Remote job
Product Security
Job details
About this role
Role overview
A Product Security Engineer position focused on embedding security into engineering workflows and scaling product and cloud security practices across a fast-growing organization. The role partners closely with engineering teams on architecture reviews, threat modeling, secure design, and the maintenance of first- and third-party security tooling in an environment where AI-assisted development is accelerating. It combines hands-on execution with enablement work—mentoring engineers, producing practical documentation, and reporting risk and progress to security leadership.
Responsibilities
- Partner with product and engineering teams on architecture reviews, threat modeling, and secure design, translating complex risks into practical recommendations with clear tradeoffs. - Evaluate and roll out AI-assisted and agentic security workflows to expand coverage and accelerate reviews, triage, and remediation, with appropriate validation and human oversight. - Improve and maintain security tooling, including an in-house ASPM platform, to reduce noise, sharpen prioritization, and make findings actionable for engineering teams. - Strengthen controls throughout the SDLC and CI/CD pipeline, including code and dependency scanning, software supply chain protections, and safeguards for AI-assisted development. - Serve as a GCP security subject matter expert, advising on secure patterns for networking, data protection, secrets management, workload runtimes, and logging and monitoring. - Drive vulnerability management from triage through resolution, coordinate penetration testing engagements, and help shape and scale the product security program with clear reporting to security leadership.
Requirements
- 5–7 years of experience in product security, cloud security engineering, software development, or a closely related field. - Practical experience applying AI and agentic workflows to accelerate security reviews, vulnerability triage, and remediation, with a strong grasp of risks tied to AI-assisted development. - Strong knowledge of Google Cloud Platform (GCP) services and security best practices, including IAM, networking, data protection, and workload runtimes. - Hands-on experience with penetration testing coordination, threat modeling, and risk assessment. - Proficiency in Python and cloud-native scripting languages to design security automation, policy enforcement, and continuous compliance controls using Infrastructure as Code. - Familiarity with designing and enforcing least-privilege IAM, conducting access reviews, and communicating security risks clearly to engineering and leadership audiences.
Benefits and work setup
- Base salary range of $175,000–$200,000 USD, with Canadian compensation aligned to local bands and varying by location. - Meaningful equity participation in the company. - Remote-first culture with flexibility; open remotely across the U.S. and Canada, or hybrid from offices in New York, San Francisco, or Toronto. - Quarterly offsites and frequent opportunities to travel to company offices. - Flexible PTO, comprehensive health benefits, and parental leave.