
Senior Product Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop a recurring product security review program that spans backend, frontend, APIs, and customer-facing integrations.
• Conduct threat modeling for new features, audit high-risk areas, review code, and create secure proof-of-concepts within isolated development environments.
• Enhance application security testing through static analysis, dependency and secrets scanning, dynamic testing, and targeted automation.
• Manage the intake and remediation of vulnerabilities reported from HackerOne, scanners, penetration tests, audits, customers, and internal research.
• Reproduce issues, evaluate exploitability and impact, monitor remediation efforts, and confirm fixes.
• Act as the technical lead for the bug bounty program.
• Automate the ingestion, deduplication, enrichment, prioritization, and routing of security alerts.
• Enhance dependency scanning and develop safer workflows for upgrades and pull requests.
• Maintain an inventory of application secrets, implement rotation paths, document runbooks, and automate rotation where feasible.
• Expand the use of Vault-backed dynamic credentials while minimizing emergency secret rotations.
• Collaborate with the Infrastructure team to bolster AWS security across identity, networking, compute, storage, containers, and registries.
• Establish secure defaults, implement just-in-time access patterns, create infrastructure guardrails, and provide actionable remediation strategies.
• Assist with external assessments, audits, SOC 2 objectives, documentation, paved roads, and engineering training.
• Play a crucial technical role in security incident response, which includes investigation, containment, remediation, root-cause analysis, and follow-up improvements.
• Report to the Backend Platform team manager within Engineering, Product, and Design, while collaborating across product and infrastructure domains.
• This is a USA-only position; candidates must be legally authorized to work in the US.
• An application security engineer who is proficient in coding and can transition from code analysis to exploit reproduction and production-quality fixes.
• Strong experience in Python or TypeScript; familiarity with both backend and frontend systems is beneficial.
• Capability to identify vulnerabilities that conventional scanners might overlook.
• Experience with authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business logic security.
• Skills in threat modeling designs, performing white-box code reviews, and testing live systems.
• Ability to approach testing from an attacker's perspective while safeguarding customer data and production systems.
• Familiarity with SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling.
• Proficiency in tuning security tools, integrating them into engineering workflows, and minimizing noise.
• Experience utilizing coding agents and LLMs while validating their outputs.
• Capability to evaluate exploitability, business impact, reachability, existing controls, and attack chains.
• Ability to collaborate effectively with product engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers.
• Self-directed work style suitable for a remote environment, with the ability to transform ambiguous security surfaces into actionable plans.
• Knowledge of Python, TypeScript, React, Flask, FastAPI, GraphQL, Docker, Kubernetes, AWS, Vault, GitHub Actions, MongoDB, PostgreSQL, Redis, Kafka, Elasticsearch, or similar security tools.
• Competitive salary along with an organization-wide performance-based bonus.
• Approximately 5 weeks of paid time off (PTO) from the start.
• A one-week all-company Winter Holiday Break.
• Paid public holidays in the US.
• Two additional PTO days for every year of service with Close.
• Option for a standard 5-day workweek or a 4-day workweek at 80% pay.
• Paid leave for both primary and secondary caregivers.
• A one-month paid sabbatical every five years with the team.
• Two medical plan options for US residents, with Close covering 99% of the premium.
• Dental insurance coverage.
• Vision insurance coverage.
• Health Savings Account (HSA).
• Flexible Spending Account (FSA).
• Company-paid Long-Term Disability insurance.
• 401(k) plan with a matching contribution of up to 6% for US residents, with immediate vesting.
• Annual in-person company team gatherings and offsite events.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.