- Home
- Jobs
- G&A - GIST
- Product Security Engineer

Product Security Engineer at Bloomreach
SlovakiaFull-timeG&A - GISTPosted 15 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><div class="p-rich_text_section">Bloomreach is building the world’s premier <strong data-stringify-type="bold">agentic platform for personalization</strong>.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the <strong data-stringify-type="bold"><em data-stringify-type="italic">entire</em></strong> customer journey.</div>
<ul class="p-rich_text_list p-rich_text_list__bullet p-rich_text_list--nested" data-stringify-type="unordered-list" data-list-tree="true" data-indent="0" data-border="0">
<li data-stringify-indent="0" data-stringify-border="0">We're taking <strong data-stringify-type="bold">autonomous search</strong> mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.</li>
<li data-stringify-indent="0" data-stringify-border="0">We’re making <strong data-stringify-type="bold">conversational shopping</strong> a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey.</li>
<li data-stringify-indent="0" data-stringify-border="0">We're designing the future of <strong data-stringify-type="bold">autonomous marketing</strong>, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.</li>
</ul>
<div class="p-rich_text_section">And we're building all of that on the intelligence of a single AI engine — <strong data-stringify-type="bold">Loomi </strong>— so that personalization isn't only autonomous…it's also consistent.From retail to financial services, hospitality to gaming, businesses use Bloomreach to drive higher growth and lasting loyalty. We power personalization for more than 1,400 global brands, including American Eagle, Sonepar, and Pandora.</div></div><p><strong>About the Role:</strong></p>
<p>You will act as the designated security focus on a specific product domain, driving threat modeling, security assessments, and vulnerability management across Bloomreach's platform.</p>
<p><strong>Your Job Will Be:</strong></p>
<ul>
<li>Support the implementation and adoption of <strong>Secure Software Development Lifecycle </strong>(<strong>SSDLC</strong>) practices across engineering teams, helping integrate security throughout the product development process.</li>
<li>Perform security reviews of <strong>application designs</strong>, <strong>system architectures</strong>, and i<strong>nfrastructure components</strong>, with guidance as needed, to identify security risks and recommend appropriate mitigations.</li>
<li>Participate in <strong>threat modeling</strong> exercises for new and existing products, helping identify threats, assess risk, and document practical security recommendations.</li>
<li>Provide security guidance to product and engineering teams by applying established security standards, patterns, and best practices, escalating complex security concerns when appropriate.</li>
<li>Conduct <strong>security assessments</strong>, <strong>penetration testing</strong>, and <strong>validation testing</strong> across applications and environments using established methodologies and processes.</li>
<li><strong>Triage</strong>, <strong>validate</strong>, and assign vulnerabilities identified through security tools and assessments, working with the appropriate stakeholders to support timely <strong>remediation</strong>.</li>
<li>Collaborate with <strong>engineering</strong>, <strong>DevOps</strong>, <strong>compliance</strong>, and other <strong>cross-functional teams</strong> to address security requirements and support secure product development.</li>
<li>Develop knowledge of assigned product domains and serve as a security point of contact for routine security questions and activities, with support from senior security team members for complex or higher-risk matters.</li>
</ul>
<p><strong>Professional Experience and Skills Requirements:</strong></p>
<ul>
<li><strong>2+ years </strong>of hands-on experience in cybersecurity, application security, product security, or a related security discipline.</li>
<li>Practical experience performing or supporting security assessments and <strong>penetration testing</strong> of <strong>web applications</strong>.</li>
<li>Familiarity with <strong>threat modeling</strong> concepts and methodologies such as <strong>STRIDE</strong>, with the ability to identify common threats and security risks.</li>
<li>Understanding of vulnerability management fundamentals, including vulnerability validation, risk-based prioritization, remediation tracking, and retesting.</li>
<li>Exposure to <strong>AI</strong> and <strong>LLM </strong>technologies with an interest in developing knowledge of associated security risks and controls.</li>
<li>Working knowledge of modern application architectures, <strong>APIs</strong>, authentication and authorization mechanisms, and common application security considerations.</li>
<li>Knowledge of <strong>OWASP</strong> standards and resources, including the <strong>OWASP Top 10</strong>, Testing Guide, and secure development practices.</li>
<li>Hands-on experience with, or familiarity with, security testing tools such as <strong>Burp Suite</strong>, <strong>OWASP ZAP</strong>, <strong>Nmap</strong>, <strong>SAST/SCA</strong> tools, and other application security technologies.</li>
<li>Ability to analyze and validate security findings and prioritize vulnerabilities based on technical risk and business context, with guidance as needed.</li>
<li>Strong <strong>communication skills</strong> with the ability to clearly document findings and communicate technical concepts to engineering and other stakeholders.</li>
<li><strong>Self-motivated </strong>and <strong>proactive</strong>, with a willingness to learn, take ownership of assigned tasks, and contribute to process improvements.</li>
<li>Team-oriented mindset with the ability to collaborate effectively with <strong>Security</strong>, <strong>Engineering</strong>, <strong>DevOps</strong>, and other <strong>cross-functional teams</strong>.</li>
<li>Continuous learning mindset with a strong interest in developing technical security expertise and staying current with emerging technologies and threats.</li>
<li>Excellent command of the English language, demonstrating strong listening, speaking, reading, and written communication skills.</li>
</ul>
<p><strong>Your Success Story Will Be</strong></p>
<p><strong>In the First 30 Days</strong></p>
<ul>
<li>Develop a foundational understanding of Bloomreach's product portfolio, architecture, and core services.</li>
<li>Become familiar with internal SOPs, security policies, standards, and Product Security team workflows.</li>
<li>Gain working knowledge of the security tools, technologies, and platforms used by the Product Security team.</li>
<li>Understand established processes for security assessments, threat modeling, vulnerability management, and penetration testing.</li>
<li>Begin establishing working relationships with key partners across Engineering, DevOps, Compliance, and other relevant teams.</li>
</ul>
<p><strong>In the First 60 Days</strong></p>
<ul>
<li>Actively contribute to penetration tests and security assessments of web applications and product components, with guidance from more senior team members as needed.</li>
<li>Participate in threat modeling sessions using methodologies such as STRIDE and contribute to identifying potential threats and design risks.</li>
<li>Review and triage vulnerability data and security findings from scanning tools, manual testing, and other security sources.</li>
<li>Analyze and validate security findings, assess potential risk, and develop remediation recommendations in collaboration with senior team members and Engineering.</li>
<li>Continue building knowledge of Bloomreach's products, architecture, and security landscape, including emerging AI and LLM-related security risks.</li>
</ul>
<p><strong>In the First 90 Days</strong></p>
<ul>
<li>Independently perform well-defined security assessments and testing activities, escalating complex or higher-risk issues when appropriate.</li>
<li>Actively contribute to threat modeling sessions by identifying threats, documenting risks, and recommending appropriate security controls.</li>
<li>Engage directly with Engineering teams to communicate security findings, support remediation efforts, and validate implemented fixes.</li>
<li>Apply established Product Security standards and processes to provide security guidance for routine application security questions and development activities.</li>
<li>Demonstrate growing ownership of assigned security activities and product areas while seeking guidance for unfamiliar or complex scenarios.</li>
<li>Identify opportunities to improve team processes, documentation, tooling, or workflows and contribute to implementing those improvements.</li>
</ul>
<p><span style="color: rgb(255, 255, 255);">#LI-HO1</span></p><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p><span style="font-weight: 400;">The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.</span></p></div><div class="title">Base Salary Range</div><div class="pay-range"><span>€28.114</span><span class="divider">—</span><span>€35.143 EUR</span></div></div></div><div class="content-conclusion"><h2 style="text-align: justify;"><span style="font-size: 18pt;">More things you'll like about Bloomreach:</span></h2>
<h3 style="text-align: justify;"><strong>Culture:</strong></h3>
<ul>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one. </span></div>
</li>
<li>
<div><span style="font-weight: 400;">We have defined our </span><a href="https://www.bloomreach.com/en/careers?utm_source=Job-Description-Footer&utm_medium=Job-Description&utm_content=Hyperlink-1" target="_blank"><span style="font-weight: 400;">5 values</span></a><span style="font-weight: 400;"> and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication. </span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We believe in flexible working hours to accommodate your working style.</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We work virtual-first with several Bloomreach Hubs available across three continents.</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We organize company events to experience the global spirit of the company and get excited about what's ahead.</span></div>
</li>
<li data-stringify-indent="0" data-stringify-border="0">
<div>We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*.</div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">The </span><a href="https://www.glassdoor.com/Overview/Working-at-Bloomreach-EI_IE442167.11,21.htm" target="_blank"><span style="font-weight: 400;">Bloomreach Glassdoor page</span></a><span style="font-weight: 400;"> elaborates on our stellar 4.7/5 rating. The <a href="https://www.comparably.com/companies/bloomreach" target="_blank">Bloomreach Comparably page</a> Culture score is even higher at 4.9/5</span></div>
</li>
</ul>
<h3 style="text-align: justify;"><strong>Personal Development:</strong></h3>
<ul style="text-align: justify;">
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.</span></div>
</li>
<li>
<div><span style="font-weight: 400;">Our resident communication coach </span><a href="https://www.linkedin.com/in/ivo-ve%C4%8De%C5%99a-2a94291/" target="_blank"><span style="font-weight: 400;">Ivo Večeřa</span></a><span style="font-weight: 400;"> is available to help navigate work-related communications & decision-making challenges.*</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins.</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)*</span></div>
</li>
</ul>
<h3 style="text-align: justify;"><strong>Well-being:</strong></h3>
<ul style="text-align: justify;">
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Subscription to Calm - sleep and meditation app.*</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We facilitate sports, yoga, and meditation opportunities for each other.</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Extended parental leave up to 26 calendar weeks for Primary Caregivers.*</span></div>
</li>
</ul>
<h3 style="text-align: justify;"><strong>Compensation:</strong></h3>
<ul style="text-align: justify;">
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">Everyone gets to participate in the company's success through the company performance bonus.*</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We offer an employee referral bonus of up to $3,000!</span></div>
</li>
<li style="font-weight: 400;">
<div><span style="font-weight: 400;">We reward & celebrate work anniversaries -- Bloomversaries!*</span></div>
</li>
</ul>
<p style="text-align: justify;"><em><span style="font-weight: 400;">(*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.)</span></em></p>
<p style="text-align: justify;"><strong>Excited? Join us and transform the future of commerce experiences!</strong></p>
<p style="text-align: justify;"><span style="font-weight: 400;"><em>If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful!</em></span></p>
<hr>
<p style="text-align: justify;"><em><span style="font-weight: 400;">Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees.</span></em></p>
<p style="text-align: justify;"><span style="color: rgb(236, 240, 241);">#LI-Remote</span></p></div>