Overview
Product Security Engineer role focused on building security into products and services across the development lifecycle.
What you'll do
- Use threat modeling and security design reviews to find issues before production.
- Review application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations for attack paths.
- Identify and validate vulnerabilities, separate real risk from noise, and help teams prioritize.
- Work with engineers to design and remediate plans that protect customers.
- Own and improve security tooling across the lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
- Build automation for security as products and engineering teams (and AI usage) grow.
What you'll need
- Experience in product security, application security, software engineering, penetration testing, or similar.
- Ability to follow data, identify trust boundaries, and understand real risks in complex systems.
- Knowledge of threat modeling, architecture review, and application assessment beyond checklists.
- Comfort validating vulnerabilities and explaining why they matter to engineers and business leaders.
- Experience with APIs, cloud services, containers, serverless technologies, and CI/CD pipelines.
- Hands-on experience with security tools such as SAST, DAST, dependency scanning, secret scanning, or IaC scanning.
- Ability to read and write code and automate security work using Python, JavaScript, or similar.
Details
- Remote-friendly role that can sit in NYC, an office hub, or anywhere in the US.
- Most employees work East Coast hours; work hours are flexible.
Read the full description and apply on the company’s own careers page.