Product Security Engineer
Jobleads-US
Build a Safer World.
TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
About the Team
The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.
The impact you will have here:
- Lead application security reviews and threat modeling, including secure code review, architectural design, and testing
- Develop automated testing and mature our Secure SDLC
- Own and perform application security vulnerability management
- Coordinate penetration testing engagements
- Support software engineers and product teams by developing application security best practices
- Develop and maintain the bug bounty program
- Bootstrap platform security initiatives that help protect TRM data
- Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.
What we’re looking for:
- Minimum 8 years of experience in Software Development and testing.
- BS (or equivalent) in Computer Science, Computer Engineering, or related field.
- Proficiency in software development languages: Python, NodeJS, React
- Strong understanding of encryption, authentication, and authorization protocols
- Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.
- Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.
- Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis
- Experience triaging and remediating vulnerabilities in software packages or libraries
- Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools
- Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.
- Experience with Threat modeling tools such as OWASP Threat Dragon, etc.
- Experience working in a previous agile-based software development role required
- Experience Red Teaming or penetration testing applications and infrastructure
- Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.
- Strong written and verbal communication skills.
- Security certifications such as OSCP, CEH, GWAPT are a plus.
- Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus
About the Team:
- The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.
- We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.
- Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.
- Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.
Team’s Time Zones:
- Eastern Standard Time (EST - GMT-4)
- Pacific Standard Time (PST - GMT-7)
- Central European Summer Time (CET - GMT+2)
Learn about TRM Speed in this position:
- Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.
- Integrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.
- Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.
- Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.
Work Week Travel: This role requires participation in in-person R&D work weeks, typically 1–2 times per quarter, at a TRM hub or other designated location. Work weeks may be scheduled with as little as 14 days’ notice, and some roles may require additional travel based on team and cross-functional needs. TRM coordinates and covers approved travel, lodging, and workspace. Accommodations are available for legitimate caregiving, health, immigration, and similar constraints.
What to Expect From Our Interview Process
Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.
- Recruiter Intro: Explore your experience, motivations, and alignment with the role.
- Hiring Manager: Dive deeper into your relevant experience, skills, and impact.
- First Round: Typically 1–2 interviews focused on the skills most critical to the role.
- Final Round: Meet some of the people you'd be working with. This is usually a panel-style session where we go deeper on your craft, problem-solving, and alignment with TRM.
- References: We’ll speak with former colleagues who can provide perspective on your work and impact.
- Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.
- Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.
Your recruiter will share your specific interview plan and preparation guidance along the way.
Learn more about interviewing at TRM
Life at TRM
We are building a safer world. That promise shows up in how we work every day.
TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.
Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.
At TRM, you should expect:
- Priorities and targets to change quickly as we experiment and iterate
- Work that often requires operating with a high degree of ambiguity
- A high level of personal ownership and accountability
- Close collaboration across teams and functions
- Frequent, high-touch communication
- Creative problem solving and out-of-the-box thinking
- A pace that rewards urgency, adaptability, and outcomes
This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.
We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.
At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more about Interviewing at TRM
AI Fluency at TRM
AI fluency is a baseline expectation at TRM.
We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.
At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:
- Accelerate repeatable workflows
- Structure and solve problems
- Improve output quality
- Increase speed and leverage
You will be evaluated on applied AI fluency during the interview process.
Leadership Principles
We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.
- Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.
- Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday.
- Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset — giving and receiving feedback to make the team stronger.
Join our Mission
At TRM, we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.
TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Learn more about building tools for defenders
Privacy Policy and Additional Information
By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy.
We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.
Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at View email address on click.appcast.io.
To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form.
Recruitment agencies
TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.
Learn More : Company Values | Interviewing | FAQs
#J-18808-Ljbffr Jobleads-US$175k - $215k
...and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures...SuggestedTemporary work$117.2k - $176.7k
...the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.Job Title: Product Security Engineer, InfrastructureJob Category: Technology / SecurityLocation: San Francisco, CA or Bellevue, WAThe ExperienceJoin our...SuggestedFull time$208k - $312k
...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.Now,... ...background is manual penetration testing. A software engineer with a strong desire to move into security,...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$188k - $282k
...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re... ...re just getting started.Role OverviewAs a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity to build...SuggestedWork experience placementFlexible hours$160k - $250k
...financial operations or build and monetize financial products of their own.We started in Melbourne in 2015 to build... ...see it in full.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data...SuggestedTemporary workLocal area$180k - $258k
...infrastructure from the ground up.Our core product is an autonomous Revenue Cycle Management... ...by AI agents and a configurable rules engine, the platform unifies clinical, billing,... ...Role OverviewWe are looking for a Product Security Engineer to join our team and act as a champion...Shift work$192k - $240k
...architecture, tools, processes, and culture that keep security risk very low while working hands-on with the team to ship product features quickly.At Datadog, we place value... ...through production operation.Work with engineering, product, infrastructure, and security teams...Work at office- ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on DataRobot... ...in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform meets...Full timeLocal areaRemote workWorldwideFlexible hours
- ...communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security challenges, but our...Work at officeRelocation3 days per week1 day per week
$250k - $285k
...of a high-performing team that believes in each other, come build with us at Crusoe.About This RoleWe’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and distributed...Temporary work$172.5k - $313.7k
...right place! Agentforce is the future of AI, and you are the future of Salesforce.Job Title: Principal Engineer, Product SecurityThe ExperienceThe Product Security team sits within Trust & Security, partnering closely with engineering across Salesforce's fastest-growing...Full time$231.9k - $318.25k
...Work as a hands-on Product Security Engineer to make secure outcomes the default across the codebase and delivery workflow. Responsibilities Identify systemic security gaps in the codebase and engineering workflows, then partner with engineering teams to design and...- ...Senior Product Security Engineer At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray, a popular open-source project that's creating an ecosystem of libraries...Flexible hours
$227k - $296k
...deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprises. We're hiring a...Full timeWork at officeWork from homeVisa sponsorshipRelocation packageFlexible hours- ...Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and...Full time
- ...and other critical infrastructure that developers need to securely scale their products to large organizations.We recently raised a $100M Series... ...success.We are a highly collaborative group with a strong engineering mindset. Our security program is shaped by hands-on...Work experience placementRemote work
$160k - $250k
...financial operations or build and monetize financial products of their own.We started in Melbourne in 2015 to build... ...see it in full.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data...Temporary workLocal area- ...tenant isolation, and the blast radius of a single agent action product design questions, and it puts product security on the critical path of every enterprise deal we close. We are looking for the engineer who owns that. This is a hands-on role and the first dedicated...Work at officeFlexible hours
$130k - $215k
...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers... ...Snowpoint, and employs a team of 500 engineers and entrepreneurs. Astranis designs, builds... ...in Northern California, USA. Product Security Engineer As a Product Security...Permanent employmentFlexible hours$175k - $200k
...Doppel is building the future of social engineering defense. Our AI-native platform uses agentic... ..., Human Risk Management and Email Security, Doppel connects threats into a real-time... ...customers and teammates. We’re looking for a Product Security Engineer to support and scale...Work at officeImmediate startRemote workFlexible hours- ...identity verification infrastructure where security isn't a layer we add later, it's core to... .... As AI tooling expands what engineers can build and how fast they can build it... ...that scale security across every team and product. Partner with product engineers to shape...Full timeFor contractorsInternshipRelocation package
$172.5k - $313.7k
...Job Category Product Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer... ...are the future of Salesforce. Job Title: Principal Engineer, Product Security The Experience The Product Security team sits within...$235k - $275k
...Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00...Full time$50 per hour
...computational biology. About This Role Crusoe Security & Compliance is hiring a Senior/Staff Application Security Engineer to play a critical role in ensuring the... ...improvement of our security posture, making our products safer and our customers' data more secure....Temporary work- ...WorkOS’s Security team secures data and identities for hundreds of millions of users, partnering with engineering on secure design and rapid risk reduction. We balance offensive testing... ...embraces AI to scale security across products, while maintaining a strong focus on customer...Remote job
- ...Cybersecurity Jobs is seeking a hands-on Product Security Engineer in San Francisco to make secure outcomes the default across the codebase and delivery workflow. You will identify security gaps, build tooling, and lead threat modeling for new features. You’ll review...
$231.9k - $318.25k
...risk of shipping ungoverned software into production grows just as fast. At Retool, we're... ...they write and execute arbitrary code. The security surface that comes with that is large,... ...’re looking for an Application Security Engineer who combines deep security fundamentals...Shift work- ...60k - $225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A funding, and...Full time
- ...Rippling is seeking a hands-on staff security engineer to help build and lead Rippling's Product Security program. You’ll own critical security initiatives, mentor engineers, and shape security practices across the development lifecycle. The role focuses on securing...
- ...Harvey is building AI-native software for professional services, embedding security across the engineering org. You will lead a team of Product Security Engineers, translating security strategy into focused priorities and measurable outcomes. Reporting to the Senior...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Engineer. Be the first to apply!
- entry level product engineer San Francisco, CA
- senior manager product engineering San Francisco, CA
- product design engineer San Francisco, CA
- digital design engineer San Francisco, CA
- product engineering intern San Francisco, CA
- sr. product engineer San Francisco, CA
- staff design engineer San Francisco, CA
- senior product design engineer San Francisco, CA
- rtl design engineer San Francisco, CA
- entry level design engineer San Francisco, CA


