Remote job
Senior Product Security Engineer (USA Only, 100% Remote)
Job details
About this role
Role overview A senior product security engineer is being hired as the first dedicated owner of product and application security at a 100% remote, US-based CRM company. Reporting into the Backend Platform team within Engineering, Product, and Design, the role spans the entire stack—from Python services and a TypeScript/React frontend to public APIs, Docker/Kubernetes on AWS, and integrations with sensitive-data providers. The focus is finding real vulnerabilities, prioritizing what matters, and driving fixes through to remediation, often hands-on.
Responsibilities - Analyze code, build proof-of-concepts, test running applications, and tune or replace noisy security tools. - Determine which findings matter most and drive them through remediation—either by fixing issues directly or by giving owning teams clear reproductions and practical paths forward. - Partner with the Infrastructure team on cloud security, access, secrets, and registry hygiene, turning findings into secure defaults and infrastructure guardrails. - Support audits and security assessments alongside the Security & Trust team, providing technical context and ensuring findings are fixed, not rediscovered. - Take a key technical role in security incident response, coordinating investigation, containment, and remediation across Engineering and Infrastructure. - Create documentation, paved roads, and lightweight training that helps engineers make safer choices without waiting on a review.
Requirements - Substantial experience with product or application security across a modern web stack (Python services, TypeScript/React frontends, REST and GraphQL APIs). - Comfort across browser behavior, frontend state, API authorization, asynchronous processing, data access, and third-party integrations. - Hands-on skills with infrastructure-adjacent security (Kubernetes on AWS, secrets, access patterns, container registries). - Ability to script, prototype, and write small amounts of code to automate vulnerability management and reduce toil. - Strong communication and judgment for triaging findings, influencing without direct authority, and partnering across teams. - Eligibility to work in the United States; this is a fully remote position.
Benefits and work setup - Competitive pay plus an organization-wide, goal-based bonus. - ~5 weeks of PTO to start, a 1-week all-company winter holiday break, and 2 extra days accrued per year of tenure. - Option to work a 4-day week at 80% pay (manager-approved) or a standard 5-day week. - Paid parental leave for primary and secondary caregivers, and a 1-month paid sabbatical every 5 years. - US healthcare: two medical plans with the company covering ~99% of premiums, plus dental, vision, HSA/FSA, and company-paid long-term disability. - 401(k) with up to 6% match, vested immediately.