
Senior Security Engineer, Product Security
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in United States.
• Conduct adversarial testing on AI- and LLM-driven features, focusing on prompt injection, jailbreaks, tool misuse, and data exfiltration.
• Develop and manage production security services and internal tools utilizing TypeScript, Node.js, .NET, or Python.
• Discover opportunities to automate manual security tasks and prototype enhanced solutions.
• Review and assess pull-request vulnerability findings, investigate authentication pathways and high-risk modifications, and enhance security tools.
• Perform threat modeling on product specifications and technical designs by recognizing trust boundaries, data flows, and security inquiries.
• Execute manual testing of web applications and APIs, evaluate exploitability, verify fixes, and assist with bug bounty and penetration testing initiatives.
• Manage and optimize AppSec tools, including SAST/dependency scanning, finding triage and routing, SSO, and access management.
• Fortify tooling infrastructure through least-privilege IAM, secrets management, container/network lifecycle management, infrastructure as code, and drift checks.
• Develop practical security training and documentation tailored for engineers.
• Assess security products through organized bake-offs and contribute to defining AI/agent production standards.
• Assist with investigations, threat hunting, incident response, vulnerability management, and security analytics.
• Proficient in backend engineering with at least one modern programming language.
• Experience in building at least one production service that is relied upon by others.
• Familiarity with asynchronous patterns, HTTP APIs, and streaming transports.
• Capability to read and understand code in multiple languages and technology stacks.
• Knowledge of identity and authorization vulnerabilities, including token exchange, scope management, session lifetime and revocation, request signing, OAuth challenges, SSRF, and DNS rebinding.
• Practical understanding of REST and GraphQL, OpenAPI, schema contracts, input validation, rate limiting, gateway-level authentication, and webhook/service-to-service verification.
• Hands-on experience with manual testing of web applications and APIs.
• Ability to conduct threat modeling based on written product and technical specifications.
• Proficient in AWS and infrastructure-as-code practices, including IAM, secrets management, containers/compute, network egress control, and drift checks.
• Practical exposure to AI/LLM security through professional experience, CTF participation, published research, or personal projects.
• Strong written and verbal communication skills for interaction with engineers, product managers, executives, and legal teams.
• Preferred: Experience in AppSec tooling management, vendor assessments, security policy or AI standards, security training, cryptography and key management, detection engineering, incident response, threat hunting, understanding of SaaS product development, or experience in product/engineering management.
• Eligibility for salary bonuses.
• Reasonable accommodations for known disabilities as mandated by law.
FRSecure
Synack, Inc.
Coinbase
6sense
Get handpicked remote jobs straight to your inbox weekly.