CareerPlanGet AI match score →

Product Security Engineer

Movable Ink - Remote (U.S. - EST)💼 Full-time💰 $170,000–$170,000🗓 2026-06-11 → 2026-07-31

Core

Securing codebases, CI/CD pipelines, and development practices to reduce risk without slowing down software delivery.

Role type

Product Security Engineer

Builds

Automation for vulnerability management and secure coding practices

Domain

Software Engineering / Application Security

Deliverable

production ML models | product features | infrastructure

Required skills

SAST, SCA, secrets scanning, CI/CD pipeline integration, vulnerability triage, secure coding guidelines, automation scripting

Preferred skills

Ruby, Python, JavaScript, Go

Technologies

Semgrep, Dependabot, Trufflehog, GitHub Actions, ZAP

Responsibilities

Implement and maintain static application security testing (SAST) using Semgrep; Configure and improve software composition analysis (SCA) tooling; Manage secrets detection scanning and respond to findings; Integrate security scanning into CI/CD pipelines; Triage and prioritize vulnerability findings; Support dynamic application security testing (DAST) efforts; Contribute to Application Security Posture Management (ASPM) platform; Set up and configure automation scripts; Document secure coding guidelines and educate developers; Evaluate and recommend new security tools

Seniority

Mid-level, hands-on IC

Rewrite
## Responsibilities - Implement and maintain static application security testing (SAST) using Semgrep across our repositories - Configure and improve software composition analysis (SCA) tooling (Dependabot) to identify vulnerable dependencies - Manage secrets detection scanning (Trufflehog) and respond to findings - Integrate security scanning into CI/CD pipelines (GitHub Actions) to catch issues before code is merged - Triage and prioritize vulnerability findings, working with engineering teams to drive remediation - Support dynamic application security testing (DAST) efforts using tools like ZAP - Contribute to our Application Security Posture Management (ASPM) platform to centralize findings and track remediation - Set up and configure automation scripts to support our vulnerability management practices - Document secure coding guidelines and help educate developers on security best practices - Evaluate and recommend new security tools as the landscape evolves ## Requirements - 2+ years of experience in application security, DevSecOps, or a security-focused software engineering role - Hands-on experience with SAST, SCA, or secrets scanning tools (Semgrep, Dependabot, Snyk, or similar) - Familiarity with CI/CD pipelines and GitHub Actions - Understanding of common web application vulnerabilities (OWASP Top 10) and how to detect/prevent them - Experience reading and reviewing code in at least one language (Ruby, Python, JavaScript, or Go preferred) - Comfortable navigating codebases and working with engineering teams to explain and prioritize security findings - Strong written communication skills for documentation and customer-facing security responses - Self-motivated and able to manage competing priorities in a fast-paced environment ## Nice to Have - None specified ## Benefits - The base pay range for this position is $170,000-$200,000/year, which can include additional bonus depending on the position ultimately offered, in addition to a full range of medical, financial, and/or other benefits. The base pay offered may vary depending on job-related knowledge, skills, and experience.
Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Greenhouse ↗