Lead Product Security Engineer (AI)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠΎΠΊΠ°ΠΆΠ΅Ρ Π²Π°ΡΡ ΡΠΎΠ²ΠΌΠ΅ΡΡΠΈΠΌΠΎΡΡΡ ΠΈ Π½Π°ΠΏΠΈΡΠ΅Ρ ΠΏΠΈΡΡΠΌΠΎ
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Lead Product Security Engineer (AI): Setting the technical direction and prioritization for a Product Security team, covering multiple product lines, with an accent on threat modeling, secure code reviews, and vulnerability mitigation. Focus on collaborating with product engineering teams, implementing end-to-end security solutions, and experimenting with AI-based tools to enhance security measures.
Location: Dynamic hybrid working model
Salary: $300,000 β $400,000/year (USD)
Company
is the trusted AI assistant for communication and productivity, helping over 40 million people and 50,000 organizations do their best work.
What you will do
- Set the technical direction and prioritization for a Product Security team covering three separate product lines.
- Collaborate with Product Engineering teams throughout the SDLC, creating Threat Models and conducting Design Reviews.
- Develop and implement end-to-end security solutions to mitigate security risks in our suite of products.
- Help drive improvements across our Product Security tooling, automation, and bug bounty program.
- Experiment with and develop AI-based tools to enable the Security team to move even faster.
- Engage with stakeholders across engineering teams, communicating security risks and trade-offs while keeping customer data secure.
Requirements
- Has 7+ years of relevant experience in securing applications at scale.
- Experience working at each touch-point in a secure SDLC: threat modeling, design reviews, secure code reviews, and web app pentesting.
- Familiarity with the standard Product Security tool suite: SAST, DAST, and SCA.
- Software engineering or programming experience in at least one language, such as Java, Python, JavaScript, or Go.
- Experience managing vulnerability disclosure programs or conducting security research on bug bounty platforms such as HackerOne or Bugcrowd.
- The ability to think like an adversary to identify risk, and then build like an engineer to mitigate those risks.
Culture & Benefits
- Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits).
- 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and flexible sick time.
- Generous stipends (including those for caregiving, pet care, wellness, your home office, and more).
- Annual professional development budget and opportunities.
- Disability and life insurance options.
- 401(k) and RRSP matching.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ Π²Π°Ρ ΠΏΡΠΎΡΡΡ Π²ΠΎΠΉΡΠΈ Π² iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β