
Senior Product Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take ownership of the daily implementation of the product security program across cloud backend, mobile applications, and the Android platform.
• Manage the entire vulnerability management process, encompassing intake, triage, prioritization, and ensuring fixes are completed within remediation SLAs.
• Write and deploy security fixes directly in backend, mobile, and Android codebases.
• Lead and advance AI security scanning and verification, minimizing false positives, broadening repository coverage, and integrating it into continuous integration (CI) processes.
• Oversee the HackerOne bug bounty program, which includes report triage, validation of findings, collaboration with researchers, decisions on payouts, and management of vendor relationships.
• Administer third-party penetration testing engagements from initial scoping through to remediation.
• Direct security design reviews and threat modeling for new features and products, including those utilizing AI/LLM technology and handling children's data.
• Evaluate and provide guidance on device and firmware security initiatives.
• Supply metrics and data regarding findings, remediation efforts, and SLA compliance for reporting to compliance and leadership teams.
• Act as a subject matter expert during product security incidents.
• Collaborate closely with the Head of Security and provide hands-on security expertise to engineering teams.
• Minimum of 6 years in application or product security, coupled with a software engineering background.
• Capability to deliver production code, not just conduct reviews.
• Extensive experience in securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling.
• Proven experience in building and maintaining security tools and automation, incorporating static analysis, CI integrations, and custom scanners.
• Comfort with working on LLM-based systems.
• Practical experience in managing or triaging a bug bounty program.
• Demonstrated ability to influence engineering teams to prioritize and resolve security issues through sound judgment.
• Strong written communication skills with the ability to articulate risks to both technical and non-technical stakeholders.
• Experience in mobile application security (OWASP MASVS) [nice to have].
• Background in Android platform or application security [nice to have].
• Experience in assessing AI/LLM features for prompt injection and data leakage [nice to have].
• Familiarity with children's privacy regulations such as COPPA or other sensitive consumer data [nice to have].
• Exposure to embedded systems, IoT, or firmware security [nice to have].
• Knowledge of the EU Cyber Resilience Act or UK PSTI [nice to have].
• Experience in incident response [nice to have].
• Competitive Salary + Equity Package.
• 401K matching.
• Budgets for wellness, learning, and home-office expenses.
• Comprehensive Health, Dental & Vision Medical Plans.
• Significant autonomy in directing your work.
• Unlimited Paid Time Off (PTO).
• Company holidays on the first Friday of every month (with exceptions for November, December, and January).
• Paid time off.
Cloudiax
Cisco
Cisco
Sony Interactive Entertainment
Get handpicked remote jobs straight to your inbox weekly.