Staff Product Security Engineer
$174.2k - $293.7kSailPoint
Staff Product Security Engineer
Overview
SailPoint’s Cybersecurity organization is seeking a Staff Product Security Engineer with a passion for cybersecurity and protecting the organization. The ideal candidate combines strong application security expertise with practical software engineering experience and can effectively influence to build secure, resilient products at scale. This position reports to the Director of Cyber Product Security (CPS) and the successful candidate will join a team of security engineers who collaborate with stakeholders across the organization. This role will partner closely with Engineering and the other security teams within the Cyber organization to identify security risks, drive remediation efforts, and embed security throughout the product development process.
Central to SailPoint’s product security program is the implementation of a shared security model that impacts all software developed by SailPoint. Under this model, CPS is responsible for multiple key areas affecting product security and collaborates with SailPoint's Engineering Product Security (EPS) team on areas of mutual responsibility. The shared responsibility model was developed to shift product security left, moving security checks to the earliest phases of our secure software development lifecycle.
The staff product security engineer will have the opportunity to shape our future through process and technology optimization, capability acquisition and development, and maturation of our existing activities. They’ll already be comfortable with the 4 I’s at SailPoint (individual, Impact, Innovation, and Integrity) even if they’re new to the concept. They will embrace new challenges and will be a positive contributor to an already positive work culture and environment.
Location is remote with the ability to work from anywhere within the continental United States.
Key Responsibilities
Partner with Engineering teams throughout the software development lifecycle to identify and mitigate security risks, and implement secure deployment practices
Support threat modeling activities and help engineering teams implement appropriate security controls
Define and promote secure coding standards, security policies, best practices, and secure-by-design principles
Participate in the Cyber organization’s efforts to leverage AI across the team, as well as the use of AI in our SSDLC.
Partner with Engineering on improving security testing programs
Coordinate internal and external application and penetration testing initiatives
Validate vulnerability findings and prioritize remediation based on risk
Perform root cause analysis and recommend long-term security improvements
Collaborate with the Security Operations team on security monitoring and detection capabilities for applications and services
Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty program
Develop security training, guidance, and technical documentation
Interact with other organizations at SailPoint as a consultant on security-related matters
Required Qualifications
Successful candidate will meet most, if not all of the following requirements:
5-7 years of experience in product security, application security, software engineering, or a related field
Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners
Experience with CI/CD security controls and DevSecOps practices
Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby
Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts
Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows
Deep expertise in threat modeling, secure architecture design, and vulnerability management
Experience influencing engineering organizations and driving security initiatives across multiple teams
Knowledge of artificial intelligence software security frameworks is strongly preferred, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework.
Core Competencies
The successful candidate will:
Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues
Have a continuous learning mindset and passion for security
Have strong analytical and problem-solving skills
Be flexible, with the ability to balance security vs the needs of the business
Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation
Be able to translate technical risks into business impact
Be collaborative and able to foster relationships with teams we partner with
First 90 Days: Discovery, Strategic Alignment, and Partnership
Strategic Alignment & Planning Integration: Deepen collaboration with key engineering and tooling leads by Day 90, reinforcing recurring touchpoints to integrate product security proactively into early planning cycles, roadmaps, and feature designs.
SDLC Optimization Assessment: Review the end-to-end Software Development Life Cycle (SDLC) by Day 60 to identify enhancement opportunities, accelerate "shift-left" practices, and further standardize secure-by-design deployment pipelines.
Asset & Dependency Inventory: Refine and centralize the inventory of supported products, underlying architecture, and third-party dependencies by Day 90 to deliver a highly visible, comprehensive single source of truth.
First 6 Months: Advanced Tooling, Training, and Scalable Frameworks
Modernizing Tool Stack & AI Integration (Q3): Evaluate the current security tooling and implement state-of-the-art AI-assisted scanning across product code (utilizing tools like Cursor and Claude Enterprise) to further automate and scale security workflows.
Optimized Remediation & Board Metrics (Q4): Implement a highly scalable, risk-based vulnerability prioritization framework, optimizing Time to Remediate (TTR) metrics to provide clear, actionable risk visibility for executive leadership and the Board.
Security Champions & Developer Empowerment: Elevate developer security education and launch a formal "Security Champions" program by Day 180, embedding security advocates across core product lines to champion secure development practices.
First 12 Months: Systemic Security Advancements and "Paved Roads"
Systemic Architecture Enhancements: Conduct comprehensive reviews of the production environment (including Kubernetes and containerized applications) to systematically address complex architectural security opportunities and build long-term environment resilience.
Standardizing "Paved Road" Configurations: Define, document, and roll out standardized, secure "paved road" configurations and guardrails, making secure deployment the friction-free path of least resistance for product teams.
Program Scaling & Mentorship: Maintain and scale updated product architecture documentation while continuously elevating team capabilities, autonomy, and cross-functional alignment through active, hands-on mentorship.
Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.
As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-max, USD):
$174,200 - $293,702.00Base salaries for employees based in other locations are competitive for the employee’s home location.
Benefits Overview
1. Health and wellness coverage: Medical, dental, and vision insurance
2. Disability coverage: Short-term and long-term disability
3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)
4. Additional life coverage options: Supplemental life insurance for employees, spouses, and children
5. Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account
6. Financial security: 401(k) Savings and Investment Plan with company matching
7. Time off benefits: Flexible vacation policy
8. Holidays: 8 paid holidays annually
9. Sick leave
10. Parental support: Paid parental leave
11. Employee Assistance Program (EAP) and Care Counselors
12. Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options
13. Health Savings Account (HSA) with employer contribution
SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law.
Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact View email address on us.fitly.work or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations. NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.
$106k - $209k
...The MongoDB Product Security organization is a diverse collection of individuals working together to scale MongoDB’s security, both security... ...MongoDB Product Security organization works with software engineers to design, implement, and operate systems in a manner that...SuggestedFull timeWork at officeLocal areaRemote workWorldwideFlexible hours$100k - $125k
Aras is a leader in product lifecycle management (PLM) and digital thread solutions. As one of the fastest growing PLM companies,... ...aerospace and defense, and high-tech electronics. As a Product Security Engineer specializing in our Security Operations Center (SOC) for...SuggestedTemporary workFlexible hours$122.8k - $184.2k
...locally and globally. Come make an impact every day at Zebra.What We're Looking For:The Advanced Engineer Security, as an integral part of the Advanced Data Capture (ADC) product security team, is responsible to ensure that a Secure Development Lifecycle (SDLC) is defined,...SuggestedFull timeSummer workWork at officeLocal areaFlexible hours$122.8k - $184.2k
...toward causes you care about—locally and globally. Come make an impact every day at Zebra.What We're Looking For:Advanced Product Security Engineer for the Print and Encode business unit, reporting to the Director of Systems Engineering. The Product Security Engineer is...SuggestedFull timeSummer workWork at officeLocal areaFlexible hours$208k - $312k
...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now... ...is manual penetration testing. A software engineer with a strong desire to move into security, or...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$165k - $200k
Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is the leading family fintech company on a mission to help parents... ...on it.We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. This individual will be...Full timeWork at officeLocal areaRemote workWork from homeFlexible hoursDay shift- ...Role Overview Design and build AI-native security capabilities that embed directly into... ..., machine learning, and developer productivity, leading the evolution of a security platform... ...from finance, healthcare, STEM engineering, and other fields into high quality training...Full timeRemote work
$180k - $270k
...Requirements: We require a bachelors degree in Engineering, Computer Science, or a related discipline, plus 6+ years of experience in Security Engineering or a similar role, or a... ...such as Ghidra, IDA, or Binary Ninja Product security incident response in mobile, IoT...Full timeWork from home$208k - $312k
...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now... ...: We are looking for a Product Security Engineer to join our security team to drive critical product...Full timeWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...Product Security Engineer We are seeking a Product Security Engineer to join our team and lead the implementation of enterprise security strategies across our orthopedic medical device portfolio. This position plays a key role in both pre-market and post-market product...Remote work
$154k - $210k
...Job Description Job Description Description: Position Overview We are seeking a Product Security Engineer to own product-level security across OKSI's hardware and software systems. You will define and maintain the policies, standards, and architectural practices...Permanent employmentWork at officeRemote work- ...experiences; and dramatic increases in productivity. Leading organizations including American... ..., Stryker, The United States Social Security Administration, The United States... ...documents. As a Senior Product Security Engineer, you will be the cornerstone of our product...Remote workWork from homeFlexible hours
$170k - $200k
...Product Security Engineer Movable Ink - Remote (U.S. - EST) Movable Ink scales content personalization for marketers through data-activated content generation and AI decisioning. The world's most innovative brands rely on Movable Ink to maximize revenue, simplify workflow...Remote work- ...manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and... ...moving forward. Job Description Sandisk’s Product Security Engineering & Assurance (PSEA) organization is seeking highly motivated...Temporary workRemote workFlexible hoursShift work
- ...Product Security Engineer As a Product Security Engineer at FAIRTIQ, you will play a pivotal role in enhancing and evolving our cybersecurity program, with a particular emphasis on application security. Working as part of a small, dynamic team, you will design, implement...Remote workFlexible hours
$74.16 - $92.7 per hour
...Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave eligibility is contingent...Permanent employmentFull timeContract workRemote work- ...CrowdStrike, Inc. is seeking a Senior Product Security Engineer to dive into our endpoint products, identify design and implementation flaws, and help engineers ship secure code. If you enjoy dissecting Linux applications to uncover security gaps, we want to hear from...Remote work
$169.15k - $191.25k
...Product Security Engineer United States (remote) About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 3,000 customers and ARR that has grown over 250 percent...Local areaRemote workHome officeFlexible hours$169.15k - $191.25k
...Come be a part of our journey! About the team The Security Team is responsible for providing key security capabilities... ...security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms...Local areaRemote workHome officeFlexible hours- ...mission is to leverage data science, smart product design and personalization to make... ...smart product design and personalization to securely make healthcare more affordable and... ...efficiently and safely. As a Product Security Engineer at Cedar, you will work with an...Hourly payFull timeWork at officeRemote workWork from homeFlexible hours
$168k - $210k
...Joining Collibra's Product Security team Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product...Work experience placementRemote workFlexible hours$161k - $242k
...Category Engineering Hire Type Employee Job ID 17542 Base Salary Range $161000-$242000 Remote... ...You are a strategic and technically adept security professional, passionate about embedding security into every stage of product development. You thrive in dynamic,...Remote work$119.3k - $140.4k
...from you! The Role Maintaining the security and privacy of our users is paramount to... ...This is a unique opportunity to use your engineering and security skills to make a direct... ...posture. This role will be part of the Product Security (ProdSec) team, report to the Head...Full timeRemote workWork from homeFlexible hours- ...Product Security Engineer DataRobot delivers AI that maximizes impact and minimizes business risk. Our platform and applications integrate into... ...when to escalate architectural decisions to Senior and Staff engineers. Strategic Mindset: Experience determining not...Local areaRemote workWorldwideFlexible hours
- ...Affirm is seeking an early-career Application Security Engineer to help assess application risks, support vulnerability management, and collaborate with engineering teams to design secure systems. You will read code, contribute lightweight tooling, review pull requests...Remote work
- ...Product Security Engineer Sea Machines is a fast-growing startup that is leading the new high-tech sector of autonomous technology for marine vessels. We are passionate about applying practical A.I. to the massive global ocean transportation market. Our products provide...Full timeRemote workFlexible hours
$108.24k - $151.48k
...your work location, balancing what your work requires. What's in it for you: The Residential HVAC team is adding a Product Security Engineering position to focus on embedded systems, services, applications and the associated product development processes used in...Hourly payLocal areaWork from home- ...identity verification infrastructure where security isn't a layer we add later, it's core to... .... As AI tooling expands what engineers can build and how fast they can build it... .... What you'll work on This is a product security role embedded in a generalist security...Full timeFor contractorsInternshipRelocation package
- ...financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role: We're hiring a Product Security Engineer to build Collective's application security program - with AI agents at the center of it from day one. This is not a legacy...Self employmentWork at officeRemote workFlexible hours
$137.86k - $250k
...safely creating abundance for all. About the Team The Security Engineering team is responsible for protecting our robots,... ...how we build and operate humanoid robotics systems. The Product Security team focuses on the end-to-end security of NEO itself...Temporary workLocal areaRemote workWork from homeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!


