Staff Application & Product Security Engineer

New
C
CleoEnterprise software security
Remote USFull-TimeStaff
Salary$160,000 to $180,000 + Bonus Opportunity
Apply NowOpens the employer's application page

Job Details

Experience
6+ years in application security, product security, or secure software engineering
Required Skills
JavaCI/CDGitHub

Requirements

  • Have 6+ years in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams.
  • Have strong proficiency in an object-oriented programming language; Java is preferred. Be able to read, debug, and write production-quality code.
  • Bring deep knowledge of application attack surfaces, including authentication, authorization, API security, business-logic flaws, and modern service architectures.
  • Have hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines.
  • Be able to reproduce reported vulnerabilities against running applications, validate fixes, and communicate findings to researchers and customers.
  • Have coordinated disclosure experience with external security researchers and customers, including managing an embargo timeline and driving a CVE to publication.
  • Have product security experience with shipped software, including secure defaults, hardening guidance, customer advisories, and security release notes.
  • Have experience running threat modeling, design reviews, and manual security testing, and working directly with developers on remediation.
  • Be able to communicate technical risk as engineering guidance for developers and executives and hold release-gating decisions with Engineering leadership when warranted.

Responsibilities

  • Own and mature Cleo’s SSDLC, including security requirements, threat modeling, and design reviews for high-risk product changes, APIs, and integrations.
  • Run and tune SAST, SCA, secrets detection, container, and IaC scanning.
  • Build reusable secure patterns, reference implementations, and policy-as-code controls.
  • Lead developer security enablement through training, Security Champions, remediation guidance, office hours, and self-service capabilities.
  • Manage risk-based application and product vulnerability triage, remediation, verification, SLAs, escalation, and exceptions.
  • Own the penetration testing program, including third-party engagements, targeted testing, and retesting findings.
  • Run the Vulnerability Disclosure Program and coordinate researcher communications, disclosure, and the CVE lifecycle.
  • Own product security controls across SaaS and customer-hosted deployments and lead the Product Security Roadmap.
  • Triage customer security findings and requests, and produce security advisories, release notes, and hardening documentation.
  • Lead threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows.
View Full Description & ApplyYou'll be redirected to the employer's site
$160,000 to $180,000 + Bonus Opportunity
Apply Now