
Senior Security Engineer – Product & Infrastructure
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in North America.
• Take ownership of product and infrastructure security across various Squads.
• Act as the security reviewer during product and engineering discussions.
• Lead the threat modeling process and conduct security design evaluations for products, features, and infrastructure modifications.
• Execute secure code assessments across backend services, APIs, frontends, and Solana programs.
• Concentrate reviews on aspects such as authentication, authorization, and access control.
• Manage the lifecycle of findings from audits, penetration tests, code scans, and bug bounty programs.
• Triage, prioritize, monitor remediation efforts, and verify fixes.
• Establish severity and SLA standards and ensure compliance.
• Oversee bug bounty intake and validate external reports against the source.
• Collaborate with audit partners and define the scope for internal assessments.
• Optimize and expand SAST, dependency, secrets, and container scanning within CI/CD pipelines.
• Review IAM, network controls, encryption, and secrets management across cloud environments.
• Evaluate access for internal AI tools, MCP integrations, and agents operating in production.
• Develop product security standards, review checklists, and provide guidance for developers.
• Over 8 years of experience in product security, application security, or security engineering, grounded in a software engineering background.
• Proven ownership of threat modeling and architectural reviews for intricate financial or distributed systems.
• A history of identifying critical, non-obvious vulnerabilities within extensive production codebases.
• Proficiency in TypeScript, Rust, Go, or Python.
• Familiarity with LLM and agent-based review workflows.
• Experience in creating and managing a vulnerability management program or executing a bug bounty process from start to finish.
• Knowledge of CI/CD scanning methodologies.
• In-depth expertise in IAM, secrets management, network controls, and container security on AWS or an equivalent provider.
• Excellent written communication skills and the ability to work autonomously.
• Experience with reviewing Solana programs (Rust/Anchor), working at an audit firm, cryptography and key management (HSMs, MPC, PKI), conducting offensive testing across web and mobile platforms, red teaming AI systems, or supporting SOC 2 from the product perspective is advantageous.
• Equity
• Remote work opportunities in North America or Europe
NVIDIA
Soteria - Security Solutions & Advisory
BMO U.S.
Abnormal Security
Get handpicked remote jobs straight to your inbox weekly.