Staff Product Security Engineer
New
P
PhantomFinancial Technology
This role is fully remote and open to candidates based in the US, UK and Canada.Full-TimeStaff
Salary$200,000 to $250,000 with the addition of equity and benefits
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of experience
- Required Skills
- PythonJavascriptTypeScriptGoRust
Requirements
- 5+ years of experience in product security, application security, or security engineering.
- Proven experience operating at a senior or staff level.
- Strong understanding of web, mobile, API, and distributed-system security principles.
- Deep knowledge of authentication, authorization, session management, cryptography, and vulnerability classes.
- Hands-on experience building or applying AI-assisted security tooling for applications and APIs.
- Ability to review production code in TypeScript, JavaScript, Rust, Python, or Go.
- Experience securing software supply chains and CI/CD infrastructure, including secrets and build provenance.
- Experience performing threat modeling for complex products.
- Demonstrated ability to translate security risks into actionable engineering requirements.
- Strong judgment in evaluating exploitability and business impact.
- Effective communication skills for both technical and non-technical stakeholders.
Responsibilities
- Partner with engineering teams to identify and address security risks across Phantom’s mobile applications, web products, APIs, and backend services.
- Lead security reviews for new products and major architectural changes, focusing on authorization, transaction integrity, and sensitive data.
- Embed practical security controls into the software development lifecycle from design through production.
- Perform AI-assisted security code reviews and target testing of high-risk features to identify vulnerabilities.
- Develop tooling to provide engineers with fast, actionable security feedback and build automated workflows.
- Harden CI/CD and release systems against supply chain threats and dependency risks.
- Triage and drive remediation for findings from internal testing, bug bounty programs, and third-party assessments.
- Support incident response investigations and transform findings into durable architectural improvements.
View Full Description & ApplyYou'll be redirected to the employer's site