18 дней назад
Product Security Engineer
136 500 - 187 660$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Engineer (Cloud Security/AI): Strengthening the security of a critical software delivery platform through threat modeling, cloud security posture management, and repeatable product security practices with an accent on CNAPP triage, SDLC tooling, and engineering partnership. Focus on designing scalable threat modeling processes, applying AI to security workflows, and identifying systemic fixes for cloud and application risks.
Location: Remote - US West
Salary: $116,000–$159,500, $122,800–$168,850, or $136,500–$187,660 annually, depending on US geographic zone
Company
provides a software delivery platform for controlled feature releases, experimentation, targeted experiences, and instant rollbacks.
What you will do
- Lead threat modeling engagements for higher-risk features and services.
- Help evolve product security from an on-request service into a repeatable practice with clear engagement criteria.
- Investigate, prioritize, route, and resolve CNAPP findings while identifying systemic security improvements.
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage.
- Partner with engineering and product teams on security reviews, guidance, and practical remediation paths.
- Apply AI to triage, threat modeling, code scanning, findings analysis, and security documentation.
Requirements
- 2–4 years of full-time experience in application security, product security, cloud security, or a related security-focused role.
- Experience participating in or leading threat modeling using STRIDE, attack trees, or an equivalent structured approach.
- Working knowledge of cloud security posture management and strong familiarity with OWASP Top 10, authentication, authorization, secrets management, and common cloud misconfigurations.
- Ability to read and critique pull requests in a modern technology stack and write small tools when useful.
- Hands-on experience applying AI tools to security or engineering work.
- Must be based in the United States; the role is remote in the US West region.
Nice to have
- Experience with developer tools, SaaS platforms, or feature management.
- Bug bounty triage experience with HackerOne or Bugcrowd.
- Familiarity with Go, Python, or TypeScript.
- Contributions to internal security tooling or open-source security projects.
Culture & Benefits
- Work on a small, high-leverage product security team with close collaboration across engineering, product, and security.
- Collaborative, respectful, humble, open, and inclusive working environment.
- Restricted stock units, health, vision, and dental insurance.
- Mental health benefits.
- Transparent geographic pay zones based on US location.
Hiring process
- Formal interview process required before an offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Secure Software Engineer (Application Security)
100 000 - 150 000$
3 дня назад
Product Security Engineer (AI)
231 900 - 318 250$
Affirm
4 дня назад
Staff Product Security Engineer (AI)
220 000 - 280 000$
3 дня назад
Senior Product Security Engineer
90 000 - 100 000GBP
Anthropic
8 дней назад
Staff+ Application Security Engineer (AI)
320 000 - 485 000$
3 дня назад
Product Security Engineer IV (AI)
140 000 - 151 000$