Senior Product Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Product Security Engineer (AI/security automation): Building AI-powered security agents, secure development controls, and automated protection across CI/CD pipelines with an accent on application security, vulnerability detection, and supply chain integrity. Focus on designing autonomous code review and adversarial testing systems, embedding secure-by-default practices, and solving complex security challenges without slowing engineering delivery.
Location: Remote within the United States or Canada. Candidates must be authorized to work in the US or Canada and should indicate whether visa sponsorship is required.
Company
is an AI-powered health platform using diagnostics, biomarker data, longitudinal insights, and software to support proactive healthcare.
What you will do
- Design and deploy AI-powered security agents for automated code review, risk classification, escalation, and auto-remediation.
- Build and operate security tooling across CI/CD pipelines, including SAST, SCA, secrets scanning, IaC validation, and supply chain integrity checks.
- Conduct threat modeling, secure design reviews, manual security assessments, and proactive vulnerability testing across applications, APIs, and infrastructure.
- Partner with engineering and product teams to embed security into design, development, testing, and deployment without becoming a delivery blocker.
- Roll out secure-by-default development frameworks, connect application telemetry to detection and response systems, and contribute to incident response and postmortems.
- Shape the long-term product security strategy and roadmap.
Requirements
- 5+ years of experience in product security, application security, software engineering, or a combination of these areas.
- Experience building or operating AI-assisted security tooling, automated triage pipelines, or custom security automation.
- Strong Python experience; familiarity with FastAPI, LangChain, or agentic frameworks is beneficial.
- Deep expertise in identifying and exploiting web, API, and application vulnerabilities beyond the OWASP Top 10.
- Experience embedding security controls into CI/CD pipelines and guiding engineers through secure design decisions.
- Authorization to work in the United States or Canada is required; visa sponsorship requirements must be disclosed.
Nice to have
- Experience with HIPAA or healthcare data.
- Red teaming experience.
- Security architecture experience at scale.
Culture & Benefits
- Flexible working hours and a collaborative, dynamic work environment.
- Competitive salary and benefits package.
- Strong emphasis on member-first outcomes, integrity, clear communication, and ownership.
- Commitment to diversity, inclusion, and equal employment opportunity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →