Senior Product Security Engineer – Taiwan
Obsidian Security · Taipei, Taiwan
- Senior
- Full-time
- Posted 2026-09-16
- Confirmed live on 25 September 2026
Job description
Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.
In August 2026, Obsidian raised $85 million in Series D financing led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing Ventures, and GV — pushing Obsidian's valuation to $1.1 billion, crossing into unicorn status. Obsidian is using the funding to deepen its R&D in agentic AI security and extend its platform as the standard for governing what AI agents can access and do inside third-party applications.
With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and fresh capital from its Series D behind it, Obsidian is scaling rapidly toward long-term growth and IPO readiness.
Senior Product Security Engineer – Taiwan
About the Role: Obsidian Security is looking for a Senior Product Security Engineer to join our growing engineering organization in Taiwan. In this role, you will strengthen the security of Obsidian’s products, software supply chain, development pipelines, and cloud infrastructure. You will work across the complete product lifecycle—from architecture and implementation through deployment and production operations—to identify security risks and build practical, scalable solutions. This is a hands-on engineering role requiring deep product security knowledge and strong software development skills. You will lead vulnerability and CVE remediation, improve security controls within CI/CD pipelines, conduct product security reviews, and develop security features for both application and infrastructure platforms. You will collaborate closely with Product Engineering, Platform Engineering, SRE, Security Research, and Infrastructure teams across Taiwan, the US, the UK, and Australia.
What You’ll Do:
• Perform security architecture and design reviews for new products, services, APIs, data pipelines, and infrastructure components.
• Identify security risks early in the development lifecycle and help engineering teams design practical mitigations.
• Lead the end-to-end CVE management process, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation.
• Evaluate the real-world exploitability and customer impact of vulnerabilities rather than relying exclusively on severity scores.
• Partner with product, platform, infrastructure, and SRE teams to safely patch vulnerable application and infrastructure dependencies.
• Improve patch reliability through automated regression testing, staged rollouts, compatibility validation, rollback mechanisms, and post-deployment monitoring.
• Strengthen CI/CD pipelines with automated security controls, including dependency scanning, static analysis, container scanning, infrastructure-as-code scanning, secrets detection, and policy enforcement.
• Develop and maintain software supply chain security controls covering source code, open-source dependencies, build systems, artifacts, containers, and deployment workflows.
• Design and build security features for Obsidian’s products, backend services, APIs, and cloud infrastructure.
• Develop reusable security libraries, services, automation, policies, and developer tools.
• Conduct threat modeling for product capabilities and identify risks related to authentication, authorization, data access, tenant isolation, secrets, APIs, and cloud infrastructure.
• Review application code and infrastructure configurations for security vulnerabilities and design weaknesses.
• Partner with engineering teams to improve secure coding practices and resolve complex security findings.
• Investigate product and infrastructure security incidents, determine root causes, and lead corrective engineering work.
• Define security requirements, standards, metrics, and release criteria for production services.
• Improve visibility into vulnerability exposure, remediation status, security-control coverage, and residual risk.
• Mentor engineers on product security, secure architecture, vulnerability remediation, and software supply chain security.
What We’re Looking For:
• Significant experience in produc
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Obsidian Security
- Principal Solutions Engineer - APAC · Remote
- Chief Information Security Officer (CISO) · Palo Alto, CA
- AI Security Engineer - Taiwan · Taipei, Taiwan
- Senior Threat Research Engineer – Taiwan · Taipei, Taiwan
- Senior Customer Marketing Manager · US Remote
- Lead IT Systems Engineer · Palo Alto, CA
- Head of GTM Enablement · Remote - US
- Software Engineer - AI Security Product · Palo Alto, California, USA