I was in security industry before I came to an engineering role before I came to a product based company. Product security is a different beast when compared to traditional service in security, product differs in a few ways. When you’re in product based role your threat modeling and analysis needs to be done by you. Apart from this product security testing needs a system level understanding that you’ll get when you end up engineering some products. Some skills that might help you go a long way in this industry is threat modeling and analysis, cross layer understanding of OSI, elinux and Linux internals, fuzzing, a little bit of programming (few things off of my head). Even for a tradition “pipe hitter” roles in security if you have these skills it’ll be helpful for you.