Staff Application & Product Security Engineer

Posted Oct 2

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of and enhance Cleo’s secure software development lifecycle, encompassing security requirements, threat modeling, and design evaluations.

• Execute and optimize SAST, SCA, secrets detection, container, and Infrastructure as Code (IaC) scanning.

• Develop reusable secure patterns, reference implementations, and policy-as-code controls.

• Lead developer security enablement initiatives through Security Champions, training sessions, remediation guidance, office hours, and self-service options.

• Manage risk-based triage, remediation, verification, SLAs, escalations, and exceptions concerning application and product vulnerabilities.

• Reproduce vulnerabilities reported externally and validate patches prior to release.

• Oversee and coordinate penetration-testing engagements and targeted assessments.

• Administer the Vulnerability Disclosure Program and facilitate communications and disclosures with researchers.

• Manage the CVE lifecycle and assist with product-security incident response.

• Direct application and product-security controls in Cleo’s NIST CSF 2.0 program, tracking maturity, addressing gaps, and generating audit evidence.

• Maintain the security posture of SaaS and customer-hosted products, which includes secure defaults, authentication, session controls, RBAC, tenant isolation, admin data access, configuration, and hardening guidance.

• Lead the Product Security Roadmap in collaboration with Product Management, the CTO, and Architecture.

• Prioritize and implement security features such as SSO/SAML upgrades, RBAC redesign, endpoint-level access control, and controls requested by customers.

• Represent security in RTE Sync and Boundary Review meetings.

• Assess customer vulnerability-scan findings and penetration-test reports.

• Respond to security RFIs and enhancement requests.

• Write customer-facing advisories, security release notes, and hardening documentation.

• Manage threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows.

• Create controls addressing prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply chain risks.

• Implement OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework across product and engineering.

• Report to the CISO and collaborate with the Engineering and Cloud Security teams.


⛳️ Requirements

• 6+ years of experience in application security, product security, or secure software engineering, with a background in building or enhancing an AppSec program across various engineering teams.

• Strong expertise in an object-oriented programming language; Java is preferred.

• Proficient in reading, debugging, and writing production-quality code.

• Comfortable working with TypeScript, Python, or Go.

• Extensive knowledge of authentication, authorization, API security, business-logic flaws, and contemporary service architectures.

• Practical experience in integrating and tuning SAST, SCA, and secrets scanning within GitHub and CI/CD pipelines.

• Hands-on experience in exploit reproduction and patch validation for running Java web applications.

• Experience in coordinated disclosure with external security researchers and clients, including driving a CVE to publication.

• Product security experience on deployed software with an established user base.

• Familiarity with conducting threat modeling, design reviews, and manual security assessments.

• Capability to work directly with developers during remediation efforts.

• Ability to translate technical risks into actionable engineering guidance for both developers and executives.

• Proficiency in making release-gating decisions in collaboration with Engineering leadership.

• Nice-to-have: experience securing LLM applications, AI agents, or AI-assisted development tools.

• Nice-to-have: knowledge of SBOM, CycloneDX/SPDX, VEX, artifact signing, and SLSA.

• Nice-to-have: familiarity with AWS, Kubernetes/EKS, Terraform, and Jenkins.

• Nice-to-have: experience with tools such as Snyk, GitHub Advanced Security, Semgrep, and Burp Suite.

• Nice-to-have: understanding of NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, and SOC 2 or ISO 27001 audits.

• Nice-to-have: relevant certifications such as CSSLP, OSWE, GWAPT, AWS Security, or equivalent.

• Nice-to-have: familiarity with SaaS and customer-hosted deployment models; SSO/SAML, RBAC design, multi-tenant isolation; MFT/EDI or other B2B integration products.


🏝️ Benefits

• Bonus Opportunity

• Excellent Healthcare + Dental + Vision

• Flexible PTO

• Supportive culture promoting Life-Work balance

• 401k matching

• FSA and HSA options available

• Employee Assistance Program

• Paid Parental Leave

• Remote work environment

• Opportunities for accelerated title and salary growth

• A fun and energetic work environment

People also viewed

Cummins Inc.14 hours ago

Cybersecurity Director

US flagAlabama, +45 more statesFull-timeCybersecurity / Security Engineer$180.6k – $265k/year
ApplyView job
Tangible14 hours ago

Information Security Engineer – CISO Track

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GitLab14 hours ago

Staff Software Engineer, Security Factory – Static Analysis

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$152.8k – $259.2k/year
ApplyView job
Tevora14 hours ago

Senior Director – Cybersecurity Transformation, AI Security

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$190k – $225k/year
ApplyView job
Delinea16 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$170k – $200k/year
ApplyView job
OptiMantra16 hours ago

Lead Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers