
Product Security Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Canada.
• Identify high-impact opportunities to enhance Fellow's security, establish practical strategies, and facilitate collaboration across teams.
• Build upon and refine existing security systems and practices as product developments, architecture, and threat landscapes evolve.
• Collaborate with engineering teams to conduct threat modeling for features, review designs, and mitigate risks prior to production.
• Conduct security-focused code reviews and provide guidance on authentication, authorization, data protection, input handling, secrets management, and business logic.
• Develop reusable security primitives, paved-road patterns, libraries, and platform controls.
• Introduce and enhance security tools including static analysis, dependency scanning, secret detection, infrastructure scanning, and CI/CD guardrails.
• Identify, prioritize, and drive the remediation of vulnerabilities identified through internal testing, automated tools, penetration tests, customer reports, and external researchers.
• Contribute to security incident response, investigation, containment, root-cause analysis, and post-incident fortification.
• Assist engineers in developing security acumen through practical guidance, shared learning, and collaboration.
• Assess the security implications of AI agents and AI-assisted development, and create tools, controls, and workflows for safe application at scale.
• Professional experience in product security, application security, software engineering, infrastructure security, or a combination of these fields.
• Strong skills in software engineering.
• Proficiency in at least one modern programming language, preferably Python.
• Experience in identifying and remediating application vulnerabilities related to authentication, authorization, injection, data exposure, secrets management, and business logic.
• Experience performing threat modeling, security design reviews, and security-focused code reviews for production software.
• Capability to write code, develop tools, and assist engineering teams in implementing sustainable solutions.
• Experience with SAST, SCA, DAST, secret scanning, cloud posture management, or infrastructure-as-code scanning.
• Familiarity with cloud infrastructure and security concepts, including IAM, networking, containers, Kubernetes, and infrastructure as code.
• Proven ability to take ambiguous and significant problems from investigation to implementation with measurable improvements.
• Ability to work with substantial ownership and set direction within the domain.
• Extensive, practical experience using AI coding agents such as Claude Code, Cursor, Codex, or similar tools.
• A history of developing agentic workflows, tools, or practices that significantly enhance software development.
• A curiosity for emerging threats and a commitment to ongoing learning.
• Nice to have: experience with penetration testing, offensive security, bug bounty programs, or engagement with external security researchers.
• Nice to have: experience securing AI-powered products, agentic systems, model integrations, or tools enabling AI systems to access data and take actions.
• Nice to have: participation in the security community through research, open-source contributions, writing, or public speaking.
• All employees receive stock options.
• Health and dental coverage, including prescription drug benefits and life insurance.
• 12 weeks of paid parental leave at 80% of salary.
• Three weeks of vacation.
• Paid sick leave.
• Paid company-wide break at the end of the year.
• Remote-first flexibility — Work remotely within Canada.
• Learning budgets.
• Lunch-and-learn sessions.
• Freedom to take ownership of your work from start to finish.
• Optional office space available in Ottawa, Montreal, and Toronto.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.