Product Security Engineer
Theory Ventures
Product Security Engineer
San Francisco
Engineering
Hybrid
Full-time
About BackOps
BackOps AI transforms supply-chain operations with agentic AI that automates complex workflows, freeing teams to focus on what matters most. Headquartered in the San Francisco Bay Area, we foster a culture of innovation, ownership, and measurable impact.
The Role
Our agents take real actions inside our customers' live operations. They read from and write to the systems a supply-chain team runs its business on. That makes authorization, tenant isolation, and the blast radius of a single agent action product design questions, and it puts product security on the critical path of every enterprise deal we close.
We are looking for the engineer who owns that. This is a hands-on role and the first dedicated product security hire, so you will build the product security practice and do the work at the same time.
You will work closely with engineering and infrastructure on how our systems get built and run, and with product on what gets built next. You will read the code, write the fix, and ship guardrails that engineers keep switched on because they are fast and mostly right.
Your Impact
In this role, you will own the security of the BackOps product end to end, and set the bar for how secure software gets built here while the company triples in size.
- Own product security end to end: authentication, authorization, multi-tenant isolation, APIs, and the data model behind them.
- Threat model the agent platform. Define what an agent is allowed to do in a customer's systems, prove the boundary holds, and design what happens when an agent is asked to do something it should not.
- Build the secure development lifecycle: design review, code review standards, and scanning in CI with a triage path engineers actually use.
- Run application vulnerability management end to end. Find it, prioritize it by real exploitability rather than by scanner severity, get it fixed, verify the fix.
- Set the security bar for AI-assisted code. A large share of our code is written with coding agents, and human ownership of what merges is not optional.
- Secure the software supply chain: dependencies, build pipeline, artifacts, and third-party integrations.
- Own the engineering side of enterprise security reviews, penetration tests, and coordinated vulnerability disclosure, so customer scrutiny stops being a fire drill.
- Extend the same controls to customer-hosted and on-prem deployments, where they have to hold up without our infrastructure around them.
What We're Looking For
- 5+ years in product or application security engineering, or a software engineer who moved into security and stayed hands-on.
- Strong coding skills in Python, Go, TypeScript, or similar. You review real code and write the fix yourself.
- Real depth in authentication, authorization, and multi-tenant isolation: OAuth and OIDC, RBAC, token and session handling, and the access-control bugs that only show up between two features.
- Web and API security depth across the OWASP Top 10 classes: injection, SSRF, deserialization, and broken access control, and how these actually get exploited rather than how they are listed.
- Working familiarity with the OWASP Top 10 for Agentic Applications and the OWASP Top 10 for LLM Applications. Excessive agency and prompt injection are live concerns in our product today.
- Threat modeling that produces engineering work with owners and dates, not a document.
- Hands-on with SAST, DAST, SCA, and secrets scanning in CI, including keeping the noise low enough that teams do not turn the checks off.
- Judgment about risk. You can say what to fix now, what to accept, and why, to an audience that will push back.
- Clear written and verbal communication with engineers, executives, and customers, including saying plainly what is still unknown.
- Comfortable defining the structure while doing the work, in a company where requirements change week to week.
Nice to Have
- Hands-on securing LLM or agentic systems: prompt injection, insecure tool use, excessive agency and permissions, sandboxing, and handling model output as untrusted input.
- SOC 2 Type I/II, ISO 27001, or similar audits taken end to end, and compliance automation tooling such as Vanta or Drata.
- Enterprise security reviews and customer questionnaires answered from the engineering seat.
- Multi-tenant B2B SaaS, and on-prem or customer-hosted deployment.
- Running a bug bounty or coordinated disclosure program.
- Security capabilities delivered as an internal product, with real adoption numbers behind them.
- Standing up a product security function where none existed: charter, practices, and the culture around it.
What Success Looks Like
- What an agent can do inside a customer's systems is bounded by design, and we can demonstrate the boundary holds.
- Security shows up when a feature is being designed, rather than as a gate in front of the release.
- Vulnerabilities are found earlier and fixed faster, and we can show the trend.
- Enterprise security reviews stop holding up deals.
- Engineers keep the automated checks on because they are fast and usually right.
- Teams ship secure features without you in the room.
Why BackOps
- Own product security at an AI-native company while the product is still being shaped.
- Our agents take real actions in customer operations, which makes this work matter more here than it does in most places.
- Small team with real autonomy and direct access to founders and customers.
- Backed by exceptional investors and advisors.
Rewards
- Competitive salary and meaningful equity.
- Comprehensive health, dental, and vision coverage.
- 401(k) plan, disability insurance, and life insurance.
- Flexible time off.
- Daily meals in the office, and regular team events and offsites.
- ...Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and...SuggestedFull time
- ...tenant isolation, and the blast radius of a single agent action product design questions, and it puts product security on the critical path of every enterprise deal we close. We are looking for the engineer who owns that. This is a hands-on role and the first dedicated...SuggestedWork at officeFlexible hours
- ...identity verification infrastructure where security isn't a layer we add later, it's core to... .... As AI tooling expands what engineers can build and how fast they can build it... ...that scale security across every team and product. Partner with product engineers to shape...SuggestedFull timeFor contractorsInternshipRelocation package
- ...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re... ...getting started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity to build...SuggestedWork experience placement
$250k - $285k
...high-performing team that believes in each other, come build with us at Crusoe. About This Role We’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and...SuggestedTemporary work$50 per hour
...computational biology. About This Role Crusoe Security & Compliance is hiring a Senior/Staff Application Security Engineer to play a critical role in ensuring the... ...improvement of our security posture, making our products safer and our customers' data more secure....Temporary work$235k - $275k
...Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00...Full time$130k - $215k
...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers... ...Snowpoint, and employs a team of 500 engineers and entrepreneurs. Astranis designs, builds... ...in Northern California, USA. Product Security Engineer As a Product Security...Permanent employmentFlexible hours- ...humble and collaborative; turn zerotoone ideas into real products, and you "get stuff done" end-to-end. You use AI to... ...'s next. About the team Airwallex's Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data...Worldwide
$148.5k - $246k
...to ensure you are not duplicating efforts. Job Category Product Job Details About Salesforce Salesforce is the #1 AI CRM... ...are the future of Salesforce. Job Title: Senior Product Security Engineer, Infrastructure Job Category: Technology / Security Location...Full time- Parallel seeks a senior security engineer to build and operate the security systems enabling fast shipping with minimal risk. You will cover application security, secure defaults, and AI-assisted tooling, addressing the unique attack surface of agentic systems that consume...
$175k - $215k
...and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures...Temporary work- ...WRITER is seeking an Application Security Engineer with deep expertise in AppSec, DevSecOps automation, and red team operations to secure their AI and AGI applications. The role involves integrating security into development pipelines, conducting penetration testing, and...H1bWork from homeRelocationHome officeFlexible hours
$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$300k - $320k
...growing group of committed researchers, engineers, policy experts, and business leaders working... ...AI systems. About the Team The Security Engineering team's mission is to safeguard... ...practices, or partnering with our research and product teams, we are committed to operating as...Work at officeVisa sponsorshipFlexible hours$268k - $321k
...Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-... ...unicorn valuation, we've built a suite of products that help millions of people build... ...sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI...Full timeLocal area- ...Anything is the AI product engineer for the next wave of entrepreneurs. It’s an AI agent that turns English into apps. Everything you need to make money on the internet built in – mobile, web, design, AI, backend, infra, payments. Launched Aug 7th. Hit $5m rev...Temporary work
- ...applications is our core focus at Witness. The products and tools you build will be instrumental... ...payment rail purpose built for secure and fixed cost transactions. It utilizes... ...facing applications on top of it. As an engineer at Witness, you'll play a critical role...Remote workFlexible hours
- ...PromptArmor is an AI security company based in San Francisco. We help the world's most demanding... ...novel risks introduced by AI in their products and across their assets and ecosystem.... ...wasn't built to solve. We're hiring engineers across the stack to help us build the...
- ...Senior Product Engineer World Labs is a frontier AI research and product company advancing spatial intelligence, the next frontier beyond large language models. Co-founded by Dr. Fei-Fei Li, Justin Johnson and Ben Mildenhall, the company is pioneering world models...Work at officeVisa sponsorshipWork visaRelocation packageFlexible hours
- ...Senior Product Engineer @ Kato About the Job Position: Senior Product Engineer (Full-Time) Reporting to: CTO Location: San Francisco (4 days/week in person) Company Overview Lenders spend over $24B every year hiring agents to perform manual, repetitive...Full timeStart working today
- ...billion people due to age, injury, or disability. We are building products that will restore mobility for millions and enable a new... ...to consumers. We are a flat team of 22 phenomenal and senior engineers, where everyone contributes directly to product development, as...Full timeWork at officeRelocation
$180k - $240k
...in the Presidio in San Francisco. About The Role You’ll own the product surface of Sauna: the interfaces people use to hand work to it,... ...it look good without a designer. Founding or early frontend engineer who set standards from scratch. Compensation And Benefits Base...Full timeWork at officeLocal areaRelocationVisa sponsorshipNight shiftDay shift- TEST BOARD Example org is a leading software company. Example org allows real-time collaboration on important example workflows. Founded in 2012 we have over 10,000 customers worldwide and are backed by fantastic investors such as Example Capital TEST BOARDWorldwide
$150k - $200k
...own the outcome. Search infrastructure, data pipelines, ML, APIs, product – you move across all of it depending on what matters most that week. You're a true generalist. Backend, frontend, AI engineering, data systems, product thinking, growth experiments – you pick...Local areaNight shiftWeekend work$150k - $224k
...our website. Role We're looking for a hands-on Senior Product Engineer who takes pride in writing excellent code and raises the bar... ...data pipelines is a plus. ~ Experience building scalable, secure, production-grade SaaS applications. ~ Deep understanding of...Shift work- ...about how we think about building teams: About Vitalize's Engineering Team Every recommendation Vitalize makes flows through this... ...needs, and operational constraints. Partner with our Product Managers, Designers, and other Engineers to build complex software...Work at officeRelocation packageFlexible hours
$110k - $170k
...the company | Product Engineer | San Francisco (SF) | HYBRID | $110k-$170k + Equity | US CITIZEN / GREEN CARD ONLY (NO VISA SPONSORSHIP) PLEASE NOTE: We CANNOT provide visa sponsorship, transfers, or OPT/STEM extensions of any kind. Applicants must already be authorized...- ...Turn the AI runtime into product. Design and ship full vertical experiences — Search, Shop, Finance, Health, Legal — end to end on the... ...white, pixel‑perfect interfaces that ship the same day Wire AI engines into product through the engine‑registry pattern Talk to...
- ...We're looking for a Product Engineer with strong product judgment, UX instincts, and frontend expertise to shape how customers experience... ...when and how we notify them, and how they understand and act on security work inside the Casco console. This is a role for someone...Contract workWork at officeVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Engineer. Be the first to apply!
- design assurance engineer San Francisco, CA
- product engineering manager San Francisco, CA
- senior software design engineer San Francisco, CA
- product design engineer San Francisco, CA
- senior manager product engineering San Francisco, CA
- senior product design engineer San Francisco, CA
- senior design verification engineer San Francisco, CA
- sr. product engineer San Francisco, CA
- new product engineer San Francisco, CA
- design engineer San Francisco, CA

