Staff Application & Product Security Engineer
$160k - $180kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application & Product Security Engineer based in United States.
This Staff-level individual contributor role owns application and product security across both SaaS and customer-hosted products.
You will shape how security is embedded throughout the software development lifecycle, from architecture and threat modeling through release and remediation.
The role combines hands-on engineering with program ownership, allowing you to establish standards, build automated guardrails, and influence security decisions across engineering teams.
You will partner closely with Engineering, Product, Architecture, Cloud Security, and executive leadership to strengthen the security posture of shipped products.
A major focus will be vulnerability management, secure development practices, customer-facing product security, and security enablement for developers.
You will also lead emerging AI security efforts, establishing practical controls for LLM-enabled features, AI agents, and AI-assisted development workflows.
This is an opportunity to make high-impact technical decisions while creating scalable security programs, automation, and processes that support a growing product organization.
Accountabilities:
- Own and continuously mature the secure software development lifecycle, including security requirements, threat modeling, design reviews, and security controls for high-risk product changes, APIs, and integrations.
- Run and optimize SAST, SCA, secrets detection, container, and infrastructure-as-code scanning across development and CI/CD environments.
- Build reusable secure patterns, reference implementations, and policy-as-code controls that make secure development practices easier for engineering teams to adopt.
- Lead developer security enablement through Security Champions programs, training campaigns, remediation guidance, office hours, and self-service security capabilities.
- Manage application and product vulnerabilities through risk-based triage, remediation SLAs, escalations, exceptions, exploit reproduction, patch validation, and release verification.
- Own the penetration testing program, including scoping third-party engagements, performing targeted testing, coordinating remediation, and validating findings through retesting.
- Manage the Vulnerability Disclosure Program and coordinate communications with external researchers, customers, and other stakeholders through coordinated disclosure processes.
- Coordinate the CVE lifecycle for products and support product-security incident response activities.
- Own application and product-security controls within the NIST CSF 2.0 program, tracking maturity, closing gaps, and producing audit evidence.
- Establish and maintain the security posture of products across SaaS and customer-hosted environments, including secure defaults, authentication, session controls, RBAC, tenant isolation, administrative access, configuration security, and hardening guidance.
- Own the Product Security Roadmap in partnership with Product Management, Technology leadership, and Architecture, ensuring priority security capabilities are incorporated into product development.
- Serve as the technical owner for customer-facing product security, including reviewing vulnerability scans and penetration-test reports, responding to security RFIs and enhancement requests, and preparing security advisories, release notes, and hardening documentation.
- Lead threat modeling and security reviews for LLM-enabled product features, AI agents, and AI-assisted development workflows.
- Develop security controls and secure patterns addressing prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply-chain risks.
- Apply and operationalize relevant AI security frameworks and guidance, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.
Requirements:
- 6+ years of experience in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams.
- Strong software development capabilities in an object-oriented programming language, with Java experience preferred; ability to read, debug, and write production-quality code and work across languages such as TypeScript, Python, or Go.
- Deep understanding of modern application attack surfaces, including authentication, authorization, API security, business-logic vulnerabilities, and contemporary service architectures.
- Hands-on experience integrating and tuning SAST, SCA, and secrets scanning within GitHub and CI/CD pipelines.
- Demonstrated ability to reproduce security exploits against running applications, validate patches, and translate technical findings into actionable guidance for both researchers and customers.
- Experience coordinating vulnerability disclosure with external security researchers and customers, including managing disclosure timelines and driving CVEs through publication.
- Experience securing shipped software with an established customer base, including secure defaults, hardening guidance, customer advisories, security release notes, and responses to customer scan reports or security RFIs.
- Practical experience with threat modeling, architecture and design reviews, manual security testing, and direct collaboration with developers throughout remediation.
- Strong communication skills and the ability to translate complex technical risks into clear engineering guidance for developers and concise risk assessments for executives.
- Confidence making and defending release-gating security decisions when risk levels warrant escalation.
- Experience with AI application security, AI agents, or AI-assisted development tools is preferred.
- Familiarity with SBOM standards such as CycloneDX or SPDX, VEX, artifact signing, and SLSA is a plus.
- Experience with AWS, Kubernetes/EKS, Terraform, or Jenkins is beneficial.
- Familiarity with security tools such as Snyk, GitHub Advanced Security, Semgrep, and Burp Suite is preferred.
- Knowledge of NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, and security audit frameworks such as SOC 2 or ISO 27001 is advantageous.
- Security certifications such as CSSLP, OSWE, GWAPT, AWS Security, or comparable credentials are a plus.
- Experience with enterprise software supporting both SaaS and customer-hosted deployment models, including SSO/SAML, RBAC, multi-tenant isolation, MFT/EDI, or other B2B integration products, is beneficial.
Benefits:
- $160,000–$180,000 base compensation plus bonus opportunity.
- Healthcare, dental, and vision coverage.
- Flexible paid time off.
- Culture focused on support and sustainable work-life balance.
- 401(k) with company match.
- Flexible Spending Account (FSA) and Health Savings Account (HSA) options.
- Employee Assistance Program.
- Paid parental leave.
- Remote work environment.
- Opportunity to contribute to products serving more than 4,000 clients with a 99% retention rate.
- Accelerated opportunities for title and salary growth.
- Energetic and collaborative work environment.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$117.2k - $176.7k
...future of AI, and you are the future of Salesforce.Job Title: Product Security Engineer, InfrastructureJob Category: Technology /... ...premises and in public cloud environments, including web applications, distributed systems, and virtualized infrastructures. You...ApplicationFull time- ...SaaS Product Security Engineer - Contracting role to start (Hybrid NYC) - Can convert to full-time down the road We are looking for a SaaS... ...product environment. What you’ll do: Harden SaaS applications, systems, and endpoints against security threats Work...ApplicationFull time
- ...Responsibilities Aedify and its customers are seeking a Product Security Engineer to support the Product Security Director and help deliver scalable product security capabilities across modern applications, APIs, cloud-native services, third-party products, desktop...ApplicationFull timeFor contractorsRemote work
$145k
...assets – our employees. Why This Role Matters As a Product Security Engineer at Group 1001, you will lead efforts to integrate... ...ensuring the security and integrity of our revenue-generating applications and systems from design to deployment. This role requires...Application- ...as required by business and on-call availabilityThe Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-... ...as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain...Application
- ...Job Title: Senior Product Security Engineer Location: Remote, United States Employment Type: Contract-to-Hire Workplace Type: Remote... ...into the software development lifecycle, strengthening application security processes, and partnering closely with Engineering...ApplicationContract workRemote workFlexible hours
$150k - $190k
DescriptionKforce's client in Boston, MA is seeking a Product Security Engineer.Summary:We're partnering with a highly respected global organization that is investing heavily in modern application security, cloud technologies, and secure software development practices....Application$188k - $282k
...true inflection point. We have strong product-market fit and world-class investor... ....Role OverviewAs a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity... ...of experience in product security, application security, offensive security, and/or...ApplicationWork experience placementFlexible hours$160k - $250k
...or build and monetize financial products of their own.We started in Melbourne... ...the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to... ...security of our networks, systems and applications.What you’ll be doingPartner with...ApplicationTemporary workLocal area$180k - $258k
...from the ground up.Our core product is an autonomous Revenue Cycle... ...agents and a configurable rules engine, the platform unifies... ...OverviewWe are looking for a Product Security Engineer to join our team and... ...on product security or application security.Technical Skills:Proficiency...ApplicationShift work$135.4k - $201.85k
...Our cloud-first networking and security solutions already protect 70%... ...anything, Be Infoblox.Senior Product Security EngineerWe are... ...for a Senior Product Security Engineer to join our Product Security... ...behaveSolid understanding of application and cloud security fundamentals...ApplicationTemporary workWork experience placementWork at officeFlexible hoursNight shift$110k - $130k
...StephensZachary Piper Solutions is seeking an experienced Product Security Engineer to support a leading aerospace and defense organization delivering... ..., vulnerabilities are remediated, and solutions meet applicable cybersecurity standards and controls.Responsibilities of...Application- ...Pharma GroupContact: ApplicationsEmail: applications@staffingfuture.comCan you please... ...required? Vulnerability Management, Security signal Analytics with automation/AI,... ...____________________________________ Product Security Engineer, Consultant - Job DescriptionPosition...Application
- ...possible, with the ultimate goal of enabling human life on Mars.PRODUCT SECURITY ENGINEER (STARLINK)At SpaceX we’re leveraging our experience in... ...:To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful,...ApplicationPermanent employmentWorldwideWeekend work
$175k - $215k
...someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be... ...building it, working closely with engineering teams, shipping production code,... ...experience with application security tooling (SAST, DAST, SCA...ApplicationTemporary work$123.5k - $169.85k
...transformation. Job DescriptionJoin the future of product security at BoseAt Bose, security and stability... ...innovation. We are seeking a Security Engineer to support the product security... ...processesEnsure compliance with applicable security regulations and standards (e....ApplicationFull time- ...with the ultimate goal of enabling human life on Mars.SR. PRODUCT SECURITY ENGINEER (STARLINK)At SpaceX we’re leveraging our experience in building... ...:To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful,...ApplicationPermanent employmentWorldwideFlexible hoursWeekend work
- ...breakthroughs, or bringing leading edge products to market, every role at AMD... ....THE ROLE: AMD responds to security incidents in collaboration... ...for an experienced software engineer who will be responsible for... ...and will consider all applicants without regard to age, ancestry...ApplicationWork at office
$140.3k - $233.8k
...We are known for delivering insights, products, and services that make quality care more... ...is seeking a Senior Product Security Engineer, AI & DevSecOps to embed security throughout... ...software developer who understands how applications are designed, written, deployed, and operated...ApplicationFull timeH1bRemote work$208k - $312k
..., v0, and AI SDK, we create products that help builders move from... ...idea to production with speed, security, and exceptional developer... ...testing. A software engineer with a strong desire to move... ...platforms where customer-built applications run on shared infrastructure...ApplicationWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- Join Hologic's mission to drive a Secure by Design culture within our... ...Skeletal Health Connected Health products. As a Senior Product Security Engineer, you will play a pivotal role in... ...Linux operating systemsSoftware application testing and maintenanceCybersecurity...ApplicationRemote work
$198.4k - $342k
We are seeking a highly technical Product Security Engineer to join our Public Sector Infrastructure & Security team. Our Product Security Engineers... ...pipelines with a strong focus on security.Perform Static Application Security Testing (SAST) and Dynamic Application Security...ApplicationFull time$130.5k - $193.6k
...shopping simple, personalized, and secure, PayPal empowers consumers... ...and Venmo branded credit products, a credit card, a debit card,... ...As a Senior Product Security Engineer at PayPal, you'll help secure... ...experience in software engineering, application or product security,...ApplicationFull timeWork at officeLocal areaImmediate startFlexible hours$156k - $253k
...military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your technical... ...focus on platform security, or has pivoted to a product or application security role. They will be able to conduct complex security...ApplicationFull timeWork experience placementImmediate start$225k - $300k
CLEAR is building THE secure identity company of the future. Our mission is to make... ...experiences.We are seeking a Senior Product Security Engineer to serve as a technical leader and... ...will drive the evolution of CLEAR’s application security posture by influencing architecture...ApplicationCasual workWork at officeFlexible hours$132k - $198k
We anticipate the application window for this opening will close on - 12 Oct 2026Careers... ...collaboration as we work together to engineer the extraordinary.Medtronic Cardiac Ablation... ...Solutions (CAS) is seeking a Senior Product Security Engineer to join our R&D organization...ApplicationFull timeH1bWork at officeLocal areaImmediate startFlexible hours$132k - $198k
We anticipate the application window for this opening will close on - 5 Oct 2026Careers... ...breadth of our talent, technologies, products, services, and solutions to address the... ...retention, and much more.The Senior Product Security Engineer - Embedded IoT is responsible for...ApplicationFull timeH1bWork at officeLocal areaImmediate startRemote workFlexible hours$180k
...for. About The Role: YipitData is looking for a Product Security Engineer to help build security into the products and services we... ...a hands-on role for someone who understands how modern applications are designed and built. You should be comfortable reviewing...ApplicationWork at officeRemote workFlexible hours$168.2k - $310.1k
The OpportunityAt Adobe, securing the future of creativity is... ...Our customers rely on our products every day to transform ideas... ...depend on.We seek a Staff Product Security Engineer to act as a Security Partner... ...need to succeed10+ years in Application or Product Security and a...ApplicationFull timeTemporary workLocal areaWorldwide- ...addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope... ...Product Security lead talked about the Future Application Security EngineersOur Security Engineering...ApplicationWork at officeRelocation3 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Application & Product Security Engineer. Be the first to apply!
- assistant engineer United States
- staff automation engineer United States
- senior staff systems engineer United States
- technology administrator United States
- engineering aide United States
- senior staff engineer United States
- staff qa engineer United States
- assistant building engineer United States
- staff design engineer United States
- assistant project engineer United States


