Overview
Senior Product Security Engineer for Endor Labs’ application security platform, owning application security end to end.
What you'll do
- Secure the application from code through artifact to runtime.
- Own software supply chain security across dependencies, binaries, containers, and build tools.
- Own first-party application security including code and container scanning.
- Harden AI agents by enforcing least-privilege access across MCP, credentials, filesystem, and network resources.
- Own and run the responsible disclosure program, including triage and review scaling.
- Partner with engineering on security design reviews and secure architecture definition.
What you'll need
- 5+ years of experience in application security or product security.
- At least 2 years of experience working with security implications of agentic software development.
- Strong experience with threat modeling and secure architecture design.
- Practical experience securing build systems and CI/CD pipelines at scale, with Bazel monorepos as a strong plus.
- Hands-on experience running penetration tests end-to-end and triaging responsible disclosure submissions.
- Ability to investigate, understand, and remediate security issues.
- Strong collaboration and communication skills with engineering and product teams.
Read the full description and apply on the company’s own careers page.