Product Security Engineer
Bloomreach · Slovakia
- Junior
- Full-time
- Posted 2026-09-22
- Confirmed live on 25 September 2026
Job description
Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey.
• We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.
• We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey.
• We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.
And we're building all of that on the intelligence of a single AI engine — Loomi — so that personalization isn't only autonomous…it's also consistent.From retail to financial services, hospitality to gaming, businesses use Bloomreach to drive higher growth and lasting loyalty. We power personalization for more than 1,400 global brands, including American Eagle, Sonepar, and Pandora.
About the Role:
You will act as the designated security focus on a specific product domain, driving threat modeling, security assessments, and vulnerability management across Bloomreach's platform.
Your Job Will Be:
• Support the implementation and adoption of Secure Software Development Lifecycle (SSDLC) practices across engineering teams, helping integrate security throughout the product development process.
• Perform security reviews of application designs, system architectures, and infrastructure components, with guidance as needed, to identify security risks and recommend appropriate mitigations.
• Participate in threat modeling exercises for new and existing products, helping identify threats, assess risk, and document practical security recommendations.
• Provide security guidance to product and engineering teams by applying established security standards, patterns, and best practices, escalating complex security concerns when appropriate.
• Conduct security assessments, penetration testing, and validation testing across applications and environments using established methodologies and processes.
• Triage, validate, and assign vulnerabilities identified through security tools and assessments, working with the appropriate stakeholders to support timely remediation.
• Collaborate with engineering, DevOps, compliance, and other cross-functional teams to address security requirements and support secure product development.
• Develop knowledge of assigned product domains and serve as a security point of contact for routine security questions and activities, with support from senior security team members for complex or higher-risk matters.
Professional Experience and Skills Requirements:
• 2+ years of hands-on experience in cybersecurity, application security, product security, or a related security discipline.
• Practical experience performing or supporting security assessments and penetration testing of web applications.
• Familiarity with threat modeling concepts and methodologies such as STRIDE, with the ability to identify common threats and security risks.
• Understanding of vulnerability management fundamentals, including vulnerability validation, risk-based prioritization, remediation tracking, and retesting.
• Exposure to AI and LLM technologies with an interest in developing knowledge of associated security risks and controls.
• Working knowledge of modern application architectures, APIs, authentication and authorization mechanisms, and common application security considerations.
• Knowledge of OWASP standards and resources, including the OWASP Top 10, Testing Guide, and secure development practices.
• Hands-on experience with, or familiarity with, security testing tools such as Burp Suite, OWASP ZAP, Nmap, SAST/SCA tools, and other application security technologies.
• Ability to analyze and validate security findings and prioritize vulnerabilities based on technical risk and business context, with guidance as needed.
• Strong communication skills with the ability to clearly document findings and communicate technical concepts to engineering and other stakeholders.
• Self-motivated and proactive, with a willingness to learn, take ownership of assigned tasks, and contribute to process improvements.
• Team-oriented mindset with the ability to collaborate effectively with Security, Engineering, DevOps, and other cross-functional teams.
• Continuous learning mindset with a strong interest in developing technical security expertise and staying current with emerging technologies and threats.
• Excellent command of the English language, demonstrating strong listening, speaking, reading, and written communication skills.
Your Success Story Will Be
In the First 30 Days
• Develop a foundational understanding of Bloomreach's product portfolio, architecture, and co
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Bloomreach
- Senior Commerce Experience Advisor (BeNeLux) · United Kingdom
- Business Consultant (6 months contract with possible extension) · Czechia
- Business Consultant (6 months contract with possible extension) · Slovakia
- Principal Solutions Architect · US
- Principal Solutions Architect · United Kingdom
- Public Relations and Communications Specialist · United States
- Senior Business Consultant w/ French · Czechia
- Senior Business Consultant w/ French · Slovakia