Overview The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle ...
Overview The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle ...
Principal Product Security Engineer
Vienna, VA · On-site
$130 - $180/hr
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
Principal Product Security Engineer
Vienna, VA · On-site
$130 - $180/hr
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
Responsibilities Product Security Engineering * Lead security reviews for complex products, features, services, and architectures. * Perform threat modeling and identify security risks early in the ...
Responsibilities Product Security Engineering * Lead security reviews for complex products, features, services, and architectures. * Perform threat modeling and identify security risks early in the ...
Overview The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle ...
Overview The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle ...
Senior Staff Product Security Engineer, AI Security & Security Assurance
Mclean, VA · On-site
$154 - $205/hr
Responsibilities Product Security Engineering * Lead security reviews for complex products, features, services, and architectures. * Perform threat modeling and identify security risks early in the ...
Senior Staff Product Security Engineer, AI Security & Security Assurance
Mclean, VA · On-site
$154 - $205/hr
Responsibilities Product Security Engineering * Lead security reviews for complex products, features, services, and architectures. * Perform threat modeling and identify security risks early in the ...
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development
Herndon, VA · On-site
$117K - $161K/yr
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development
Herndon, VA · On-site
$117K - $161K/yr
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development
Arlington, VA · On-site
$131K - $180K/yr
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
Senior Product Security Engineer - Avionics Development
Arlington, VA · On-site
$131K - $180K/yr
Senior Product Security Engineer - Avionics Development Company: The Boeing Company Boeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our ...
You will work closely with Product Security leadership to identify gaps in current workflows, propose improvements, and operationalize repeatable processes that produce defensible security outcomes.
You will work closely with Product Security leadership to identify gaps in current workflows, propose improvements, and operationalize repeatable processes that produce defensible security outcomes.
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices ...
Sr Product Application Security Engineer
Reston, VA · On-site
$87 - $157/hr
Leidos Security Enterprise Solutions (SES) is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms and product capabilities used across Ports & Borders and ...
Sr Product Application Security Engineer
Reston, VA · On-site
$87 - $157/hr
Leidos Security Enterprise Solutions (SES) is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms and product capabilities used across Ports & Borders and ...
Enterprise Cybersecurity Product Analyst
Mclean, VA · On-site +1
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
Enterprise Cybersecurity Product Analyst
Mclean, VA · On-site +1
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
You will translate security requirements into practical guidance that product teams can use, while improving consistency in how products are assessed, documented, and approved. You will work closely ...
Partner directly with product and engineering teams to embed security across the full AI stack - including AI experiences, agents, agent harnesses, underlying models, and context sources such as MCP ...
Partner directly with product and engineering teams to embed security across the full AI stack - including AI experiences, agents, agent harnesses, underlying models, and context sources such as MCP ...
Special Access Program (SAP) Product Security Manager
Alexandria, VA · On-site
$120 - $180/hr
Special Access Program (SAP) Product Security Manager #4772 Everforth ECS Federal has an immediate opening for a Special Access Program (SAP) Product Security Manager for a Department of Defense (DoD ...
Special Access Program (SAP) Product Security Manager
Alexandria, VA · On-site
$120 - $180/hr
Special Access Program (SAP) Product Security Manager #4772 Everforth ECS Federal has an immediate opening for a Special Access Program (SAP) Product Security Manager for a Department of Defense (DoD ...
Thomson Reuters is seeking a Vice President, AI Product Security to embed security across the AI stack, define risk requirements, and guide architecture decisions. You will engage with product ...
Thomson Reuters is seeking a Vice President, AI Product Security to embed security across the AI stack, define risk requirements, and guide architecture decisions. You will engage with product ...
Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with security ...
Quick apply
Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with security ...
Product Security information
See Virginia salary details
$51.1K - $64.2K
0% of jobs
$64.2K - $77.3K
1% of jobs
$77.3K - $90.4K
3% of jobs
$90.4K - $103.5K
4% of jobs
$103.5K - $116.6K
5% of jobs
$116.6K - $129.7K
5% of jobs
$135.3K is the 25th percentile. Wages below this are outliers.
$129.7K - $142.9K
14% of jobs
$142.9K - $156K
5% of jobs
The median wage is $164.5K / yr.
$156K - $169.1K
18% of jobs
$179.1K is the 75th percentile. Wages above this are outliers.
$169.1K - $182.2K
24% of jobs
$182.2K - $195.3K
19% of jobs
$51.1K
$158K
$195.3K
How much do product security jobs pay per year?
What is a product security?
A Product Security job focuses on ensuring that software, hardware, and services are designed, developed, and maintained with strong security measures. Professionals in this role identify vulnerabilities, implement security controls, and work closely with development teams to integrate security throughout the product lifecycle. They may conduct threat modeling, perform security assessments, and ensure compliance with industry standards. The goal is to protect products from cyber threats, safeguard user data, and maintain trust in the organization's offerings.
What are the typical daily responsibilities of a product security professional?
In a Product Security role, your daily tasks might include performing threat modeling, reviewing code for security vulnerabilities, and working with development teams to implement secure coding practices. You may also conduct regular security assessments, oversee the remediation of identified issues, and respond to security incidents as needed. Collaboration is a key part of the job, as you’ll work closely with product managers, engineers, and IT teams to ensure security is integrated from design through deployment. Staying up-to-date with emerging threats and industry best practices is also an important part of the role.
What are the key skills and qualifications needed to thrive in product security, and why are they important?
To excel in Product Security, you typically need a solid understanding of application security, secure software development, vulnerability assessment, and a relevant degree in computer science or cybersecurity. Familiarity with security testing tools (like Burp Suite, Fortify, or Nessus), as well as certifications such as CISSP, CEH, or OSCP, is often expected. Strong analytical thinking, problem-solving skills, and the ability to communicate complex security concepts to non-technical stakeholders set top candidates apart. These abilities are essential to effectively identify, mitigate, and communicate product risks, ensuring robust security throughout the product lifecycle.
What are the most commonly searched types of Product Security jobs in Virginia?
The most popular types of Product Security jobs in Virginia are:
What are popular job titles related to Product Security jobs in Virginia?
For Product Security jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Product Security jobs in Virginia look for?
The top searched job categories for Product Security jobs in Virginia are:
What cities in Virginia are hiring for Product Security jobs?
Cities in Virginia with the most Product Security job openings:

Other
This job post has expired 1 day ago. Applications are no longer accepted.
Navy Federal Credit Union rating
8.1
Based on 275 frontline employees who took The Breakroom Quiz
63rd of 151 rated financial services
Job description
The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating Secure Software Development Lifecycle practices across Navy Federal's software delivery environment. This role serves as the Secure Development Practice integration lead with our Engineering and Technology Services (ETS) organization software delivery teams, ensuring product security expectations are embedded into standard engineering workflows, governance forums, delivery processes, and lifecycle activities.
The role will help evolve product security from standalone reviews and manual touchpoints into a scalable, risk-informed, AI powered, and developer-aligned operating model. The individual will partner with Secure Development Practice leaders, ETS, Product Engineering, Architecture, DevSecOps, platform teams, Information Security, governance, and risk stakeholders to define practical integration patterns for secure-by-design delivery.
This position will establish repeatable process definitions, ownership models, workflow guidance, control integration points, and adoption measures that improve security outcomes while reducing delivery friction.
Responsibilities
- Define and mature Secure Software Development Lifecycle practices aligned to Navy Federal software delivery processes, operating models, and secure development practices.
- Define and support a pre-production product security scorecard to support risk-informed release decisions, ensuring product security posture, open risks, exceptions, and required remediation actions are clearly communicated to business and technology stakeholders.
- Serve as the senior individual contributor integration lead for embedding Secure Development Practice capabilities into Navy Federal engineering workflows, governance forums, and lifecycle activities.
- Map product security activities to software delivery processes including intake, planning, architecture review, design, development, testing, release, exception management, and operational handoff.
- Establish repeatable process patterns for integrating threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, product integrity testing, and risk-based exception handling into engineering workflows.
- Identify and reduce redundant reviews, unclear handoffs, late-stage security friction, and legacy process steps that are not aligned to Navy Federal software delivery practices.
- Develop Secure SDLC operating models, workflow diagrams, playbooks, process documentation, RACI models, control integration points, and implementation guidance.
- Translate security standards, objectives, and risk expectations into practical engineering requirements and developer-consumable guidance.
- Partner with software engineering, architecture, DevSecOps, Information Security, governance, and risk stakeholders to align secure development practices with enterprise delivery processes.
- Support integration of secure development expectations into architecture governance, delivery boards, exception processes, and lifecycle risk decision points.
- Recommend process improvements that strengthen security outcomes, improve developer experience, increase risk visibility, and enable secure delivery at scale.
- Establish adoption and effectiveness measures that demonstrate Secure SDLC maturity, control integration, developer enablement, reduced friction, and improved product security outcomes.
- Lead cross-functional working sessions, develop executive-ready recommendations, and influence process decisions across security and engineering stakeholders without direct authority.
Qualifications
- Bachelor's degree in information technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, or related field, or the equivalent combination of education, training, and experience.
- Experience defining, improving, or integrating secure development lifecycle practices into enterprise software delivery processes.
- Strong understanding of secure development practices including threat modeling, secure coding, application security testing, software composition analysis, API security, software supply chain security, vulnerability management, and risk-based exception handling.
- Extensive hands-on experience translating security requirements, control objectives, or risk expectations into practical engineering processes, workflow guidance, and delivery requirements.
- Demonstrated experience developing process documentation, operating models, workflow diagrams, playbooks, standards, RACI models, implementation guidance, or executive-level recommendations.
- Strong facilitation, analytical thinking, systems thinking, problem-solving, communication, and stakeholder influence skills.
- Ability to operate independently as a senior individual contributor and lead complex cross-functional initiatives without direct reporting authority.
Desired Qualifications
- Extensive hands-on experience in application security, secure SDLC, software engineering, DevSecOps, enterprise architecture, technology risk, or software delivery governance.
- Strong understanding of software delivery practices including Agile, SAFe, DevOps, DevSecOps, CI/CD, product-oriented delivery, architecture governance, and release management.
- Advanced degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Information Systems, Engineering, Business Administration, or related field.
- Experience with industry frameworks or models such as NIST Secure Software Development Framework, OWASP SAMM, OWASP ASVS, OWASP Top 10, BSIMM, ISO 27001, NIST Cybersecurity Framework, or similar security and software assurance practices.
- CISSP, CISM, CSSLP, CCSP, GIAC, cloud security, architecture, Agile, SAFe, or related professional certifications.
Additional Information
Hours:
- Monday - Friday, 8:00AM - 4:30PM
Location:
- 820 Follin Lane, Vienna, VA 22180
- 5510 Heritage Oaks Drive, Pensacola, FL 32526
- 141 Security Drive, Winchester, VA 22602
About Us
Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.
Our approach to careers is simple yet powerful: Make our mission your passion.
FORTUNE 100 Best Companies to Work For 2026
Yello and WayUp Top 100 Internship Programs 2025
Computerworld Best Places to Work in IT 2026
Most Loved Workplace - America's Top Most Loved Workplaces 2025
2025 PEOPLE Companies That Care
Newsweek Most Trustworthy Companies in America 2026
Military Times 2025 Best for Vets Employers
Forbes 2026 America's Best Large Employers
Forbes 2025 America's Best Employers for New Grads
Forbes 2025 America's Best Employers for Tech Workers
2025 RippleMatch Campus Forward Award Winner for Overall Excellence
Military.com Top Military Spouse Employers 2025
2026 Handshake Early Talent Award
Newsweek America's Greatest Workplaces for Culture, Belonging and Community 2026
From Fortune Magazine. 2026 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune 100 Best Companies to Work For are registered trademarks of Fortune Media IP Limited and are used under license. Fortune Magazine, Fortune Media (USA) Corporation, and its affiliates are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.
Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to age, race, sex, color, religion, national origin, disability, veteran status, pregnancy, sexual orientation, genetic information, gender identity or any other basis protected by applicable law.
Accommodations: If you need accommodation or assistance for a qualifying condition to complete the online application (or during any stage of the hiring process), you can contact Navy Federal's Medical Accommodations team at or by calling 1-. This team cannot provide any information on job postings or application status.
Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team's discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position. For additional details regarding compensation and benefits, review the Benefits page of the Navy Federal Career Site.
Protect Yourself from Job Scams: Navy Federal Credit Union jobs are posted on our career site, jobs.navyfederal.org and reputable job boards (e.g., LinkedIn, Indeed). We do not post jobs on social media marketplaces, messaging apps or unverified websites. We will never ask candidates for payment, bank details or personal financial information during the hiring process.
Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.
What Navy Federal Credit Union employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Navy Federal Credit Union
Sourced by ZipRecruiter
Navy Federal Credit Union, based in Vienna, Virginia, United States, is a significant player in the financial services industry. Their official website is navyfederal.org. With its roots dating back to 1933, it was initially established to provide credit to Navy members. Over the years, Navy Federal has magnified its scope, evolving into a full-service credit union serving all branches of the military, the Department of Defense, veterans, and their families. The company’s core values include integrity, service, education, and leadership. Navy Federal aims to be the most preferred and trusted financial institution serving the military and their families.
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
Vienna, VA, US
Year founded
1933