Senior Product Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of the daily implementation of the product security program across cloud backend, mobile applications, and the Android platform.

• Manage the entire vulnerability management process, encompassing intake, triage, prioritization, and ensuring fixes are completed within remediation SLAs.

• Write and deploy security fixes directly in backend, mobile, and Android codebases.

• Lead and advance AI security scanning and verification, minimizing false positives, broadening repository coverage, and integrating it into continuous integration (CI) processes.

• Oversee the HackerOne bug bounty program, which includes report triage, validation of findings, collaboration with researchers, decisions on payouts, and management of vendor relationships.

• Administer third-party penetration testing engagements from initial scoping through to remediation.

• Direct security design reviews and threat modeling for new features and products, including those utilizing AI/LLM technology and handling children's data.

• Evaluate and provide guidance on device and firmware security initiatives.

• Supply metrics and data regarding findings, remediation efforts, and SLA compliance for reporting to compliance and leadership teams.

• Act as a subject matter expert during product security incidents.

• Collaborate closely with the Head of Security and provide hands-on security expertise to engineering teams.


⛳️ Requirements

• Minimum of 6 years in application or product security, coupled with a software engineering background.

• Capability to deliver production code, not just conduct reviews.

• Extensive experience in securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling.

• Proven experience in building and maintaining security tools and automation, incorporating static analysis, CI integrations, and custom scanners.

• Comfort with working on LLM-based systems.

• Practical experience in managing or triaging a bug bounty program.

• Demonstrated ability to influence engineering teams to prioritize and resolve security issues through sound judgment.

• Strong written communication skills with the ability to articulate risks to both technical and non-technical stakeholders.

• Experience in mobile application security (OWASP MASVS) [nice to have].

• Background in Android platform or application security [nice to have].

• Experience in assessing AI/LLM features for prompt injection and data leakage [nice to have].

• Familiarity with children's privacy regulations such as COPPA or other sensitive consumer data [nice to have].

• Exposure to embedded systems, IoT, or firmware security [nice to have].

• Knowledge of the EU Cyber Resilience Act or UK PSTI [nice to have].

• Experience in incident response [nice to have].


🏝️ Benefits

• Competitive Salary + Equity Package.

• 401K matching.

• Budgets for wellness, learning, and home-office expenses.

• Comprehensive Health, Dental & Vision Medical Plans.

• Significant autonomy in directing your work.

• Unlimited Paid Time Off (PTO).

• Company holidays on the first Friday of every month (with exceptions for November, December, and January).

• Paid time off.

People also viewed

Cloudiax11 hours ago

Information Security, Compliance & IKS Manager – ISO 27001

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco14 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Cisco23 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j1 day ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers