Application Product Security Engineer
New
J
JumpFinTech AI
Remote (US)Full-TimeMiddle
Salary$130,000–$170,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 2–4 years
- Required Skills
- PythonJavascriptTypeScriptCI/CD
Requirements
- 2–4 years of experience in application security, product security, or a software engineering role with significant security responsibilities.
- Solid grasp of common vulnerability classes (OWASP Top 10, authn/authz flaws, injection, SSRF) and how to prevent them in real codebases.
- Experience with threat modeling and secure design review.
- Hands-on incident response experience.
- Ability to read and write code (e.g., Python, TypeScript/JavaScript, Go, or similar) well enough to review PRs and build small tools.
- Strong communication and collaboration skills.
- Comfort with ambiguity and shifting priorities.
Responsibilities
- Partner with product and engineering teams during design and planning to identify risks early and build security into new features from the start.
- Lead threat modeling and secure design reviews for new products, features, and architecture changes.
- Perform security-focused code reviews and help engineers fix vulnerabilities.
- Build and maintain application security tooling (SAST, dependency scanning, secrets detection) integrated into CI/CD.
- Participate in incident response: triage, investigate, contain, and drive post-incident learning.
- Triage findings from bug bounty reports, pen tests, and vulnerability scans, and drive remediation with owning teams.
- Develop lightweight security guidance, paved-road patterns, and training that make the secure way the easy way.
- Wear multiple hats as needed — from customer security questionnaires to cloud and corporate security improvements.
View Full Description & ApplyYou'll be redirected to the employer's site