Principal Product Security Engineer

Location US-MA-Burlington
Job ID
Information Technology - All Openings
Pos. Type
Full Time

Company Overview

At Nuance, we empower people with the ability to seamlessly interact with their connected devices and the digital world around them. We are creating a world where technology thinks and acts the way people do by designing the most human, natural, and intuitive ways of interacting with technology.

Our nimble technology uses analytics and advanced algorithms to transform the inanimate into animate and reduce complicated processes into simple ones.

The Nuance Global IT team is focused on supporting the company and employees with technical solutions and expertise that help the business run more efficiently, ensure security and data privacy, and support new IT infrastructure initiatives that drive innovation. Our team is composed of problem solvers with constant curiosity and different perspectives who love to collaborate to transform and rethink IT.

Job Summary

The Principal Product Security Engineer will report to the Director of Information Security.  Major duties will focus on providing secure development services such as design reviews, code reviews, and security testing during product development, as well as providing training and consultation to product teams to improve their internal capabilities in these areas. This engineer will also drive adoption of security tools and services from external vendors, evaluating and selecting vendors, assisting integration of these services into engineering workflows, and providing expertise to interpret and remediate security issues identified by these tools and services.




Perform design consultation, architecture review, threat modeling, code review, and testing.

•Assist in the development of test cases, scripts, procedures, and tooling for QA security testing.

•Perform application vulnerability assessments

•Analyze output from security tooling and provide guidance to drive remediation

•Assess SDLC processes and provide guidance on increasing security review coverage

•Identify toolsets and vendors, drive adoption and implementation

•Consult with development and QA staff to remove false positives and prioritize remediation based on security scanning tools’ output.



Perform tasks related to securing and keeping the products, tools, and processes that you are responsible for secure.


Bachelor’s Degree in Computer Engineering, Computer Science, or Information Systems Management.  Will consider work experience in lieu of or supplementing formal education.

CISSP, CSSLP, CEH or equivalent security certifications

Minimum years of work experience:
5 years’ experience in application security + 3-5 years software development experience (development or QA)

Required skills:
In-depth knowledge of IT organization end-to-end areas and functions

Understanding and familiarity with common code review methods and standards

Knowledge of secure coding patterns and pitfalls in multiple languages (Java, .NET, C++, Python…)

Knowledge of secure configuration patterns for middleware and OS platforms (Tomcat, JBoss, Weblogic; common relational and NoSQL dbs; Windows, Linux, iOS, Android, Azure and AWS Cloud infrastructure)

Demonstrated experience providing security review of web applications, mobile applications, thick clients, web APIs (REST, SOAP), AuthZ/AuthN protocols and technologies, and cryptography

Experience with static analysis and dynamic analysis tools

Experience with offensive security tools and methodologies

Penetration testing experience, especially at the application level

Familiarity with development and test toolsets (source code control, build systems, test automation, ticketing systems)

Knowledge of OWASP tools and methodologies (Top 10 2013,2017)

Knowledge of standard SDLC practices and security touchpoints in Agile, DevOps, waterfall processes

Experience with application security requirements of HIPAA, PCI and ISO 27000.

Preferred skills:

Solid understandings of security on networks, hardening, patch management, pen testing, vulnerability testing, Windows systems, open systems, applications, and web and public facing systems. Azure / AWS Cloud architecture related to application security a must.

Knowledge of analytic and monitoring tools (ElasticSearch, LogStash, and Kibana (ELK) and/or Splunk, Sumologic)

Ability to code python

Expertise with Vericode, Rapid7 Nexpose, Whitehat or other vulnerability scanners

Ability to reverse engineer undocumented applications or architectures

Linux, Windows system administration

Ability to multi-task under agilee deadlines.

Proficient English language written and oral communication skills

Additional Information

Nuance offers a compelling and rewarding work environment. We offer market competitive salaries, bonus, equity, benefits, meaningful growth and development opportunities and a casual yet technically challenging work environment. Join our dynamic, entrepreneurial team and become part of our continuing success.


Nuance Communication Inc.  is an equal opportunity employer.  We evaluate qualified applicants without regard to race, age, color, religion, sex, national origin, disability, veteran status, gender identity, sexual orientation and other legally protected characteristics. The EEO is the Law poster and its supplement is available here. If you need a reasonable accommodation because of a disability for any part of the employment process, please call 781-565-5000 – Human Resources Department and let us know the nature of your request and your contact information.


Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed

Connect With Us!

Not ready to apply? Connect with us for general consideration.