Staff Security Engineer, Product Security team
Core
Drive the overarching technical strategy for application security, designing automated guardrails, developer tooling, and technical frameworks to enable secure scaling of global web and mobile applications.
Role type
Staff-level individual contributor (IC4) Product Security Engineer
Builds
Automated security guardrails, DevSecOps workflows, AI-powered security automation, and secure architectural blueprints for a global delivery platform.
Domain
Application Security, AI/ML Security, Cloud Security, DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
Application security strategy, Threat modeling, Vulnerability management, DevSecOps automation, AI/LLM security frameworks, Secure coding (Java, Python, Go), Cloud security (AWS/GCP/Azure), IAM/Zero Trust, Stakeholder management
Preferred skills
Microservices security, Public security research/CVE discovery, Open-source security contributions, Advanced security certifications (CSSLP, CISSP, etc.)
Technologies
SAST, DAST, SCA, Kubernetes, Docker, AWS, GCP, Azure, OAuth, OIDC, SAML, OWASP Top 10 for LLM, MITRE ATLAS, NIST AI RMF
Responsibilities
Drive strategic technical roadmap for Product Security, Lead threat modeling and security architecture reviews, Scale vulnerability management and governance programs, Automate DevSecOps & CI/CD pipelines, Pioneer AI-driven security automation, Mentor and inspire engineering teams
Seniority
Staff, hands-on IC with domain-wide impact