Remote job
Product Security Engineer
Job details
About this role
Role overview
Help protect the security and privacy of users by strengthening application, product, cloud, and corporate security practices. This role combines vulnerability management, secure software development, threat modeling, code review, penetration-testing support, security automation, and close partnership with engineering, infrastructure, operations, and product teams.
Responsibilities
- Assess vulnerabilities in web and mobile applications, prioritize risk, and coordinate remediation with engineering teams. - Research emerging threats and recommend practical mitigations for evolving products and services. - Perform secure code reviews and help integrate security controls into agile delivery processes. - Support targeted penetration tests for new features and identify issues before production release. - Review controls for endpoint protection, device management, access management, cloud architecture, and general IT security hygiene. - Improve security posture through automation, IAM and access reviews, segmentation, centralized logging, detection, vulnerability management, and secure CI/CD or infrastructure-as-code controls.
Requirements
- Two to four years of product or application security experience, or one to three years in security-focused software engineering. - Practical experience with secure development, security architecture, vulnerability management, threat modeling, and secure code review. - Experience integrating security into agile product-development workflows. - Hands-on scripting experience, preferably with Python or Bash. - Ability to assess and execute projects independently in a fast-paced environment. - Strong written and verbal communication skills and the ability to work effectively with developers, product managers, and other stakeholders.
Nice to have
- Experience with high-growth companies, SaaS products, or healthcare technology. - Familiarity with AWS, GitLab CI/CD, Python web frameworks, PostgreSQL, Redis, Datadog, Sentry, Terraform, or Packer. - Software-engineering experience and exposure to cloud-native security practices.
Benefits and work setup
This is a fully remote U.S. role with required overlapping working hours; employees outside the Pacific time zone are expected to work at least six hours overlapping 8 a.m.–5 p.m. Pacific time. Employer sponsorship is not available. Listed base-salary ranges vary by U.S. location from $101,405–$140,400. Benefits may include health and insurance coverage, flexible time off, family-support programs, professional-development funding, retirement benefits, wellness and home-office stipends, and equity eligibility.