Remote Senior Security Engineer, Product Security
Goodleap
- Remote job
About GoodLeap:
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Overview
GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.
GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.
Essential Job Duties and Responsibilities
- Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
- Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
- Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
- Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
- Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
- Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
- Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
- Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
- Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
- Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
- Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.
Required Skills, Knowledge, and Abilities
- You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your résumé.
- You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
- You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
- You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
- Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
- Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
- Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
- Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
- You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.
Preferred:
- Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
- Running structured vendor evaluations or proofs of concept
- Contributing to security policy or standards, including for AI systems
- Delivering security training or building hands-on learning environments
- Depth in cryptography and key management
- Detection engineering, incident response, or threat hunting exposure
- An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.
Compensation
In addition to the above salary, this role may be eligible for a bonus.
Additional Information
Additional Information Regarding Job Duties and Job Descriptions:
Job duties include additional responsibilities as assigned by one’s supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI .
Jobicy JobID: 153887- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around... ...the Manager of Product Security.Work Location: This is a remote position, open to candidates who reside in: San Francisco...Remote workSeniorFull timeWork experience placementWork at office
- ...best-in-class financing and software products for sustainable solutions, from... ...Position Overview GoodLeap’s security team safeguards the organization’s information... ..., and technology governance. As a Senior Product Security Engineer, you’ll partner with product and...Remote workSenior
$165k - $242k
...What You’ll Do:The Enterprise Security team at CoreWeave is... ...that actually make people more productive, this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll... ...segmentation, mTLS, ZTNA) in hybrid or remote-friendly environments....Remote workSeniorPermanent employmentFull timeTemporary workFor contractorsCasual workWork at officeFlexible hours$190.8k - $267.1k
...they care most about. Reddit is hiring a Senior Security Engineer, AI Security to help teams build and ship AI-powered products securely. This role combines product security... ..., tooling, or reusable patterns. #LI-Remote Pay Transparency: This job posting may...Remote workSeniorFor contractorsWork experience placement- ...vaccines, medical supplies, food, and retail products. Our customers include the world’s... ...breaking speeds.About You and The Role Product security at Zipline protects systems that... ...embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific...SeniorLocal area
- ...organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and... ...of this role As a Senior Security Engineer on GitLab’s Security Incident... ...world. All of our roles are remote, however some roles may carry...Remote workSeniorFull time
$105.4k - $124k
...multi-platform converged enterprise engineering solutions targeted to meet... ...scalability, and capacity. Evaluates product and service solutions. Basic... ...similar platformsExperience with remote access technologies, VPN solutions, and secure connectivity servicesUnderstanding...Remote workSeniorFull timeLocal area3 days per week- ...technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to... ...support Capital Markets, Treasury, Credit Risk, Product, and Engineering to conduct feedback loops on policy changes against the...SeniorFull time
$165k - $215k
...help us create it. Who you are Metropolis is seeking a highly technical, developer-oriented Senior Security Engineer to focus on securing our software engineering and product environments across web applications, mobile applications, APIs, AI/CV platforms, and cloud-native...SeniorTemporary workWork at officeLocal area- ...young, energetic global IT-Engineering services company with clients... ...forward to hearing from you! Senior Security Engineer, Network Security Pennsylvania - Remote 6 Months Pay rate: $70... ...environments. Develop production traffic migration and cutover...Remote workSeniorWork at officeLocal area
$160k - $215k
...Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure... ...our corporate office networks and remote access environments. Collaborating... ..., you'll join a team of world-class product leaders and engineers, building an ecosystem...Remote workSeniorTemporary workWork at officeLocal area$105.4k - $124k
...multi-platform converged enterprise engineering solutions targeted to meet... ...scalability, and capacity. Evaluates product and service solutions. Basic... ...platforms Experience with remote access technologies , VPN solutions, and secure connectivity services Understanding...Remote workSeniorFull timeTemporary workWork experience placementLocal area3 days per week$210k - $230k
...About the Role: We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network... ..., partnering with infrastructure and product teams to make high‑impact architectural... ...0/yr to $230,000/yr in Denver & most remote locations, $230,000/yr to $270,000/yr...Remote workSeniorFull timeWork at officeLocal area2 days per week3 days per week- ...Description Job Description Job title: Product Security PKI and Cloud Environment Architect \... ...\t5+ years of experience \tAny Engineering or computer science BS or BS information... ...PHONE CALLS \tShifts: 1ST \tOnsite/remote/hybrid: onsite \tInterview Information...Remote workContract workFor contractorsWork experience placementImmediate start
$116k - $162.5k
...better food accessible to everyone. THE OPPORTUNITYAs the Senior Engineer, IT Security Engineering, under minimal supervision, you will participate... ...office 4 days per week (with work from home on Friday). Remote work is not available for this role.WHAT YOU’LL DOEvangelize...Remote workSeniorWork at officeLocal areaWork from homeShift work- Join Hologic's mission to drive a Secure by Design culture within our Breast... ...Skeletal Health Connected Health products. As a Senior Product Security Engineer, you will play a pivotal role in ensuring... ..., CA, Marlborough, MA or can sit remotely. This is your chance to be part of...Remote workSenior
- Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services... ..., and the ideal candidate will be comfortable working remotely/work from home within the U.S. or from our...Remote workSeniorTemporary workWork at officeWork from homeFlexible hours
$200k - $250k
...popular and innovative financial products accessible to everyone. We... ...are around 180 people, fully remote, backed by a $150M Series C... .... Responsibilities Security is core to the product and the... ...crypto assets. As a Security Engineer, you will be responsible for...Remote workFull timeLive inWorldwideFlexible hours$184k - $245k
...exceptional people to create extraordinary experiences together. Bring your whole self. The Role and Team We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic systems, next-...SeniorTemporary workWork experience placementLocal area3 days per week$248k - $391k
...scale breakthroughs. As an Engineering Manager within our Infrastructure Security Engineering organization... ...a distributed team of senior security and... ...Security as an Internal Product: You have delivered security... ...SummaryLocation: US, CA, Remote; US, TX, Remote; US, CO,...Remote workSeniorFull time$220k - $292k
...monitoring the perimeter of secure areas, land or sea, for... ...by sensor data feeds. Our products leverage advanced sensor fusion... ...has to hold. We’re hiring a Senior Software Engineer to own product security for... ...measured boot, TPMs, or remote attestation.Experience with...Remote workSeniorFull timeWork experience placementLive inImmediate start$140.8k - $176k
...dreamers and builders in the world. We’re looking for a Senior Product Security Engineer who is passionate about partnering with engineers to... ...Compensation Range: ~$140,800 - $176,000 *This is a remote role JR: 2026-8010 #LI-Remote Why You’ll...Remote workSeniorLocal areaWorldwideFlexible hours$152.5k - $205k
...responsible for:Circle is seeking a hands-on and technically sharp Senior Security Engineer, Executive & Endpoint Security to contribute to Circle’s... ...for our most sensitive users and locations, including remote offices and other key company sites.This role has two important...Remote workSeniorContract workWork at officeLocal areaFlexible hours$200k - $250k
...innovative financial products accessible to everyone... ...around 180 people, fully remote, backed by a $150M... ...Capital and Paradigm. Security is core to Phantom’s... ...for strong security engineers with high agency who can... ...operating at a senior or staff level....Remote workContract workWorldwideFlexible hours- Senior Product Security Engineer This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is... ...values diverse perspectives, backgrounds, and experiences. Remote work opportunity within the United States. JobgetherRemote workSeniorFull timeContract work
$149.8k - $205.9k
...expertise across connectivity, AI, security and more, we’ll map a new... .... Role Summary The Product Security team develops and... ...protections in production. As a Senior IAM Engineer, you will own core... ...vehicle operations such as remote commands and OTA. You will drive...Remote workSeniorFull timeContract work- ...and make an impact. Join us! Seeking a highly technical, hands-on Senior Engineer with deep Systems Engineering expertise to lead AI security, platform modernization, and developer productivity initiatives across Digital Technology. The role will drive secure adoption...SeniorWork at officeFlexible hoursShift workDay shift
$140k - $190k
...nation’s vital interests. Title : Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP) Clearance :... ...that blocks something at two in the morning at a remote checkpoint does not inconvenience an employee at a desk...Remote workSeniorTemporary workImmediate startRelocation packageDay shift- ...Senior Cribl Engineer / Security Data Engineer Location: Charlotte, NC preferred. Candidates in New York City, Los Angeles, Southern California... ...may also be considered. Work Model: Flexible hybrid or remote Position Overview Seeking an experienced Senior Cribl...Remote workSeniorFull timeFlexible hours
$212k - $340k
...mission of Aurora’s OneTech Security Architect team is to... ...aspect of Aurora’s products; spanning software,... ...hardware, and services.As a Senior Staff Security Product... ...Security, System Engineering, and Product teams across... ...based employees (Full remote is not available for...Remote workSeniorWork at officeLocal areaFlexible hours3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Remote Senior Security Engineer, Product Security. Be the first to apply!
- information system security engineer Remote
- product security engineer Remote
- cloud security engineer Remote
- network security engineer Remote
- security software engineer Remote
- security engineer Remote
- IT security engineer Remote
- security engineering manager Remote
- aws cloud security engineer Remote
- senior security operations engineer Remote


