Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Product Security Engineer (USA Only, 100% Remote)

Jobleads-US

Kentucky
  • Remote job

About Us
Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication‑first, AI‑powered sales software designed to help you succeed and scale.


We're bootstrapped and profitable which means we answer to our customers and play by our rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can’t figure out sales.

About the Role

Close is a CRM built around the communication tools sales teams use every day: email, calling, SMS, workflows, reporting, and AI. Underneath that product is a broad technical surface — Python services and a large application backend, a TypeScript and React frontend, public APIs, Docker and Kubernetes, AWS infrastructure, and integrations with providers that handle sensitive customer data.

Security work happens across it all today, but the ownership is spread across Engineering, Infrastructure, and Security & Trust. We’re hiring our first dedicated Product Security Engineer to make that work systematic. You’ll report to the Backend Platform team manager within EPD (Engineering, Product, and Design), while working across the entire product and infrastructure surface. You’ll find vulnerabilities, determine which findings matter most, and drive them through remediation. Often you’ll fix the problem yourself. Other times you’ll give the owning team a clear reproduction, a practical path forward, and enough context to prioritize correctly.

You’ll analyze code, build proof‑of‑concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management. This is not a role where you forward scanner alerts and call the queue managed. Product and application security will be your responsibility. You’ll partner closely with our Infrastructure team on cloud security, access, and secrets, and with our Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.

This role is a new one at Close. You’ll have significant room to decide where better tooling, clearer ownership, and a small amount of code can reduce the most risk.

Our stack

Our backend is primarily Python, with Flask and FastAPI services and TaskTiger and Temporal handling much of our asynchronous work. We expose REST and GraphQL APIs and store data in MongoDB, PostgreSQL, Elasticsearch, and Redis.

Our frontend is a large single‑page TypeScript application built primarily with React. We bundle with Vite, target modern browsers, and test with Vitest, React Testing Library, Playwright, and Chromatic. The product updates in near real time and uses technologies including WebSockets and WebRTC. Our mobile application is built with React Native.

We build and test Docker images in CI/CD and continuously deploy them to Kubernetes on AWS. Our infrastructure uses managed services including EKS, MSK, and ElastiCache, alongside services running on EC2. Terraform and Ansible automate much of the underlying infrastructure, and our containerized local development environment lets engineers run the full system on their own machines.

For this role, our stack extends beyond simply backend or frontend: browser behavior, frontend state, API authorization, asynchronous processing, data access, third‑party integrations, containers, and cloud configuration can all be part of the same attack path.

We love open sourcing our code and ideas on our GitHub and on The Making of Close, our behind‑the‑scenes Product & Engineering blog. Check out our open source projects like SocketShark, TaskTiger, LimitLion and ciso8601.

AI is both how we build and what we ship, and that's reshaped what engineering looks like. This is a transformation we’re embracing and find deeply exciting.

You are

  • An application security engineer who writes code. You can move from reading an unfamiliar code path, to reproducing an exploit, to proposing or shipping a production‑quality fix. Strong Python or TypeScript experience would be especially useful; fluency across both backend and frontend systems is even better.

  • Skilled at finding vulnerabilities conventional scanners may miss. You use modern AI‑assisted review pipelines, guided by expert judgment, to uncover subtle flaws in web apps and APIs—from authentication, authorization, and tenant isolation to injection, SSRF, unsafe data flows, and business logic. You can threat‑model designs, white‑box review code, and test running systems.

  • Offensive‑minded and operationally responsible. You know how to test like an attacker without being careless with customer data or production systems. You can turn a finding into a safe reproduction, assess exploitability and business impact, and retest the eventual fix.

  • An automation builder. You have worked with some mix of SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling. More importantly, you know how to tune tools, connect them to engineering workflows, and remove noise.

  • AI‑native and accountable. You use coding agents and LLMs to accelerate investigation, code review, and repetitive engineering work, but you verify their output. You think carefully about what happens when agents clone untrusted code, install dependencies, or receive access to credentials.

  • Able to separate severity from priority. A score is an input, not a foregone conclusion. You consider reachability, existing controls, customer impact, and attack chains, then explain the risk in language that is legible to an engineer or business owner.

  • Comfortable working across the business. You’ll collaborate with product engineers, Site Reliability Engineers, Security & Trust Lead, auditors, and external researchers without confusing partnership for pass‑off ownership. You will follow findings to closure even when another team is responsible for the fix.

  • Self‑directed in a remote environment. You can take an ambiguous surface (say, secret rotation or dependency remediation) and learn how it works across multiple systems then turn it into a practical plan with measurable progress.

You do not need to arrive as the deepest expert in every part of this scope. You do need to be able to investigate an unfamiliar system, determine what matters, and bring the right people with you.

You will

The work spans hands‑on application security, security automation, vulnerability management, and infrastructure partnership. Depending on where you find the greatest risk and leverage, projects could include:

  • Build a recurring product security review program. Threat model new features, audit high‑risk areas, review code, and build safe proof‑of‑concepts in isolated development environments. Work across our backend, frontend, APIs, and customer‑facing integrations.

  • Improve application security testing. Combine static analysis, dependency and secrets scanning, dynamic testing in development, and carefully scoped production testing. Use existing tools where they fit and build focused automation where they don’t.

  • Own vulnerability intake and remediation. Triage findings from HackerOne, scanners, penetration tests, audits, customers, and internal research. Reproduce issues, assess exploitability and impact, track remediation, and verify fixes. Serve as technical lead for our bug bounty program while contract and budget ownership remain elsewhere.

  • Turn security alerts into useful engineering work. Verify scanner coverage and automate ingestion, deduplication, enrichment, prioritization, and routing—so teams spend less time interpreting alerts and more time fixing important issues.

  • Make dependency remediation safer and less manual. Improve scanning across our Python and TypeScript codebases, then build workflows to assess upgrades, stage pull requests, run checks, and route work without exposing credentials to untrusted packages or build steps.

  • Make secrets routinely rotatable. Partner with service owners and Infrastructure to inventory application secrets, add graceful rotation paths, document provider‑specific runbooks, and automate rotation where the provider and risk justify it. Expand our use of Vault‑backed dynamic credentials and reduce the number of rotations that require a coordinated fire drill.

  • Strengthen AWS security with Infrastructure. Evaluate and improve automated detection of risky configuration across identity, networking, compute, storage, containers, and registries. Turn findings into secure defaults, just‑in‑time access patterns, infrastructure guardrails, and actionable remediation—not build a second Infrastructure team.

  • Support audits and raising the security floor. Partner with Security & Trust on external assessments, provide technical context, and ensure findings are fixed rather than rediscovered. Along the way, create documentation, paved roads, and lightweight training that helps engineers make safer choices without waiting for a security review.

  • Take a key technical role in security incident response. Partner with Engineering and Infrastructure to coordinate investigation, containment, and remediation. Contribute to root‑cause analysis and follow‑up improvements, translating lessons learned into stronger controls and reduced recurrence.

Tech you’ll touch: Python, TypeScript, React, Flask, FastAPI, GraphQL, Docker, Kubernetes, AWS, Vault, GitHub Actions, MongoDB, PostgreSQL, Redis, Kafka, Elasticsearch and the security tooling you help us choose.

Benefits

  • Compensation: Competitive pay plus an organization‑wide goal‑based bonus

  • Paid Time Off: ~5 weeks of PTO to start. Plus a 1‑week all‑company Winter Holiday Break and paid US holidays. You'll earn 2 extra days for every year you're with Close.

  • 80% Work Option: Work with your manager to choose between a standard 5‑day week or a 4‑day week at 80% pay

  • Parental Leave: Paid leave for primary and secondary caregivers

  • Sabbatical: A 1‑month paid sabbatical every 5 years with the team

  • Healthcare (US residents): Two medical plans with Close covering the majority of your premium, plus Dental, Vision, HSA, FSA, and company‑paid Long‑Term Disability

  • 401k (US residents): We match your contributions up to 6%, vested immediately

Our Values

Build a house you want to live in - Examine long‑term thinking and action

No BS - Practice transparency and honesty, especially when it’s hard

Invest in each other - Build successful relationships with your coworkers and customers

Discipline equals freedom - Keep your word to yourself and others

Strive for greatness - Constantly challenge yourself and others

Learn More

Listen to our CEO and Founder, Steli Efti, tell the story of Close’s journey in the $0-30m Blueprint.

Watch our culture video from our 2023 team retreat in Milan. Every year our entire team gathers in person to build connection, foster cross‑functional collaboration, and have fun. In 2027, we're headed to Dusseldorf, Germany!

Explore our product. Check out a demo!

Our Hiring Process

We ask a few role‑specific questions as part of our application process. These questions are designed to help us learn more about you from the start, so please answer each one thoughtfully. We see this as an opportunity to get to know you beyond your resume.

We use AI tools daily at Close and expect candidates to do the same. In evaluating your application, we aim to get a sense for you - the way you think, how you communicate, the work you've done. Applications that read as fully AI-generated will not be considered.

Regardless of fit, you can expect to hear back from our team with an update on the status of your candidacy.

If you progress to the interview process, you'll receive a full outline of the role‑specific steps in your first touchpoint with us. We do our best to make the hiring process clear and human.

#J-18808-Ljbffr Jobleads-US
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Product Security Engineer (USA Only, 100% Remote) in Kentucky vacancy
  •  ...Responsibilities Build a recurring product security review program covering...  ...efforts to raise the engineering security baseline....  ...independently in a remote environment and turning...  ...immediate vesting. ~100% remote role for candidates in the USA; the entire company... 
    Remote work
    Senior
    Full time
    Immediate start

    Close

    Remote
    2 days ago
  •  ...Iru Iru is the AI-powered security & IT platform used by the world...  ...In July 2024, Iru raised $100 million from General...  ...seeking a highly technical Senior Product Security Engineer for a 6-month contract (40...  ...protected by applicable law. #LI-Remote #J-18808-Ljbffr Iru, Inc.
    Remote work
    Senior
    Contract work

    Iru, Inc.

    Eastern, KY
    4 days ago
  • $50 - $60 per hour

     ...patch management and just in general securing these medical devices from a product securing perspective. The person...  ...Experience: Product Security Engineering Experience Vulnerability Management...  ...(Required) Threat modeling: 2 years (Required) Work Location: Remote... 
    Remote work
    Senior
    Hourly pay
    Contract work
    Immediate start

    AR Security

    United States
    3 days ago
  • $140.3k - $233.8k

     ...known for delivering insights, products, and services that make...  ...you.CoverMyMeds is seeking a Senior Product Security Engineer, AI & DevSecOps to embed...  ...McKesson!SummaryLocation: USA, OH, Columbus; Irving, TX,...  ...State Highway 161 (P001); USA, Remote; Overland Park, KS, USA - 5... 
    Remote work
    Senior
    Full time
    H1b

    McKesson

    Alpharetta, GA
    4 hours ago
  • Join Hologic's mission to drive a Secure by Design culture within our Breast...  ...Skeletal Health Connected Health products. As a Senior Product Security Engineer, you will play a pivotal role in ensuring...  ..., CA, Marlborough, MA or can sit remotely. This is your chance to be part of... 
    Remote work
    Senior

    Hologic

    Santa Clara, CA
    3 days ago
  •  ...Driving the adoption of modern security processes and tooling, the full-time Senior Product Security Engineer will collaborate with engineering and product teams to enhance...  ...measures across platforms and services in a remote setting. Key responsibilities Collaborate on... 
    Remote work
    Senior
    Full time

    Virtual Vocations Inc

    United States
    13 hours ago
  • $173.4k - $234.6k

    Senior Product Security Event Detection EngineerCompany:The Boeing CompanyBoeing...  ...Product Security Event Detection Engineer (Level 4) to join the Risk...  ...position is expected to be 100% onsite. The selected...  ...Work (Spanish)SummaryLocation: USA - Seattle, WA; USA - Everett... 
    Senior
    Permanent employment
    Full time
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Boeing

    Seattle, WA
    13 hours ago
  •  ...Close is seeking a Product Security Engineer to build and lead security efforts across backend and frontend stacks. You will own vulnerability remediation, threat modeling, and tooling optimization while collaborating with Engineering, SRE, and auditors. The role emphasizes... 
    Remote job
    Senior

    Jobleads-US

    Kentucky
    1 day ago
  • YipitData is looking for a Product Security Engineer to help build security into the products and services we deliver to customers. In this role, you will partner closely with Engineering and Product teams throughout the development lifecycle. You will assess new products... 
    Remote job
    Senior

    Bazeta

    New York, NY
    4 days ago
  • Tessera Labs is seeking a Senior Product Security Engineer to collaborate with developers and secure the product across its lifecycle. You will conduct design reviews, threat modeling, and hands-on testing to make the platform defensible while enabling engineers to ship... 
    Remote job
    Senior

    Tessera Labs

    New York, NY
    5 days ago
  • TRM Labs is seeking a Product Security Engineer to join our remote team in the United States. You will lead security reviews, threat modeling, and vulnerability management while embedding security into our fast-paced development cycles. The role emphasizes collaboration... 
    Remote job
    Senior

    Technology Resource Management

    New York, NY
    5 days ago
  •  ...Zachary Piper Solutions is seeking a Senior DoD Product Security Engineer to secure autonomous and embedded platforms across the product lifecycle....  ...programs. The position is hybrid in Clarksburg, MD with remote days offered, and requires DoD security #J-18808-Ljbffr... 
    Remote work
    Senior

    Jobleads-US

    Clarksburg, MD
    4 days ago
  • $185k - $225k

     ...from Denu RecruitLocation:Fully Remote (Synchronous work culture;...  ...software. We're looking for a Senior Product Engineer to help build polished, user-...  ...6 workflows to potentially 100+ workflowsWhat We're Looking...  ..., AI Platform (FULLY REMOTE, USA ONLY)We're unlocking community... 
    Remote work
    Senior

    Denu Recruit

    New York, NY
    13 hours ago
  • # Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)United States13 hours agoID 1507902Price on request## DetailsEmployment type: Full-timeRemote: YesCompany...  ...on The Making of Close , our behind-the-scenes Product & Engineering blog. Check out our open source... 
    Remote job
    Senior
    Local area
    Shift work

    Jobleads-US

    Kentucky
    2 days ago
  • # Senior Backend Engineer - CRM (USA Only, 100% Remote)United States13 hours agoID 1507904Price on request## DetailsEmployment type: Full-timeRemote: YesCompany...  ...and on The Making of Close , our behind-the-scenes Product & Engineering blog. Check out our open source... 
    Remote job
    Senior
    Local area
    Flexible hours
    Shift work

    Jobleads-US

    Kentucky
    2 days ago
  •  ...believe in us and our product, and so do leading venture...  ...400 people working in Engineering, Data, and Product...  ...see how it feels to be 100% yourself at work, here...  ...not to, as we're 100% remote friendly. Job Description...  ...ensuring that compliance, security, and business... 
    Remote job
    Senior
    Contract work
    Work at office
    Flexible hours

    United States Digital Space LLC

    New York, NY
    3 days ago
  • $132k - $198k

     ...breadth of our talent, technologies, products, services, and solutions to address...  ...urinary retention, and much more.The Senior Product Security Engineer - Embedded IoT is responsible for...  ...interfaces, programmers, gateways, and remote-monitoring connectivity.Support... 
    Remote work
    Senior
    Full time
    H1b
    Work at office
    Local area
    Immediate start
    Flexible hours

    Medtronic

    Fridley, MN
    1 day ago
  •  ...Requirements This position may require a security clearance in the future. Applicants must...  ...Position Responsibilities Our products support research, classified national...  ...looking for technical, passionate security engineers to influence the security of software... 
    Remote work
    Senior
    Temporary work
    Work at office
    Local area
    Relocation
    Flexible hours

    Talentify.io

    Clarksburg, MD
    1 day ago
  • $68.9k - $131.1k

     ...under this program/contract. Security Clearance Type: None/Not...  ...a driven System Security Engineer to join our Embedded Product Cybersecurity Engineering...  ...partnership with your leader.Remote: Employees who are working...  ...role is 68,900 USD - 131,100 USD. The salary range... 
    Remote work
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Work from home
    Flexible hours

    Raytheon

    Cedar Rapids, IA
    1 day ago
  • $162.35k - $219.65k

     ...future with us. The Boeing Company is currently seeking a Senior Product Security Engineer to join our Training Systems Product Security Engineering...  ...a teaming environment This position is expected to be 100% onsite. The selected candidate will be required to work... 
    Senior
    Permanent employment
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    Shift work
    Day shift

    The Boeing Company

    Saint Louis, MO
    3 days ago
  •  ...AI, and enables leaders to secure their AI assets. Organizations...  ...an experienced Staff Product Security Engineer to drive security innovation...  ...apply to jobs when they meet 100% of the qualifications while...  ...US; Seattle, Washington, US; Remote Canada - ON; San Francisco,... 
    Remote work
    Full time
    Local area
    Worldwide
    Flexible hours

    DataRobot

    Washington DC
    3 days ago
  • $100k - $165k

     ...2027-09-25Job Title: Senior Security EngineerLocation (city...  ...Type: Direct hirePay: $100,000-$165,000 annually...  ...Monday through Thursday; remote FridayBenefits: This...  ...a Senior Security Engineer to help shape and implement...  ....Help resolve urgent production security issues... 
    Remote work
    Senior
    Work experience placement
    Monday to Thursday

    Addison Group

    Dallas, TX
    13 hours ago
  • $137.86k - $250k

     ...all. Your Charter Secure NEO end-to-end. You...  ...adversaries do, and partner with engineering teams to design and...  ...Design and contribute production code for security-...  ...similar) Familiarity with remote device attestation...  ...plan with company match (100% on the first 3% of contributions... 
    Remote work
    Temporary work
    Local area
    Work from home
    Flexible hours

    1X

    San Carlos, CA
    2 days ago
  •  ...We're looking for a hands-on Senior Security Engineer to join one of our clients and own the technical...  ...closely with Engineering to secure production systems, find weaknesses, and keep...  ...Specialty, or similar. Extra ~100% remote-first culture (work anywhere in the... 
    Remote work
    Senior
    Full time
    Fixed term contract
    Flexible hours

    Elastify

    United States
    3 days ago
  •  ..., apply now.We are currently seeking a Senior Security Engineer to join our team in Durham, North Carolina...  ..., serving 75% of the Fortune Global 100. We are committed to accelerating client...  ...’s needs. While many positions offer remote or hybrid work options, these arrangements... 
    Remote work
    Senior
    Work at office
    Flexible hours

    NTT DATA

    Durham, NC
    3 days ago
  •  ...Livermore, California, USA (topconpositioning.com)...  ...manufacture and distribute productivity tools for developing a...  ...Purpose: Serve as a senior individual contributor on the Security Engineering team with a primary focus...  ...: Standard office/remote work environment. Prolonged... 
    Remote work
    Senior
    Full time
    Casual work
    Work at office

    Topcon Electronics

    Livermore, CA
    2 days ago
  • $296k - $395k

     ....About the RoleLambda Security protects some of the world...  ...and employee productivity, we want to talk.We value...  ...readiness for a Sr. Security Engineer role. Your application...  ...solutions, and secure remote worker access...  ...with 2% company match (USA employees)Flexible paid... 
    Remote work
    Senior
    Work at office
    Local area
    Work from home
    Flexible hours

    Lambda Labs

    San Jose, CA
    3 days ago
  • $260k - $310k

     ...Cohere is the leading security-first enterprise...  ...and end-to-end products that are designed...  ...team of researchers, engineers, designers, and...  ...Seoul. Join us!As a Senior Security Engineer...  ...K, Pension Scheme.100% Parental Leave top...  ...if you are remote, plus an annual company... 
    Remote work
    Senior
    Work at office
    Local area
    Home office
    Flexible hours

    Cohere

    New York, NY
    1 day ago
  •  ...Company in Seattle/Everett, WA seeks a Product Security Event Detection Engineer (Level 4) to join the Risk...  ...Capability team onsite. You will be a senior technical contributor shaping detection...  ...customers, suppliers, and governments. 100% onsite work at listed locations.... 
    Senior

    Jobleads-US

    Seattle, WA
    2 days ago
  • $165k - $200k

     ...together. Its suite of products — including the...  ...motivated Staff Product Security Engineer to join our growing Security...  ...role reports to the Senior Manager of Product Security...  ...healthcare ~100% paid parental and caregiving...  ...~ Flexible WFH, both remote and in-office... 
    Remote work
    Work at office
    Local area
    Work from home
    Flexible hours
    Day shift

    Owl Ventures, LP

    Eastern, KY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Product Security Engineer (USA Only, 100% Remote). Be the first to apply!