Product Security Engineer
Core
Build security into products and services by partnering with Engineering and Product teams throughout the development lifecycle to assess threats, identify vulnerabilities, and implement practical fixes.
Role type
Product Security Engineer (hands-on IC)
Builds
Secure application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations
Domain
Software security, cloud security, AI-enabled products
Deliverable
production ML models | product features
Required skills
Threat modeling, vulnerability validation, system architecture review, API security, cloud security, CI/CD pipeline security, automation scripting (Python/JavaScript), identity and access management, OWASP frameworks application
Preferred skills
AI/LLM security, multi-tenant application security, infrastructure-as-code scanning, emerging attack technique analysis
Technologies
SAST, DAST, dependency scanning, secret scanning, containers, serverless technologies, CI/CD pipelines
Responsibilities
Lead threat modeling and security design reviews; analyze application architecture and data flows to identify trust boundaries; validate vulnerabilities and prioritize risks; design remediation plans; own and improve security tooling (SAST, DAST, scanning); build automation for security workflows; establish secure design patterns and documentation; lead incident response and root cause analysis; explore emerging risks in cloud and AI-enabled products
Seniority
Mid-to-Senior, hands-on IC
