Senior Product Security Engineer
New
C
CloseCRM software
USA - RemoteFull-TimeSenior
SalaryCompetitive pay plus an organization-wide goal-based bonus
Apply NowOpens the employer's application page
Job Details
- Required Skills
- PythonTypeScript
Requirements
- Be an application security engineer who writes code and can investigate unfamiliar code paths, reproduce exploits, and propose or ship production-quality fixes.
- Have strong Python or TypeScript experience; experience across backend and frontend systems is useful.
- Find vulnerabilities that conventional scanners may miss, including issues involving authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business logic.
- Be able to threat-model designs, review code, and test running systems.
- Test like an attacker while protecting customer data and production systems; create safe reproductions and retest fixes.
- Have worked with some combination of SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling.
- Tune security tools, integrate them into engineering workflows, and reduce noise.
- Use coding agents and LLMs to accelerate investigation and engineering work, and verify their output.
- Assess severity and priority using reachability, existing controls, customer impact, and attack chains.
- Collaborate with product engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers, and follow findings through closure.
- Work independently in a remote environment and turn ambiguous security problems into practical plans with measurable progress.
Responsibilities
- Build a recurring product security review program through threat modeling, high-risk area audits, code review, and safe proof-of-concepts.
- Improve application security testing with static analysis, dependency and secrets scanning, and dynamic testing.
- Triage findings from HackerOne, scanners, penetration tests, audits, customers, and internal research; reproduce issues, assess impact, track remediation, and verify fixes.
- Automate security alert ingestion, deduplication, enrichment, prioritization, and routing.
- Improve dependency scanning and build workflows to assess upgrades, stage pull requests, run checks, and route remediation safely.
- Partner with service owners and Infrastructure to inventory application secrets and implement rotation paths, runbooks, and automation.
- Work with Infrastructure to improve AWS security detection, secure defaults, access patterns, guardrails, and remediation.
- Partner with Security & Trust on assessments and audits, technical context, documentation, and engineering training.
- Coordinate security incident investigation, containment, remediation, root-cause analysis, and follow-up improvements.
View Full Description & ApplyYou'll be redirected to the employer's site