Bose→
Senior Product Security Engineer at Bose in Framingham, MA
ExperiencedHybridFull-timeFramingham, MA$156k–$215k/yr
Job Description
Senior Product Security Engineer
Location: US, MA - Framingham
At Bose Corporation, we believe sound is the most powerful force on earth — and for over 60 years, we have been a company built on innovation, excellence, and independence. Privately owned, fiercely customer-focused, and driven by our values, we continue to lead industries and transform lives through sound.
Today, Bose Corporation is entering an exciting new era. Across multiple global Business Units and Global Functions, we are shaping the future of audio technology, automotive, luxury, and premium experiences. We invite you to join us in this transformation.
Job Description
SeniorProduct Security Engineer
Team:GIS Product Security
Location:Remote / Hybrid
Reports to:Senior Manager, Product Security
About the Role
At Bose, soundisn’tjust a product —it’spart of how people experience the world. From music and entertainment to travel, work, and communication, Bose products show up in moments that matter every day.
We’relooking for aSeniorProduct Security Engineerto help protect the systems and services behind those experiences — atreal, globalscale.
Bose is aproduction environment, not a lab or a startup. The work done by this team directlyimpactsproducts that aredesigned, manufactured, and shipped worldwide, withmillions of units inmarket. Security decisions made here influence real production lines, firmware releases, cloud services, software updates, and long‑term customer trust in the Bose brand.
This role sits at the intersection ofproduct development, enterprise security services, and regulatory readiness.You’llwork on security challenges that spanhardware, firmware, mobile apps, cloud services, cryptographic infrastructure, and shared engineering platforms— enabling teams across Bose to ship confidently without slowing innovation.
While experience with embedded or device security is valuable, this role focuses onenterprise‑scale product security:operatingshared services, improving visibility, managing systemic risk, and helping many teams succeed at once. Curiosity,systemsthinking, and sound judgment matter as much as depth in any one domain.
This isnota penetration testing role andnotan embedded‑only role.It’sahigh‑leveragesenior IC rolefor engineers who want their work to ship, scale, and last.
Scale & Real‑World Impact
This roleoperateswhere engineering decisions meet the real world:
Bose products ship globally and remain inmarketfor years.
Security decisions affectmillions of deployed devices, not demos or prototypes.
The Product Security team runsshared servicesused by many product and engineering teams across the company.
Software supply chain decisions — including open source and third‑party dependencies — directly affectwhat ships in production and what must be supported in market.
Ifyou’remotivated by work that hasvisible, long‑lived impact, this role delivers it.
WhatYou’llDo
Operate & Scale Core Product Security Services
Operate and evolveenterprise product security services, including:
GitHub Advanced Security and related tooling to managesoftware supply chain risk(dependency security, secrets exposure, third‑party code usage)
Product vulnerability intake and triage workflows
Cryptographic key management and HSM‑backed services
Support security activities that directly affectproduction releases and in‑market products, including signing, provisioning, vulnerability handling, and post‑launch response.
Keep these servicesreliable, predictable, and easy for product teams to use.
Enable Secure Product Development at Scale
Partner with product and platform teams acrosshardware, firmware, mobile, cloud, and backend servicesto provide practical, risk‑based security guidance.
Help defineclear engagement modelsso teams understand when and how Product Security should be involved.
Reduce friction by improvingstandards, documentation, and self‑service workflows, so security helps teams move fast and safely.
Key Management, Cryptography & IP Protection
Supportenterprise‑scale key management and HSM operations, including:
Understanding how keys are used across products and platforms
Supporting signing, provisioning, and security investigations
Improving visibility and auditability of cryptographic workflows
Champion pragmatic cryptographic practices that protect Bose intellectual property and product integrity.
Software Supply Chain & Third‑Party Risk
Support secure use ofopen source and third‑party softwareacross Bose products.
Helpidentifyand manage dependency risk using tooling (e.g., GHAS) and clear ownership models.
Partner with engineering, legal, and supply chain stakeholders when security findings involveexternal components or suppliers.
Improve visibility into what softwareactually ships— and how vulnerabilities areidentifiedand addressed over time.
Vulnerability Management & Incident Response
Support coordinated vulnerability disclosure and product security incident response.
Review vulnerability and penetration test reports, help calibrate severity, and guide remediation conversations.
Work collaboratively with engineering teams without owning their delivery backlogs.
Compliance & Regulatory Support
Support creation and maintenance of product security artifacts such as:
SBOMs
Threat models
Vulnerability evidence
Assistwith regulatory and customer assurance activities (e.g., EU CRA,ISO‑alignedrequirements) by providing technical insight and evidenceto avoidcompliancebottlenecks.
WhatWe’reLooking For
Core Qualifications
8+ yearsof experience in product security, application security, or security engineering with broad system exposure.
Strong understanding ofsecure product development lifecycles, threat modeling, and risk‑based decision‑making.
Experience working acrossmultiple products or platforms, not just a single codebase.
Practical experience reviewing security findings and collaborating on mitigation.
Solid foundation inmodern cryptography, key management concepts, and secure provisioning.
Comfort working inlarge GitHub‑based environmentswith CI/CD pipelines and automation.
Clear communicator who can explain security tradeoffs to engineers and non‑security partners.
Embedded Experience (Valued, Not Required)
Familiarity with embedded systems, firmware, or device security (secure boot, OTA, provisioning) is a plus.
Deep embedded specialization isnotrequiredifyou’recurious and willing to learn.
Nice to Have
Experienceoperatingor supportingshared security platforms(GHAS, KMS, PKI, signing services).
Exposure toconsumer electronics, automotive, or connected devices.
Experience supporting audits or regulatory reviews through technical evidence.
Comfort working on asmall, senior teamwith broad impact.
How We Work
We valuesound judgment over securitytheater.
Weoptimize forrisk reduction, consistency, and enablement, not finding the most bugs.
We make security decisions in aproduction environment, balancing risk, timelines, and real‑world constraints.
You’llbe trusted to work independently, collaborate openly, and raise concerns early.
WhyYou’llEnjoy This Role
Your work ships — and stays shipped.
You’llinfluence how security works acrossmany products, not just one.
You’llhelp protect not just code, but theentire chain of software and partnersbehind products people use every day.
You’llhelp safeguardexperiencespeople care about — music, sound, performance, and connection.
You’lljoin asmall, experienced teamwhere your perspective and judgment matter.
At Bose, you're inspired to be and do your best and are rewarded for your unique talents! Our compensation is thoughtfully tailored to your skills, experience, education, and location, and goes beyond base salary. The hiring range for this position in the primary work location of Framingham, Massachusetts is: $156,000-$214,500.The hiring range for other Bose work locations may vary.
In addition to competitive base pay we offer rewards including bonus programs, comprehensive health and welfare benefits, a 401(k) plan, plus exclusive perks designed to support your wellbeing, and a generous employee discount where you can immerse yourself in our products and experiences. We are a proudly independent company—driven by purpose, guided by our values, and united by a belief in the power of sound. As the world leader in audio experiences, we’re creating what’s next—pushing boundaries and delivering transformative sound experiences for people everywhere. Join us and make your next career move a mic-drop. Let’s Make Waves.
Bose is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status, or any other legally protected characteristics. The EEOC’s “Know Your Rights: Workplace discrimination is illegal” Poster is available here: https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf. Bose is committed to providing reasonable accommodations to individuals with disabilities. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to applicant_disability_accommodationrequest@bose.com. Please include "Application Accommodation Request" in the subject of the email.
Our goal is to create an atmosphere where every candidate feels supported and empowered in the interviewing process. Diversity and inclusion are integral to our success, and we believe that providing reasonable accommodation is not only a legal obligation but also a fundamental aspect of our commitment to being an employer of choice. We recognize that individuals may have different needs and requirements based on their abilities, and we provide reasonable accommodations to ensure ideal conditions are met during the application process.