Senior Product Security Engineer
Are you ready for what’s next?
Come explore opportunities within Brunswick, a global marine leader committed to challenging conventions and innovating next-generation technologies that transform experiences on the water and beyond. Brunswick believes “Next Never Rests™,” and we offer a variety of exciting careers and growth opportunities within united teams defining the future of marine recreation.
Location: Mettawa, IL
Workplace Category: Hybrid
Travel Required: Ability to travel domestically and internationally, up to 15% as business needs require.
Direct Reports: None
Pay Range: $118,400 - $174,000
Visa Sponsorship: Applicants must be currently authorized to work in the United States. This position is not eligible for employment visa sponsorship now or in the future.
Relocation: Relocation assistance is not routinely provided and may be considered for exceptional candidates.
Innovation is the heart of Brunswick. See how your contributions will help transform vision into reality:
Position Overview**:**
The Product Security team is responsible for protecting our customers and Brunswick Corporation from evolving security threats in our products. Product security encompasses secure systems, hardware and software design of both devices and the systems to which they connect (cloud, infrastructure, server, etc.). The Product Security team partners with application development, product engineering, cloud, infrastructure, and DevSecOps teams to integrate security throughout the product lifecycle, instituting a Secure Systems/Software Development Life Cycle (SDLC) and application of applicable standards and best practices.
As a Senior Product Security Engineer, you will serve as a technical leader and trusted advisor responsible for maturing product security capabilities, improving secure development practices, and reducing product security risk across Brunswick's product portfolio. The role requires close collaboration with development teams, architects, DevSecOps engineers, cloud engineers, and business stakeholders to ensure security is embedded throughout the product lifecycle with a secure by design and default approach.
This position is responsible for advancing Brunswick's product security program through the implementation and oversight of product security governance, threat modeling, providing architectural/design guidance, developer enablement, vulnerability management, security testing, security tooling, and DevSecOps practices. The role provides technical leadership for product security initiatives, develops and maintains security policies, standards, guidelines, and best practices, and partners with engineering teams to embed security throughout the product lifecycle. Additionally, this position plays a key role in maturing and scaling Brunswick's Security by Design program to support secure, resilient, and high-quality product development across all business units.
Success in this role requires a strong understanding of potential security threats, secure system architecture, hardware security, secure software development, application security, cloud-native technologies, software supply chain security, security automation, and modern development methodologies. The ideal candidate possesses strong technical, analytical, and communication skills and can effectively collaborate with stakeholders across engineering teams to drive secure development practices and advance Brunswick's product security objectives.
Key Responsibilities
- Help build maturity of product development teams in product security through training and mentoring.
- Conduct threat modeling, attack surface analysis, and product security risk assessments for new and existing products and applications and recommend mitigating controls.
- Lead product security design reviews and participate in architecture review processes, identifying potential weaknesses or vulnerabilities and recommend appropriate changes.
- Partner with development teams to integrate security requirements into product architecture, design, development, testing, deployment, and maintenance activities.
- Define, maintain, and promote product security policies, standards, procedures, best practices, and technical guidance.
- Review false-positive requests, mitigation plans, and risk exception submissions in accordance with established security governance processes.
- Establish security testing requirements and assist teams in implementing security verification and validation throughout the development lifecycle.
- Provide security consultation for web applications, mobile applications, cloud-native applications, microservices, embedded software, and Application Programming Interfaces (APIs).
- Serve as a senior subject matter expert for product security, secure software development, and DevSecOps practices.
- Support the implementation of secure coding practices aligned with OWASP, CWE, Security by Design requirements, and Brunswick secure development standards.
- Review and analyze application security findings and provide remediation guidance to development teams.
- Support developers in resolving vulnerabilities related to applicable product security coding standards such as the Open Worldwide Application Security Project (OWASP) Top 10 risks, Common Weakness Enumeration (CWE) Top 25 weaknesses, authentication, authorization, session management, cryptography, injection attacks, and software supply chain risks.
- Monitor vulnerability remediation activities and validate remediation effectiveness through rescanning and testing.
- Provide guidance on software supply chain security, Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) creation, dependency management, and open-source software risk reduction.
- Collaborate with Security Architecture, Cloud Security, Infrastructure Security, and Engineering teams to improve organizational security maturity.
- Support vulnerability management processes, including finding triage, remediation validation, exception review, and security reporting.
- Develop metrics, scorecards, dashboards, and executive reporting related to product security posture, vulnerability management, scan compliance, and remediation performance.
- Assist development teams with secure design reviews, security-focused code reviews, and pre-release security assessments.
- Evaluate emerging technologies, product and application security tools, software supply chain security capabilities, and artificial intelligence security solutions to identify opportunities for improving Brunswick's security posture.
- Support security assessments, penetration testing activities, and remediation efforts for critical products based on business risk, regulatory requirements, or organizational priorities.
Required Qualifications:
- Bachelor’s degree in Electrical or Electronic Engineering, Computer Science, Software Engineering, Cybersecurity, or equivalent professional experience.
- 5+ years of experience in Product Security for IoT type devices and associated cloud/server systems.
- Fundamental understanding of the application of a product security standard such as ISO/SAE 21434, IEC/ISA 62443-4-1/4-2, Articles 3.3 (d), (e), and (f) of the EU Radio Equipment Directive, EU Cybersecurity Resilience Act, or comparable.
- Experience performing product threat modeling and security risk assessments.
- Strong understanding of the application of hardware security components such as a Hardware Security Module, Trusted Platform Module or similar.
- Strong understanding of the required implementation details of secure boot, secure communications, secure storage in embedded devices which leverage a hardware security component.
- Demonstrated experience leading product security initiatives for resource constrained embedded products.
- Strong understanding of SDLC and SSDLC methodologies.
- Strong understanding of secure coding principles, OWASP Top 10 risks, CWE Top 25 weaknesses, and common application attack methodologies.
- Experience with reviewing and addressing findings from Veracode or comparable application security testing platforms.
- Experience supporting vulnerability management and remediation programs.
- Knowledge of software supply chain security concepts, dependency management, open-source software governance, and SBOM practices.
- Fundamental understanding of cloud application security principles across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
- Familiarity with containerized applications, Kubernetes, and modern cloud-native architecture.
- Knowledge of secure authentication, authorization, encryption, secrets management, and application-layer security controls.
- Strong written and verbal communication skills.
- Ability to effectively influence engineering teams and drive security outcomes without direct authority.
Preferred Qualifications:
- Certification as Automotive CyberSecurity Engineer (CASE), iSAQB® Certified Professional for Software Architecture —EMBEDDEDSEC module training, GIAC Security Essentials (GSEC) certification or comparable.
- Experience applying product security standards such as ISO/SAE 21434, IEC/ISA 62443-4-1/4-2, Clause 3.3 d, e, f of the EU Radio Equipment Directive, or EU Cybersecurity Resilience Act, or comparable to an organization’s policies, processes and procedures.
- Experience leading or playing a major role in the execution of a Threat Analysis and Risk assessment, per ISO/SAE 21434.
- Experience integrating a hardware security component such as a Hardware Security Module, Trusted Platform Module or similar into a design and leveraging it in the implementation of secure boot, secure communications, or secure storage.
- Experience with software development and DevSecOps platforms, including GitHub Enterprise, Azure DevOps, Bitbucket, Gerrit, Jenkins, or similar source code management, code review, build automation, and Continuous Integration / Continuous Deployment (CI/CD) platforms.
- Experience developing security metrics, reporting programs, and risk dashboards.
- Experience supporting software supply chain security initiatives and SBOM or HBOM management.
- Familiarity with Generative Artificial Intelligence (GenAI), secure artificial intelligence development practices, and artificial intelligence-assisted software engineering.
- Experience supporting product security programs that also encompass cloud-native, web, and mobile, software environments.
- Experience operating within a large global enterprise environment.
The hiring range for this position is $118,400 - $174,000 annually. The actual base pay offered will vary based on multiple factors including job-related knowledge/skills, relevant experience, business needs, and geographic location. Compensation decisions are dependent upon the specifics of the candidate’s qualifications and the business context.
In addition to base pay, this position is eligible for an annual discretionary bonus. This position is eligible to participate in Brunswick's comprehensive and high-quality benefits offerings, including medical, dental, vision, paid vacation, 401k (up to 4% match), Health Savings Account (with company contribution), well-being program, product purchase discounts and much more. Details about our benefits can be found here.
Why Brunswick:
Whatever tomorrow brings, we’ll be at the leading edge. As the clear leader in the marine industry, we’re committed to our values and supporting our exceptional people. We offer and encourage growth opportunities within and across our many brands. In addition, we’re proud of being recognized for making a splash with numerous awards!
About Division:
Brunswick Corporation is a leader in the marine industry, and we’re looking for people just like you to take part in the movement towards better boating for all. We rely on the thoughtful input of people from all backgrounds to create compelling, innovative products for our customers around the globe. As such, diversity, equity, and inclusion are priorities in the enduring culture of our company. As a world leader in emerging recreational products and technologies, when you join our team, you become part of some of the most innovative, forward-looking brands in the marine industry today.
Next is Now!
We value growth and development, recognizing that people come with a wealth of experience and talent beyond just the technical requirements of a job. If your experience is close to what you see listed here, please still consider applying.
Brunswick is an Equal Opportunity Employer and considers all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or any other characteristic protected by federal, state, or local law. Diversity of experience and skills combined with passion is key to innovation and inspiration and we encourage individuals from all backgrounds to apply. If you require accommodation during the application or interview process, please contact [email protected] for support.
For more information about EEO laws, - click here
Brunswick Corporation participates in E-Verify as part of our commitment to a lawful and transparent hiring process. For additional information click here: https://www.brunswick.com/e-verify.
Brunswick and Workday Privacy Policies
Brunswick does not accept applications, inquiries or solicitations from unapproved staffing agencies or vendors. For help, please contact our support team at: [email protected] or 866-278-6942.
All job offers will come to you via the candidate portal you create when applying through a posted position through https:///www.brunswick.com/careers. If you are ever unsure about what is being required of you during the application process or its source, please contact HR Shared Services at 866-278-6942 or [email protected].
#Brunswick Corporation
Job Details
Salary
$118,400 – $174,000/yr (us)
Experience
Senior · 5+ yrs