Featured Job

Product Security Engineer

San Francisco Bay Area Full-time On-site 09/12/2026 Job ID: 000174
Apply Now
Product Security Application Security Engineering Python Go TypeScript

Summary

What you’ll impact

The role is the first dedicated product security engineer at the organization, responsible for owning and building the product security practice across the entire platform. You will design and implement security controls for authentication, authorization, multi‑tenant isolation, and the software supply chain while collaborating closely with engineering, infrastructure, and product teams.

Responsibilities

What you'll do

  • Work closely with engineering and infrastructure on how our systems get built and run, and with product on what gets built next.
  • Read the code, write the fix, and ship guardrails that engineers keep switched on because they are fast and mostly right.
  • Own product security end to end: authentication, authorization, multi-tenant isolation, APIs, and the data model behind them.
  • Threat model the agent platform. Define what an agent is allowed to do in a customer's systems, prove the boundary holds, and design what happens when an agent is asked to do something it should not.
  • Build the secure development lifecycle: design review, code review standards, and scanning in CI with a triage path engineers actually use.
  • Run application vulnerability management end to end. Find it, prioritize it by real exploitability rather than by scanner severity, get it fixed, verify the fix.
  • Set the security bar for AI-assisted code. A large share of our code is written with coding agents, and human ownership of what merges is not optional.
  • Secure the software supply chain: dependencies, build pipeline, artifacts, and third‑party integrations.
  • Own the engineering side of enterprise security reviews, penetration tests, and coordinated vulnerability disclosure, so customer scrutiny stops being a fire drill.
  • Extend the same controls to customer‑hosted and on‑prem deployments, where they have to hold up without our infrastructure around them.

Requirements

What you’ll bring

  • 5+ years in product or application security engineering, or a software engineer who moved into security and stayed hands‑on.
  • Strong coding skills in Python, Go, TypeScript, or similar. You review real code and write the fix yourself.
  • Real depth in authentication, authorization, and multi‑tenant isolation: OAuth and OIDC, RBAC, token and session handling, and the access‑control bugs that only show up between two features.
  • Web and API security depth across the OWASP Top 10 classes: injection, SSRF, deserialization, and broken access control, and how these actually get exploited rather than how they are listed.
  • Working familiarity with the OWASP Top 10 for Agentic Applications and the OWASP Top 10 for LLM Applications. Excessive agency and prompt injection are live concerns in our product today.
  • Threat modeling that produces engineering work with owners and dates, not a document.
  • Hands‑on with SAST, DAST, SCA, and secrets scanning in CI, including keeping the noise low enough that teams do not turn the checks off.
  • Judgment about risk. You can say what to fix now, what to accept, and why, to an audience that will push back.
  • Clear written and verbal communication with engineers, executives, and customers, including saying plainly what is still unknown.
  • Comfortable defining the structure while doing the work, in a company where requirements change week to week.

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.