Remote job
Sr Product Security Engineer
Job details
About this role
Role overview
Senior Product Security Engineer focused on building and operating the security tooling pipeline that underpins an entire product security program. The role emphasizes designing automated review workflows with human-in-the-loop checkpoints so engineering teams receive fast, accurate security feedback on every commit, pull request, and release without manual review becoming a bottleneck.
Responsibilities
- Build and maintain the SDLC security tooling pipeline across repositories and CI/CD, integrating code scanning, secret scanning, dependency scanning, and cloud/container scanning tools. - Design automated product security review workflows with human-in-the-loop escalation for nuanced cases, using LLM platforms to handle initial triage, risk classification, and recommendation generation. - Tune rulesets, reduce false positives, and embed security gates cleanly into GitHub pull requests, CI/CD pipelines, IDE plugins, and developer dashboards so security interactions are clear and fast. - Build AI-first automation including code review triage, vulnerability pattern detection, fix suggestion generation, and policy-as-code enforcement, contributing reusable prompts, skills, and plugins to a shared library. - Support product incident response by helping investigate security issues, scoping impact, coordinating emergency fixes, and contributing to root cause analysis and post-incident improvements. - Partner with security testers, security architects, and engineering teams across the product portfolio to translate secure design standards into enforceable pipeline policies and validated findings.
Requirements
- Demonstrated experience operating a product security tooling pipeline integrated across the software development lifecycle. - An automation-first mindset with the ability to design human-in-the-loop review workflows that scale with engineering volume. - Hands-on experience integrating security tooling into developer workflows including GitHub pull requests, CI/CD pipelines, IDE plugins, and developer dashboards. - Track record of reducing false positives through ruleset tuning and building feedback loops that improve finding quality over time. - Experience using LLM-based platforms to automate triage, classification, and recommendation tasks in a security engineering context. - Strong collaboration skills for partnering with engineering, security testing, architecture, and technical program management counterparts.
Nice to have
- Experience with GitHub Advanced Security at scale, including CodeQL custom queries and secret scanning custom patterns. - Background operating cloud or container security scanning integrated into CI/CD pipelines. - Experience supporting product or security incident response and investigation. - Familiarity with policy-as-code frameworks such as OPA/Rego or Kyverno. - Background in securing endpoint technologies, identity systems, or enterprise security platforms. - Experience building developer enablement programs, security documentation, or self-service security tooling. - Cloud security experience across major providers and Kubernetes environments.