
Staff Application & Product Security Engineer
Posted Oct 2

Posted Oct 2
This is a fully remote position, open to applicants in United States.
• Take ownership of and enhance Cleo’s secure software development lifecycle, encompassing security requirements, threat modeling, and design evaluations.
• Execute and optimize SAST, SCA, secrets detection, container, and Infrastructure as Code (IaC) scanning.
• Develop reusable secure patterns, reference implementations, and policy-as-code controls.
• Lead developer security enablement initiatives through Security Champions, training sessions, remediation guidance, office hours, and self-service options.
• Manage risk-based triage, remediation, verification, SLAs, escalations, and exceptions concerning application and product vulnerabilities.
• Reproduce vulnerabilities reported externally and validate patches prior to release.
• Oversee and coordinate penetration-testing engagements and targeted assessments.
• Administer the Vulnerability Disclosure Program and facilitate communications and disclosures with researchers.
• Manage the CVE lifecycle and assist with product-security incident response.
• Direct application and product-security controls in Cleo’s NIST CSF 2.0 program, tracking maturity, addressing gaps, and generating audit evidence.
• Maintain the security posture of SaaS and customer-hosted products, which includes secure defaults, authentication, session controls, RBAC, tenant isolation, admin data access, configuration, and hardening guidance.
• Lead the Product Security Roadmap in collaboration with Product Management, the CTO, and Architecture.
• Prioritize and implement security features such as SSO/SAML upgrades, RBAC redesign, endpoint-level access control, and controls requested by customers.
• Represent security in RTE Sync and Boundary Review meetings.
• Assess customer vulnerability-scan findings and penetration-test reports.
• Respond to security RFIs and enhancement requests.
• Write customer-facing advisories, security release notes, and hardening documentation.
• Manage threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows.
• Create controls addressing prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply chain risks.
• Implement OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework across product and engineering.
• Report to the CISO and collaborate with the Engineering and Cloud Security teams.
• 6+ years of experience in application security, product security, or secure software engineering, with a background in building or enhancing an AppSec program across various engineering teams.
• Strong expertise in an object-oriented programming language; Java is preferred.
• Proficient in reading, debugging, and writing production-quality code.
• Comfortable working with TypeScript, Python, or Go.
• Extensive knowledge of authentication, authorization, API security, business-logic flaws, and contemporary service architectures.
• Practical experience in integrating and tuning SAST, SCA, and secrets scanning within GitHub and CI/CD pipelines.
• Hands-on experience in exploit reproduction and patch validation for running Java web applications.
• Experience in coordinated disclosure with external security researchers and clients, including driving a CVE to publication.
• Product security experience on deployed software with an established user base.
• Familiarity with conducting threat modeling, design reviews, and manual security assessments.
• Capability to work directly with developers during remediation efforts.
• Ability to translate technical risks into actionable engineering guidance for both developers and executives.
• Proficiency in making release-gating decisions in collaboration with Engineering leadership.
• Nice-to-have: experience securing LLM applications, AI agents, or AI-assisted development tools.
• Nice-to-have: knowledge of SBOM, CycloneDX/SPDX, VEX, artifact signing, and SLSA.
• Nice-to-have: familiarity with AWS, Kubernetes/EKS, Terraform, and Jenkins.
• Nice-to-have: experience with tools such as Snyk, GitHub Advanced Security, Semgrep, and Burp Suite.
• Nice-to-have: understanding of NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, and SOC 2 or ISO 27001 audits.
• Nice-to-have: relevant certifications such as CSSLP, OSWE, GWAPT, AWS Security, or equivalent.
• Nice-to-have: familiarity with SaaS and customer-hosted deployment models; SSO/SAML, RBAC design, multi-tenant isolation; MFT/EDI or other B2B integration products.
• Bonus Opportunity
• Excellent Healthcare + Dental + Vision
• Flexible PTO
• Supportive culture promoting Life-Work balance
• 401k matching
• FSA and HSA options available
• Employee Assistance Program
• Paid Parental Leave
• Remote work environment
• Opportunities for accelerated title and salary growth
• A fun and energetic work environment
Cummins Inc.
Tangible
GitLab
Tevora
Get handpicked remote jobs straight to your inbox weekly.