1 день назад
Senior/Staff Product Security Engineer
195 000 - 260 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior/Staff Product Security Engineer (Authentication, Authorization, and Applied Cryptography): Building and shipping security-critical identity, access-control, and data-protection systems for a financial platform with an accent on authentication architecture, delegated AI-agent access, and application-layer encryption. Focus on designing OAuth/OIDC and machine-to-machine flows, implementing key management and sensitive-data controls, and threat-modeling systems that protect member data.
Location: San Francisco, hybrid, with a balance of in-office and remote flexibility
Salary: $195K–$260K per year plus equity
Company
provides an integrated platform for self-employed people covering business incorporation, accounting, bookkeeping, tax services, and community access.
What you will do
- Own the end-to-end authentication and authorization architecture for the member platform, including sessions, multifactor authentication, authorization enforcement, and machine-to-machine authentication.
- Design and implement delegated and agent-based access with scoped, time-boxed, revocable authority and auditable attribution.
- Build application-layer encryption and sensitive-data protections, including key management, envelope encryption, rotation, tokenization, and log redaction.
- Lead RFCs and design reviews while collaborating with product engineers on security-critical changes.
- Threat-model identity and data-protection systems and remediate findings within the owned domain.
- Apply relevant regulatory requirements to encryption and access-control decisions.
Requirements
- 8+ years of software engineering experience, including production ownership of authentication, identity, authorization, or data-protection systems.
- Strong backend engineering skills with Python, Django, AWS, and modern web applications.
- Working knowledge of OAuth 2.0, token exchange and delegation, OIDC, SAML, JWT, session management, and machine-to-machine security.
- Practical applied-cryptography knowledge covering envelope encryption, KMS-based key management, key rotation, and encryption-layer tradeoffs.
- Ability to threat-model systems and work as a senior individual contributor through RFCs, design reviews, and production code.
- Ability to balance security rigor with member experience.
Culture & Benefits
- Hybrid work with in-office collaboration in San Francisco.
- Fresh lunch on in-office days and $150 monthly commuter support.
- $200 quarterly health and wellness reimbursement.
- Flexible PTO and 14 company holidays.
- 100% employee medical, dental, and vision coverage, with 75% dependent coverage.
- 16 weeks of fully paid parental leave, a 401(k) plan, equity, quarterly virtual events, and an annual in-person summit.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Cybersecurity Engineer (AI)
135 000 - 155 000$
2 дня назад
Senior Application Security Engineer (Web3)
140 000 - 200 000$
2 дня назад
Senior Security Engineer I, AI
163 944 - 215 176$
5 дней назад
Senior Application Security Engineer, AI and Machine Learning
180 000 - 220 000$
7 дней назад
Staff Product Security Engineer (AI/ML)
250 000 - 285 000$
4 дня назад
Senior Detection and Response Engineer (Cybersecurity)
120 000 - 190 000$