Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Product Security Engineer

Aalyria

About Aalyria:

Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry. With technology acquired from Google, Aalyria is at the forefront of innovation in satellite and airborne mesh networks, as well as cislunar and deep-space communications. We are revolutionizing the orchestration and management of planetary mesh networks using any radio or optical spectrum, any orbit, and any hardware across land, sea, air, and space.

Role Overview:

You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI, and you'll partner closely with hardware engineering on Tightbeam.

This is a senior to staff level individual contributor role with room to grow into management as the function scales. We need someone who's genuinely happy in a terminal and equally comfortable leading an architecture review.

Key Responsibilities:

  • Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase.
  • CI/CD and supply-chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA-aligned controls.
  • Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection.
  • Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets.
  • Vulnerability management. Triage, prioritization, remediation tracking, and exception handling, for both disclosed upstream issues and internal findings.
  • Product incident response. Leading triage and response for product-side security incidents, coordinating with corporate IR, and driving post-mortems to action.
  • Product infra hardening. Baseline configurations, secure defaults, and compensating controls across product environments.
  • Hardware security partnership. Working with the Tightbeam team on firmware security, secure boot, key storage, and hardware supply-chain integrity.
Required Qualifications:
  • Senior- or staff-level hands-on experience in product security or security engineering, with significant depth in software/AppSec.
  • Production experience securing cloud environments such as IAM, org policy, VPC Service Controls, KMS, and Kubernetes at depth.
  • Strong cryptographic foundations, PKI architecture, key management, signing, mTLS, and secrets handling at scale.
  • Hands-on coding ability in Python, Bash, and Go, you can write tooling, automate controls, and ship Terraform/scripts when the situation calls for it. Comfort reviewing code is a plus.
  • A track record of building security programs, not just operating tools someone else stood up.
  • Experience leading product incident response, triage, response, coordination with engineering teams, customer comms, and post-mortem ownership.
  • A pattern of mentoring engineers and raising the security bar of teams around you, even without direct reports.
  • Experience interfacing with hardware/firmware teams, even if hardware isn't your primary domain.
  • Strong written communication, you'll write threat models, design docs, and program updates that go to the executives, customers, and assessors.
  • Working knowledge of the compliance frameworks that govern our environment such as CMMC, FedRAMP, and DFARS along with the ability to translate controls into engineering work.
Preferred Qualifications:
  • Hands on experience with NIST 800-53, NIST 800-171, or DoD SRG environments.
  • Experience with government-cloud platforms.
  • Hardware security depth in HSMs, TPMs, secure elements, supply-chain attestation.
  • Embedded / firmware security background, secure boot, RoT, OTA update integrity, hands-on firmware review.
  • Experience standing up or running a vulnerability disclosure program or bug bounty, triage, researcher comms, and CVE coordination.
What We Offer:
  • Innovative Environment: Work at a cutting-edge company shaping the future of aerospace communications.
  • Impactful Work: Directly contribute to critical national security programs and initiatives.
  • Growth Opportunities: Expand your career with opportunities for professional development and advancement.
  • Inclusive Culture: Be part of a collaborative, supportive, and inclusive workplace where your contributions matter.
  • Flexibility: Flexible working arrangements including hybrid remote/in-office schedules.
  • Compensation and Equity: Competitive salary, comprehensive benefits (401(k), dental, vision, health, life insurance), paid time off, and equity options.
ITAR/EAR Requirements:

This position involves access to export-controlled information. To comply with U.S. government export regulations, applicants must meet one of the following criteria:

(A) Qualify as a U.S. person, which includes:
  • U.S. citizen or national
  • U.S. lawful permanent resident (green card holder)
  • Refugee under 8 U.S.C. 1157
  • Asylee under 8 U.S.C. 1158

(B) Be eligible to access export-controlled information without requiring an export authorization.

(C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency.

The company reserves the right to decline pursuing an export licensing process for legitimate business-related reasons.

Equal Opportunity Employer Statement:

Aalyria is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability status, genetic information, protected veteran status, or any other characteristic protected by law. Qualified applicants from all backgrounds are encouraged to apply.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead Product Security Engineer in United States vacancy
  • A leading identity verification company in San Francisco seeks a skilled Product Security Engineer. In this role, you'll drive the vulnerability lifecycle, design scalable security systems, and partner with engineers to ensure secure product development. Candidates should... 
    Suggested
    Relocation package

    Persona

    San Francisco, CA
    4 days ago
  • $85k - $165k

    A leading engineering services company is seeking Nuclear Physical Security Design Technicians/Engineers to engage with clients and deliver innovative solutions in Physical Security. This role involves building relationships, leading technical discussions, and managing... 
    Suggested
    Remote job

    Enercon Services, Inc.

    King of Prussia, PA
    4 days ago
  • $85k - $165k

    A leading engineering firm is seeking a Nuclear Physical Security Design Technician/Engineer in Naperville, IL. This role involves collaborating with engineering teams and clients to deliver innovative solutions in Physical Security. Candidates should have at least 6 years... 
    Suggested
    Remote job

    Enercon Services, Inc.

    Naperville, IL
    3 days ago
  •  ...PSIRT Engineer Replit is the agentic software creation platform that enables...  ...highly skilled PSIRT Engineer to lead the vulnerability response program...  .... You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation... 
    Suggested
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    San Mateo, CA
    1 day ago
  •  ...Performs daily execution of internal product security testing efforts for all new product releases...  ...and experience with embedded device engineering, Cloud technology stacks, Binary Analysis...  ...to help arrive at a decision. May lead functional teams or projects with minimal... 
    Suggested
    Remote work
    Relocation package

    GE Healthcare

    United States
    2 days ago
  •  ...Senior Product Security Engineer Remote · Full-Time · Engineering Founded in 2019, Cherry is a fast-growing FinTech offering the simplest,...  ...vulnerability management, and security testing processes. Lead security reviews for authentication and authorization systems... 
    Full time
    Remote work
    Flexible hours

    Cherry Corporation

    United States
    3 days ago
  •  ...infrastructure that developers need to securely scale their products to large organizations. We...  ...highly collaborative group with a strong engineering mindset. Our security program is shaped...  ...with you. Responsibilities Lead secure design efforts. Partner with... 
    Work experience placement
    Remote work

    WorkOS, Inc

    Canada, KY
    4 days ago
  • $110.93k - $184.88k

     ...The Product Security Engineer is responsible for conducting comprehensive security assessments on various products, including mobile applications, IoT hardware/firmware, compiled software, and browser extensions. This role involves identifying vulnerabilities, developing... 
    Temporary work
    Work experience placement
    Local area
    Remote work
    Relocation package
    Flexible hours

    Inmar

    United States
    21 hours ago
  • $119.3k - $140.4k

     ...The Role Maintaining the security and privacy of our users is...  ...unique opportunity to use your engineering and security skills to make a...  ...role will be part of the Product Security (ProdSec) team, report...  ...Hashicorp Vault, and other industry-leading application security... 
    Full time
    Remote work
    Work from home
    Flexible hours

    ModernHEALTH

    United States
    1 day ago
  • $157.25k - $198.88k

     ...Product Security Engineer Our healthcare system is the leading cause of personal bankruptcy in the U.S. Every year, over 50 million Americans suffer adverse financial consequences as a result of seeking care, from lower credit scores to garnished wages. The challenge... 
    Work at office
    Remote work
    Work from home
    Flexible hours

    Cedar

    United States
    2 days ago
  •  ...A company is looking for an Experienced Product Security Engineer (Virtual). Key Responsibilities Develops, implements, and sustains product security throughout the lifecycle Enhances system requirements and architectures for product security compliance Coordinates... 
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Annapolis, MD
    21 hours ago
  • $113k - $125k

     ...is valued at $5.5B, backed by leading investors including Goldman...  ...testing, deployments, application security, reliability, compliance, and...  .... About the Role Product Security is responsible for ensuring...  ...developing partnerships with engineering and product teams to... 
    Local area
    Immediate start
    Remote work
    Shift work

    Harness

    United States
    1 day ago
  •  ...operating directly within the product development lifecycle-...  ...that understanding to product security decisions, acceptance criteria...  ...clear success metrics. Lead Secure-by-Design initiatives...  ...Serve as advisor to product and engineering on security risk, architectural... 
    Minimum wage
    Local area
    Remote work

    Vertex Limited

    United States
    21 hours ago
  •  ...Overview Product Security Engineers work closely with software engineering and product teams to achieve product and security business objectives...  ...with support of existing systems and/or business requests. Lead the evaluation and use of security technologies and tools.... 
    Remote work

    SecureState

    United States
    2 days ago
  •  ...Senior Product Security Engineer Function Health is the AI operating system for health, designed to empower people to live 100 healthy years. We are redefining how individuals understand, measure, and improve their health by moving beyond reactive care and enabling... 
    Remote work
    Flexible hours

    Function Health

    United States
    3 days ago
  • 1Password is searching for a Senior Developer on our Device Security squad, responsible for implementing new security features across multiple platforms including macOS, iOS, and Android. The ideal candidate has extensive experience in software development with a focus... 
    Remote work

    1Password

    United States
    4 days ago
  • $180k - $220k

     ...your recruiter to learn more. Base pay range $180,000.00/yr - $220,000.00/yr Additional compensation types Stock options Product Security Engineer We are hiring a Product Security Engineer who can make real security changes in the codebase and infrastructure, not bolt... 
    Full time
    Remote work
    Visa sponsorship

    Hampton North

    Richmond, VA
    2 days ago
  • $116.5k - $154k

     ...Product Security Engineer Remote - US This is Engineering at Lattice At Lattice, we build software that helps people and organizations thrive. Our engineering team values maintainable systems, strong collaboration, and thoughtful product experiences. As we... 
    Work at office
    Remote work

    Lattice

    United States
    1 day ago
  •  ...Framework Ventures is hiring a Product Security Engineer focused on security reviews and tool development in the DeFi space. In this remote role, youll work with leading web3 professionals on complex security challenges. Key responsibilities include designing defense... 
    Remote work

    Framework Ventures

    United States
    4 hours ago
  •  ...Senior Product Security Engineer DataRobot delivers AI that maximizes impact and minimizes business risk. Our platform and applications integrate...  ...Modeling: Review technical designs for new features, leading threat models to prioritize risks and educate developer teams... 
    Local area
    Remote work
    Worldwide
    Flexible hours

    DataRobot

    United States
    2 days ago
  • $500 per month

     ...Product Security Engineer Netherlands (remote) About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the...  ...that has grown over 250 percent year over year, ClickHouse leads the market in real-time analytics, data warehousing, observability... 
    Local area
    Remote work
    Home office
    Flexible hours

    ClickHouse

    United States
    3 days ago
  • $168k - $210k

     ...Joining Collibra's Product Security team Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product... 
    Work experience placement
    Remote work
    Flexible hours

    Collibra

    United States
    4 days ago
  • £60k - £75k per year

     ...Product Security Engineer As a Product Security Engineer, you'll embed security into the software development lifecycle across multiple product teams. You'll help teams build, ship, and operate secure software by defining requirements, improving detection and prevention... 
    Flexible hours
    1 day per week

    Redgate

    United States
    1 day ago
  • $96k - $132k

     ...will find purpose and pride. Your role at Baxter At Baxter Healthcare Corporation, we invite a driven Senior Product Security Engineer who is passionate about contributing to healthcare improvements. This opportunity puts you on the frontline of... 
    Temporary work
    Local area
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Baxter

    United States
    3 days ago
  •  ...Senior Product Security Engineer Join Guidewire as a Senior Product Security Engineer and be a key technical expert responsible for shaping the security architecture of our industry-leading SaaS platforms. At Guidewire, security is not a checkbox—it is a foundational... 
    Remote work

    Guidewire

    United States
    1 day ago
  • $30 - $50 per hour

     ...Role Overview As a Product Security Engineer, you will embed security into the software lifecycle for platforms that handle AI/ML data operations...  ...practices across engineering teams and delivery pipelines Lead threat modeling and security design reviews for new features... 
    Hourly pay
    Remote work

    Rex USA

    Richmond, VA
    2 days ago
  • $152k - $224k

     ...to the ones they love. Our category-leading mobile app,Tile tracking devices,...  ...About The Team The Information Security and Technology team is responsible...  ...programs. We build things that work in production, earn adoption from engineering teams, and get better over time -... 
    Summer work
    Remote work
    Flexible hours

    Life360

    United States
    4 days ago
  •  ...Experienced Product Security Engineer We believe that the way people interact with their finances will drastically improve in the next few years...  .... By leveraging your deep industry knowledge, you'll lead the charge in implementing secure architecture and design principles... 
    Work experience placement
    Local area
    Remote work

    Plaid

    United States
    2 days ago
  • $150k - $200k

     ...Senior Product Security Engineer Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm values information security as a critical part of... 
    Remote work

    Affirm

    United States
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Product Security Engineer. Be the first to apply!