Staff Application & Product Security Engineer
New
C
CleoEnterprise software security
Remote USFull-TimeStaff
Salary$160,000 to $180,000 + Bonus Opportunity
Apply NowOpens the employer's application page
Job Details
- Experience
- 6+ years in application security, product security, or secure software engineering
- Required Skills
- JavaCI/CDGitHub
Requirements
- Have 6+ years in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams.
- Have strong proficiency in an object-oriented programming language; Java is preferred. Be able to read, debug, and write production-quality code.
- Bring deep knowledge of application attack surfaces, including authentication, authorization, API security, business-logic flaws, and modern service architectures.
- Have hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines.
- Be able to reproduce reported vulnerabilities against running applications, validate fixes, and communicate findings to researchers and customers.
- Have coordinated disclosure experience with external security researchers and customers, including managing an embargo timeline and driving a CVE to publication.
- Have product security experience with shipped software, including secure defaults, hardening guidance, customer advisories, and security release notes.
- Have experience running threat modeling, design reviews, and manual security testing, and working directly with developers on remediation.
- Be able to communicate technical risk as engineering guidance for developers and executives and hold release-gating decisions with Engineering leadership when warranted.
Responsibilities
- Own and mature Cleo’s SSDLC, including security requirements, threat modeling, and design reviews for high-risk product changes, APIs, and integrations.
- Run and tune SAST, SCA, secrets detection, container, and IaC scanning.
- Build reusable secure patterns, reference implementations, and policy-as-code controls.
- Lead developer security enablement through training, Security Champions, remediation guidance, office hours, and self-service capabilities.
- Manage risk-based application and product vulnerability triage, remediation, verification, SLAs, escalation, and exceptions.
- Own the penetration testing program, including third-party engagements, targeted testing, and retesting findings.
- Run the Vulnerability Disclosure Program and coordinate researcher communications, disclosure, and the CVE lifecycle.
- Own product security controls across SaaS and customer-hosted deployments and lead the Product Security Roadmap.
- Triage customer security findings and requests, and produce security advisories, release notes, and hardening documentation.
- Lead threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows.
View Full Description & ApplyYou'll be redirected to the employer's site