills include experience in cybersecurity, familiarity with threat modeling methodologies, and knowledge of application security standards like OWASP. This position is ideal for someone with a couple of years in the field, looking to deepen their expertise while collaborating with cross-functional teams to ensure secure product development.

Joblaze insights

  • Listed today — first seen on Joblaze September 23, 2026. Last confirmed on BloomReach's careers page September 23, 2026.
  • Starts above 1% of 142 comparable mid security roles we track (median $127,500 across 54 companies).

Quick facts

Is the Product Security Engineer role remote?
It's hybrid — BloomReach expects some on-site time in Slovakia.
What's the salary range?
BloomReach lists €28,114–€35,143 for this role.
How much experience is required?
At least 2 years of relevant experience for this Product Security Engineer role.
Where is the role based?
BloomReach is hiring for this position in Slovakia.
What's the tech stack?
Joblaze extracted these technologies from the posting: Application Security, Burp Suite, Cybersecurity, OWASP, OWASP ZAP, Penetration Testing.
What seniority level is this role?
BloomReach targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer role at BloomReach.

From the original posting

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey.

About the Role:

You will act as the designated security focus on a specific product domain, driving threat modeling, security assessments, and vulnerability management across Bloomreach's platform.

Your Job Will Be:

  • Support the implementation and adoption of Secure Software Development Lifecycle (SSDLC) practices across engineering teams, helping integrate security throughout the product development process.
  • Perform security reviews of application designs, system architectures, and infrastructure components, with guidance as needed, to identify security risks and recommend appropriate mitigations.
  • Participate in threat modeling exercises for new and existing products, helping identify threats, assess risk, and document practical security recommendations.
  • Provide security guidance to product and engineering teams by applying established security standards, patterns, and best practices, escalating complex security concerns when appropriate.
  • Conduct security assessments, penetration testing, and validation testing across applications and environments using established methodologies and processes.
  • Triage, validate, and assign vulnerabilities identified through security tools and assessments, working with the appropriate stakeholders to support timely remediation.
  • Collaborate with engineering, DevOps, compliance, and other cross-functional teams to address security requirements and support secure product development.
  • Develop knowledge of assigned product domains and serve as a security point of contact for routine security questions and activities, with support from senior security team members for complex or higher-risk matters.

Professional Experience and Skills Requirements:

  • 2+ years of hands-on experience in cybersecurity, application security, product security, or a related security discipline.
  • Practical experience performing or supporting security assessments and penetration testing of web applications.
  • Familiarity with threat modeling concepts and methodologies such as STRIDE, with the ability to identify common threats and security risks.
  • Understanding of vulnerability management fundamentals, including vulnerability validation, risk-based prioritization, remediation tracking, and retesting.
  • Exposure to AI and LLM technologies with an interest in developing knowledge of associated security risks and controls.
  • Working knowledge of modern application architectures, APIs, authentication and authorization mechanisms, and common application security considerations.
  • Knowledge of OWASP standards and resources, including the OWASP Top 10, Testing Guide, and secure development practices.
  • Hands-on experience with, or familiarity with, security testing tools such as Burp Suite, OWASP ZAP, Nmap, SAST/SCA tools, and other application security technologies.
  • Ability to analyze and validate security findings and prioritize vulnerabilities based on technical risk and business context, with guidance as needed.
  • Strong communication skills with the ability to clearly document findings and communicate technical concepts to engineering and other stakeholders.
  • Self-motivated and proactive, with a willingness to learn, take ownership of assigned tasks, and contribute to process improvements.
  • Team-oriented mindset with the ability to collaborate effectively with Security, Engineering, DevOps, and other cross-functional teams.
  • Continuous learning mindset with a strong interest in developing technical security expertise and staying current with emerging technologies and threats.
  • Excellent command of the English language, demonstrating strong listening, speaking, reading, and written communication skills.

Your Success Story Will Be

In the First 30 Days

  • Develop a foundational understanding of Bloomreach's product portfolio, architecture, and core services.
  • Become familiar with internal SOPs, security policies, standards, and Product Security team workflows.
  • Gain working knowledge of the security tools, technologies, and platforms used by the Product Security team.
  • Understand established processes for security assessments, threat modeling, vulnerability management, and penetration testing.
  • Begin establishing working relationships with key partners across Engineering, DevOps, Compliance, and other relevant teams.

In the First 60 Days

  • Actively contribute to penetration tests and security assessments of web applications and product components, with guidance from more senior team members as needed.
  • Participate in threat modeling sessions using methodologies such as STRIDE and contribute to identifying potential threats and design risks.
  • Review and triage vulnerability data and security findings from scanning tools, manual testing, and other security sources.
  • Analyze and validate security findings, assess potential risk, and develop remediation recommendations in collaboration with senior team members and Engineering.
  • Continue building knowledge of Bloomreach's products, architecture, and security landscape, including emerging AI and LLM-related security risks.

In the First 90 Days

  • Independently perform well-defined security assessments and testing activities, escalating complex or higher-risk issues when appropriate.
  • Actively contribute to threat modeling sessions by identifying threats, documenting risks, and recommending appropriate security controls.
  • Engage directly with Engineering teams to communicate security findings, support remediation efforts, and validate implemented fixes.
  • Apply established Product Security standards and processes to provide security guidance for routine application security questions and development activities.
  • Demonstrate growing ownership of assigned security activities and product areas while seeking guidance for unfamiliar or complex scenarios.
  • Identify opportunities to improve team processes, documentation, tooling, or workflows and contribute to implementing those improvements.

#LI-HO1

The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.

Base Salary Range
€28.114€35.143 EUR

More things you'll like about Bloomreach:

Culture:

  • A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one.

Personal Development:

  • We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.

Well-being:

  • The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*

Compensation:

  • Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*

#LI-Remote

Standard company text repeated across BloomReach's postings is omitted here.

Similar positions

BloomReach
Senior Staff Security Engineer
BloomReach · Slovakia
BloomReach
Senior Staff Security Engineer
BloomReach · Czechia
BloomReach
Starburst
Security Engineer
Starburst · Warsaw, Poland