Bose Logo

Bose

Senior Product Security Engineer

Posted 25 Days Ago
Be an Early Applicant
Hybrid
Atlanta, GA
Senior level
Hybrid
Atlanta, GA
Senior level
The Senior Product Security Engineer will lead security integration across hardware and software, conduct threat modeling, and enforce security standards, while collaborating with cross-functional teams.
The summary above was generated by AI

You know the moment. It’s the first notes of that song you love, the intro to your favorite movie, or simply the sound of someone you love saying “hello.” It’s in these moments that sound matters most. 

At Bose, we believe sound is the most powerful force on earth. We’ve dedicated ourselves to improving it for more than 60 years. And we’re passionate down to our bones about making whatever you’re listening to a little more magical.

 

The Information Technology team at Bose exists to deliver valuable and reliable business and technology solutions with an innovative, engaged, and collaborative team focused on contributing to our corporate vision.

Job Description

Senior Product Security Engineer

Location: Remote
Team: Product Security
Reports to: Director of Product Security

We’re seeking a Senior Product Security Engineer to join the global product security team at Bose, a globally recognized brand synonymous with premium audio experiences, innovation in sound technology, and a legacy of engineering excellence.

Founded in 1964 by Dr. Amar Bose, the company has a deep heritage rooted in research, pushing the boundaries of acoustics, electronics, and user experience.

We’re not just about headphones and speakers—our technology powers automotive audio systems, noise cancellation for pilots and the military, and increasingly, software-driven and cloud-connected audio platforms. This blend of physical products and digital ecosystems makes Bose a unique playground for engineers who want to work on end-to-end security solutions.

This isn’t a penetration testing role, but you'll need a solid grasp of common vulnerabilities and attack techniques — and know how to assess and respond to test results and reports when they land.

In this role, you’ll work across hardware, firmware, mobile apps, and cloud services to integrate security into every stage of the product lifecycle—from design to post-market support.

You’ll partner with engineers, product managers, legal, and supply chain stakeholders to ensure our devices and ecosystems are secure, resilient, and trusted by customers worldwide.

Key Responsibilities

  • Conduct threat modeling, security architecture reviews, and secure code/design assessments across hardware and software platforms including embedded, mobile and cloud.
  • Drive adoption of secure product development practices in collaboration with engineering teams.
  • Coordinate penetration tests by helping define scope, working with external testers, and managing the findings. Use CVSS and professional expertise to determine and guide fixes.
  • Support coordinated vulnerability disclosure and product security incident response.
  • Create, contribute to, and enforce security standards for firmware updates, device provisioning, authentication, and secure boot.
  • Collaborate with partners and vendors to ensure secure technology integration, licensing, and intellectual property protection.
  • Champion cryptographic best practices, key management processes, and IP protection mechanisms throughout the product development lifecycle.
  • Participate in regulatory compliance initiatives (e.g., TISAX, ISO, NIST/CISA guidance) and customer assurance activities.
  • Share knowledge through mentoring, documentation, and internal training on secure software development and product design.

Qualifications

  • 5+ years of experience in product or application security, preferably in embedded systems, consumer electronics, or connected devices.
  • Solid understanding of secure product development lifecycle (SPDLC), threat modeling, and software/hardware security principles.
  • Proficiency in secure coding and architecture review, with the ability to guide teams in implementing mitigations.
  • Skilled at assessing penetration test and scan reports, scoring findings, and collaborating with engineering teams to deliver fixes.
  • Familiarity with IoT or smart home devices, mobile platforms (Android/iOS), and cloud service integrations.
  • Hands-on experience with SAST/DAST, SBOM tools, and secure firmware update mechanisms.
  • Strong understanding of Linux environments, command-line tools, and automation such as CI/CD pipelines, Dockerized workflows, and scripting.
  • Practical knowledge of modern cryptography, key management, and secure provisioning techniques.
  • Strong interpersonal and communication skills with the ability to influence across engineering and non-engineering teams.

Preferred

  • Experience with hardware interfaces (I2C, SPI, UART), embedded Linux, or RTOS platforms.
  • Experience with secure product manufacturing processes and OTA updates.
  • Knowledge of licensing implications of 3rd-party software, open source, and technology IP.

Why Join Us?

  • Collaborate with top-tier engineers building award-winning audio and connected products.
  • Work in a security-first culture backed by leadership and aligned to modern regulatory frameworks.
  • Help shape the security posture of products used by millions globally.

Bose is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status, or any other legally protected characteristics. The EEOC’s “Know Your Rights: Workplace discrimination is illegal” Poster is available here: https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf. Bose is committed to providing reasonable accommodations to individuals with disabilities. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to [email protected]. Please include "Application Accommodation Request" in the subject of the email.

Our goal is to create an atmosphere where every candidate feels supported and empowered in the interviewing process. Diversity and inclusion are integral to our success, and we believe that providing reasonable accommodation is not only a legal obligation but also a fundamental aspect of our commitment to being an employer of choice. We recognize that individuals may have different needs and requirements based on their abilities, and we provide reasonable accommodations to ensure ideal conditions are met during the application process.

Top Skills

Ci/Cd
Cloud Services
Dast
Docker
Embedded Systems
Linux
Mobile Platforms
Sast
HQ

Bose Framingham, Massachusetts, USA Office

Bose Framingham, MA HQ Office

The Bose Corporation was founded in 1964 by Dr. Amar Bose, right here in Massachusetts - a legacy that continues to shape our culture of innovation and excellence. Our HQ campus comprises of three buildings and more than 1,500 team members, supporting collaboration and driving our shared mission.

Similar Jobs at Bose

Yesterday
Hybrid
3 Locations
Expert/Leader
Expert/Leader
Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
The Vice President of Product Management & Innovation Strategy will lead product vision and strategy, manage technology portfolios, drive innovation, and foster collaboration across functions to enhance Bose's audio technology presence.
Top Skills: Audio TechnologyInnovation StrategyLicensingProduct Management
Yesterday
In-Office
Atlanta, GA, USA
8-10
Senior level
8-10
Senior level
Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
As a Cloud Architect, you'll design, implement, and manage cloud solutions while ensuring alignment with business goals and security practices.
Top Skills: AWSAzureCi/CdCloud SecurityComputeDatabasesDockerGCPKubernetesNetworkingServerless ArchitecturesStorage
4 Days Ago
Hybrid
City of Homeland, GA, USA
Expert/Leader
Expert/Leader
Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
The IAM Engineer supports design and maintenance of identity governance and access management technologies, focusing on SailPoint and CyberArk, while enhancing security measures and managing privileged access.
Top Skills: Active DirectoryAWSAzureAzure AdCyberark Privileged CloudGCPJavaScriptMulti-Factor AuthenticationOauthPowershellPythonSailpoint IdentitynowSAMLSingle Sign-On

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account