Product Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Product Security Engineer (AI): Securing ’s core software products through architecture reviews, threat modeling, vulnerability operations, and bug bounty triage with an accent on product security, distributed cloud environments, and AI-driven automation. Focus on designing LLM-enabled security tooling, validating complex vulnerabilities, coordinating remediation, and scaling findings management across engineering teams.
Location: Hybrid in Austin, Texas, United States; in-person interviews may be required at a office or hub. The role may require authorization to access technology controlled under U.S. export laws without sponsorship for an export license.
Company
operates a large-scale global network that protects and accelerates Internet applications for customers ranging from individual creators to Fortune 500 companies.
What you will do
- Build AI-driven tools and scripts using AI and LLMs to automate code analysis, triage, and security workflow operations.
- Conduct product security reviews and STRIDE-based threat modeling for new features and define security requirements early in development.
- Manage the vulnerability lifecycle, including verification, ownership routing, SLA tracking, and mitigation.
- Technically triage and validate external bug bounty submissions, assessing exploitability and business risk.
- Coordinate penetration testing activities, review findings, and support remediation planning.
- Collaborate with DevOps and product engineering teams on security risks and secure coding practices.
Requirements
- 5+ years of Product Security or Application Security experience in large-scale distributed cloud or SaaS environments.
- Hands-on experience building production-grade automation tools and applying AI/LLMs to operational or technical challenges.
- Experience with threat modeling, risk analysis, and evaluating the practical impact of code flaws.
- Experience managing software vulnerability routing and remediation across engineering teams against defined SLAs.
- Strong communication skills for explaining technical security risks and resolving ownership ambiguity with software engineers.
- Ability to work in a hybrid arrangement in Austin, United States, and meet applicable U.S. export-control authorization requirements.
Nice to have
- Familiarity with exploitation techniques, fuzzing frameworks, or automated scanning tools.
- Experience scaling crowdsourced security programs such as HackerOne or Bugcrowd.
- Experience optimizing agile project management workflows in JIRA.
- Experience integrating hardware security features into production codebases.
Culture & Benefits
- Mission-driven work focused on protecting and improving the open Internet.
- Medical, dental, vision, flexible spending, commuter, fertility, family-forming, and mental health benefits.
- Global travel medical insurance and disability, life, and accident coverage.
- 401(k) retirement savings and employee stock participation plans.
- Flexible paid time off and parental, pregnancy health, medical, and bereavement leave programs.
- Equity plan participation is available for this position.
Hiring process
- Applicants progressing to the offer stage may be asked to attend an in-person interview at a office or hub.
- Offers may be conditioned on authorization to receive software or technology controlled under U.S. export laws without sponsorship for an export license.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →