Senior Security Engineer, Product Security
$146k - $169kGoodLeap
GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.
GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.
Essential Job Duties and Responsibilities
- Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
- Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
- Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
- Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
- Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
- Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
- Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
- Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
- Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
- Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
- Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.
Required Skills, Knowledge, and Abilities
- You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your résumé.
- You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
- You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
- You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
- Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
- Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
- Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
- Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
- You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.
- Preferred:
- Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
- Running structured vendor evaluations or proofs of concept
- Contributing to security policy or standards, including for AI systems
- Delivering security training or building hands-on learning environments
- Depth in cryptography and key management
- Detection engineering, incident response, or threat hunting exposure
- An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.
$146,000 - $169,000 a year
In addition to the above salary, this role may be eligible for a bonus.
- ...vaccines, medical supplies, food, and retail products. Our customers include the world’s... ...breaking speeds.About You and The Role Product security at Zipline protects systems that... ...embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific...SeniorLocal area
- ...technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to... ...support Capital Markets, Treasury, Credit Risk, Product, and Engineering to conduct feedback loops on policy changes against the...SeniorFull time
- ...Rippling is seeking a hands-on Staff Product Security Engineer in Seattle, WA to help build and scale its Product Security program. You’ll work with engineering teams to integrate security into the SDLC, conduct threat modeling, and perform code reviews for critical changes...Senior
- ...Google DeepMind is seeking a Senior Software Engineer, Product Security, to embed with product teams across GeminiApps and AI Studio, driving secure design and implementation from concept through production. You will perform security reviews, threat modeling, client...Senior
$160k - $250k
...breaches, and we’ve redefined modern security with the world’s most advanced AI-... ...securing our applications. CrowdStrike’s Product Security team breaks the mold of... ...threats to CrowdStrike’s products. As a Senior Application Security Engineer you will dig deep into web...SeniorRemote jobWork experience placementWork at officeLocal area- ...Role: Senior Engineer - AI Security, Systems Engineering & Developer Productivity Location: Charlotte, NC / Plano, TX (Onsite) Employment Type: Full-Time Experience: 10 15 years Must-Have Qualifications: Minimum 10 years of experience...SeniorFull time
- ...impact. Join us! Position Summary: Seeking a highly technical, hands‑on Senior Engineer with deep Systems Engineering expertise to lead AI security, platform modernization, and developer productivity initiatives across Digital Technology. The role will drive secure...SeniorWork at officeFlexible hoursShift workDay shift
- ...and Green Cards candidates only. Help Secure How AI Connects Into the Enterprise We are looking for a Senior Security Engineer with strong AppSec foundations and... ...Coordinate across Security, Engineering, Product, IAM, Cloud, and Architecture Drive issues...SeniorContract work
$174k - $252k
Identify security issues and implement and design security controls, tools, and services... ...complex security issues, guiding teams across Product Areas (PAs) to implement security... ...modeling.5 years of experience with security engineering, computer and network security and...Senior$296k - $395k
...currently Tuesday.About the RoleLambda Security protects some of the world's most valuable... ...protection with developer and employee productivity, we want to talk.We value diverse... ...understand your readiness for a Sr. Security Engineer role. Your application is not a waste...SeniorWork at officeLocal areaRemote workWork from homeFlexible hours$178.4k - $226.7k
...'s most customer-centric company!Amazon is looking for an AI Security Engineer with strong insight and passion for security to ensure our AI... ...applications. You will drive security strategy and influence product security roadmaps. You will review design and code for security...SeniorInternshipFlexible hours$178.4k - $226.7k
The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the...SeniorInternshipFlexible hours$178.4k - $226.7k
...build innovative services that protect our cloud from security threats.As a Senior Security Engineer (SecEng), you’ll help to build and manage services... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security...SeniorInternshipFlexible hours$167.5k - $226.3k
...summed up in our company values, which are reflected in our product and in our team.Our ValuesIf this sounds like you, you’ll... ...Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s...SeniorCasual workWork at officeLocal area$128.9k - $180k
...you can thrive, we can’t wait to meet you.WHAT YOU'LL DOAs a Senior Security Engineer on the Enterprise Security team, you'll protect Braze... ...infrastructure operating at the center of cloud operations, product, app security, and system architecture. That includes developing...SeniorWork at officeLocal area$165k - $242k
...Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for... ...experiences that actually make people more productive, this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship...SeniorPermanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$119.8k - $234.7k
...Individual ContributorTravel: Less than 25%Profession: Security EngineeringDiscipline: Penetration TestingCompany:... ...team is looking for learn-it-all security engineers that will help secure Microsoft Windows products and devices, with focus on offensive security and...SeniorOngoing contractWork at officeLocal areaWorldwide$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$232k - $290k
...opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest... ...and risk assessment of all AI integrations entering production, including LLM APIs, SaaS copilots, AI code editors, agentic...SeniorFull timeWork at officeLocal area$180k - $215k
...The Senior Security Engineer, AI Security is a hands-on technical expert responsible for designing, implementing, and continuously enhancing the... ...serve as a key security partner to Application Security, Product Development, Technology Architecture, Infrastructure, and AI...SeniorVisa sponsorshipWork visa- ...Discord is seeking a Senior Software Engineer for the Application Security team to protect user accounts. You will design and implement full‑stack security solutions... ...will guide engineers on secure design, work across product teams, and contribute to evolving platform defenses...SeniorRemote job
$210k - $234.1k
...few technology companies ever operate at.Security at Compass International HoldingsThe... ...estates in the industry. We are hands-on engineers who build security as a service: secure-... ...resource and subject matter expert for product and engineering teams, offering security...Minimum wageWork experience placementFlexible hours$200k - $255k
...status quo, we decided to fix it. National security professionals, journalists, parents, and... ..., you will collaborate with world-class engineers, architects, and visionaries, and work... ...Engineer with a specialization in product security to join our team. As a strategic...Odd jobImmediate start$268k - $321k
...Senior Security Engineer, Application Security Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-IPO... ...growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity...SeniorLocal area$178.4k - $226.7k
...Senior Security Engineer, AI & AGI Security Job ID: 10567905 | Amazon Web Services, Inc. Come join Earth's most customer-centric company... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the...SeniorInternshipFlexible hours$175k - $308.5k
...Senior Security Engineer - Security Assurance Scaling Seattle, Washington, United States Machine Learning and AI Apple Services Engineering... ...Engineer to partner with engineering teams working on new products and features. You will collaborate with developers, site...SeniorRelocation$105.4k - $124k
...develops multi-platform converged enterprise engineering solutions targeted to meet existing,... ..., scalability, and capacity. Evaluates product and service solutions. Basic QualificationsBachelor... ...access technologies, VPN solutions, and secure connectivity servicesUnderstanding of...SeniorFull timeLocal areaRemote work3 days per week- ...enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation... ...GitLab. An overview of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (...SeniorFull timeRemote work
$175k - $220k
...officeAbout the RoleWe are looking for a highly technical Senior Security Engineer who is passionate about protecting data across modern SaaS... ...Engineering, Privacy, Legal, and Business teams to securely enable productivity while maintaining strong data protection controls.Design...SeniorFull timeWork at office$269.17k - $326.06k
...shared experiences for everyone.The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards,... ...scalable security solutions.As a Senior Security Software Engineer - Application...SeniorFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer, Product Security. Be the first to apply!
- application security engineer United States
- principal security engineer United States
- senior cloud security engineer United States
- security operations engineer United States
- security engineer intern United States
- security support engineer United States
- associate security engineer United States
- azure security engineer United States
- junior security engineer United States
- cloud security engineer United States




