Назад
Company hidden
18 дней назад

Product Security Engineer

136 500 - 187 660$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (Cloud Security/AI): Strengthening the security of a critical software delivery platform through threat modeling, cloud security posture management, and repeatable product security practices with an accent on CNAPP triage, SDLC tooling, and engineering partnership. Focus on designing scalable threat modeling processes, applying AI to security workflows, and identifying systemic fixes for cloud and application risks.

Location: Remote - US West

Salary: $116,000–$159,500, $122,800–$168,850, or $136,500–$187,660 annually, depending on US geographic zone

Company

hirify.global provides a software delivery platform for controlled feature releases, experimentation, targeted experiences, and instant rollbacks.

What you will do

  • Lead threat modeling engagements for higher-risk features and services.
  • Help evolve product security from an on-request service into a repeatable practice with clear engagement criteria.
  • Investigate, prioritize, route, and resolve CNAPP findings while identifying systemic security improvements.
  • Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage.
  • Partner with engineering and product teams on security reviews, guidance, and practical remediation paths.
  • Apply AI to triage, threat modeling, code scanning, findings analysis, and security documentation.

Requirements

  • 2–4 years of full-time experience in application security, product security, cloud security, or a related security-focused role.
  • Experience participating in or leading threat modeling using STRIDE, attack trees, or an equivalent structured approach.
  • Working knowledge of cloud security posture management and strong familiarity with OWASP Top 10, authentication, authorization, secrets management, and common cloud misconfigurations.
  • Ability to read and critique pull requests in a modern technology stack and write small tools when useful.
  • Hands-on experience applying AI tools to security or engineering work.
  • Must be based in the United States; the role is remote in the US West region.

Nice to have

  • Experience with developer tools, SaaS platforms, or feature management.
  • Bug bounty triage experience with HackerOne or Bugcrowd.
  • Familiarity with Go, Python, or TypeScript.
  • Contributions to internal security tooling or open-source security projects.

Culture & Benefits

  • Work on a small, high-leverage product security team with close collaboration across engineering, product, and security.
  • Collaborative, respectful, humble, open, and inclusive working environment.
  • Restricted stock units, health, vision, and dental insurance.
  • Mental health benefits.
  • Transparent geographic pay zones based on US location.

Hiring process

  • Formal interview process required before an offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →