Senior Product Security Engineer

New
C
CloseCRM software
USA - RemoteFull-TimeSenior
SalaryCompetitive pay plus an organization-wide goal-based bonus
Apply NowOpens the employer's application page

Job Details

Required Skills
PythonTypeScript

Requirements

  • Be an application security engineer who writes code and can investigate unfamiliar code paths, reproduce exploits, and propose or ship production-quality fixes.
  • Have strong Python or TypeScript experience; experience across backend and frontend systems is useful.
  • Find vulnerabilities that conventional scanners may miss, including issues involving authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business logic.
  • Be able to threat-model designs, review code, and test running systems.
  • Test like an attacker while protecting customer data and production systems; create safe reproductions and retest fixes.
  • Have worked with some combination of SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling.
  • Tune security tools, integrate them into engineering workflows, and reduce noise.
  • Use coding agents and LLMs to accelerate investigation and engineering work, and verify their output.
  • Assess severity and priority using reachability, existing controls, customer impact, and attack chains.
  • Collaborate with product engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers, and follow findings through closure.
  • Work independently in a remote environment and turn ambiguous security problems into practical plans with measurable progress.

Responsibilities

  • Build a recurring product security review program through threat modeling, high-risk area audits, code review, and safe proof-of-concepts.
  • Improve application security testing with static analysis, dependency and secrets scanning, and dynamic testing.
  • Triage findings from HackerOne, scanners, penetration tests, audits, customers, and internal research; reproduce issues, assess impact, track remediation, and verify fixes.
  • Automate security alert ingestion, deduplication, enrichment, prioritization, and routing.
  • Improve dependency scanning and build workflows to assess upgrades, stage pull requests, run checks, and route remediation safely.
  • Partner with service owners and Infrastructure to inventory application secrets and implement rotation paths, runbooks, and automation.
  • Work with Infrastructure to improve AWS security detection, secure defaults, access patterns, guardrails, and remediation.
  • Partner with Security & Trust on assessments and audits, technical context, documentation, and engineering training.
  • Coordinate security incident investigation, containment, remediation, root-cause analysis, and follow-up improvements.
View Full Description & ApplyYou'll be redirected to the employer's site
Competitive pay plus an organization-wide goal-based bonus
Apply Now