Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Product Security Engineer

$174.2k - $293.7k

SailPoint Technologies

Staff Product Security Engineer

SailPoint's Cybersecurity organization is seeking a Staff Product Security Engineer with a passion for cybersecurity and protecting the organization. The ideal candidate combines strong application security expertise with practical software engineering experience and can effectively influence to build secure, resilient products at scale. This position reports to the Director of Cyber Product Security (CPS) and the successful candidate will join a team of security engineers who collaborate with stakeholders across the organization. This role will partner closely with Engineering and the other security teams within the Cyber organization to identify security risks, drive remediation efforts, and embed security throughout the product development process.

Central to SailPoint's product security program is the implementation of a shared security model that impacts all software developed by SailPoint. Under this model, CPS is responsible for multiple key areas affecting product security and collaborates with SailPoint's Engineering Product Security (EPS) team on areas of mutual responsibility. The shared responsibility model was developed to shift product security left, moving security checks to the earliest phases of our secure software development lifecycle.

The staff product security engineer will have the opportunity to shape our future through process and technology optimization, capability acquisition and development, and maturation of our existing activities. They'll already be comfortable with the 4 I's at SailPoint (individual, Impact, Innovation, and Integrity) even if they're new to the concept. They will embrace new challenges and will be a positive contributor to an already positive work culture and environment.

Location is remote with the ability to work from anywhere within the continental United States.

Key Responsibilities
  • Partner with Engineering teams throughout the software development lifecycle to identify and mitigate security risks, and implement secure deployment practices
  • Support threat modeling activities and help engineering teams implement appropriate security controls
  • Define and promote secure coding standards, security policies, best practices, and secure-by-design principles
  • Participate in the Cyber organization's efforts to leverage AI across the team, as well as the use of AI in our SSDLC.
  • Partner with Engineering on improving security testing programs
  • Coordinate internal and external application and penetration testing initiatives
  • Validate vulnerability findings and prioritize remediation based on risk
  • Perform root cause analysis and recommend long-term security improvements
  • Collaborate with the Security Operations team on security monitoring and detection capabilities for applications and services
  • Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty program
  • Develop security training, guidance, and technical documentation
  • Interact with other organizations at SailPoint as a consultant on security-related matters
Required Qualifications

Successful candidate will meet most, if not all of the following requirements:

  • 5-7 years of experience in product security, application security, software engineering, or a related field
  • Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners
  • Experience with CI/CD security controls and DevSecOps practices
  • Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby
  • Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts
  • Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows
  • Deep expertise in threat modeling, secure architecture design, and vulnerability management
  • Experience influencing engineering organizations and driving security initiatives across multiple teams
  • Knowledge of artificial intelligence software security frameworks is strongly preferred, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework.
Core Competencies

The successful candidate will:

  • Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues
  • Have a continuous learning mindset and passion for security
  • Have strong analytical and problem-solving skills
  • Be flexible, with the ability to balance security vs the needs of the business
  • Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation
  • Be able to translate technical risks into business impact
  • Be collaborative and able to foster relationships with teams we partner with
First 90 Days: Discovery, Strategic Alignment, and Partnership
  • Strategic Alignment & Planning Integration: Deepen collaboration with key engineering and tooling leads by Day 90, reinforcing recurring touchpoints to integrate product security proactively into early planning cycles, roadmaps, and feature designs.
  • SDLC Optimization Assessment: Review the end-to-end Software Development Life Cycle (SDLC) by Day 60 to identify enhancement opportunities, accelerate "shift-left" practices, and further standardize secure-by-design deployment pipelines.
  • Asset & Dependency Inventory: Refine and centralize the inventory of supported products, underlying architecture, and third-party dependencies by Day 90 to deliver a highly visible, comprehensive single source of truth.
First 6 Months: Advanced Tooling, Training, and Scalable Frameworks
  • Modernizing Tool Stack & AI Integration (Q3): Evaluate the current security tooling and implement state-of-the-art AI-assisted scanning across product code (utilizing tools like Cursor and Claude Enterprise) to further automate and scale security workflows.
  • Optimized Remediation & Board Metrics (Q4): Implement a highly scalable, risk-based vulnerability prioritization framework, optimizing Time to Remediate (TTR) metrics to provide clear, actionable risk visibility for executive leadership and the Board.
  • Security Champions & Developer Empowerment: Elevate developer security education and launch a formal "Security Champions" program by Day 180, embedding security advocates across core product lines to champion secure development practices.
First 12 Months: Systemic Security Advancements and "Paved Roads"
  • Systemic Architecture Enhancements: Conduct comprehensive reviews of the production environment (including Kubernetes and containerized applications) to systematically address complex architectural security opportunities and build long-term environment resilience.
  • Standardizing "Paved Road" Configurations: Define, document, and roll out standardized, secure "paved road" configurations and guardrails, making secure deployment the friction-free path of least resistance for product teams.
  • Program Scaling & Mentorship: Maintain and scale updated product architecture documentation while continuously elevating team capabilities, autonomy, and cross-functional alignment through active, hands-on mentorship.

Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.

As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint's differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-mid-max, USD):

$174,200 - $293,702.00

Base salaries for employees based in other locations are competitive for the employee's home location.

Benefits Overview

  • Health and wellness coverage: Medical, dental, and vision insurance
  • Disability coverage: Short-term and long-term disability
  • Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)
  • Additional life coverage options: Supplemental life insurance for employees, spouses, and children
  • Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account
  • Financial security: 401(k) Savings and Investment Plan with company matching
  • Time off benefits: Flexible vacation policy
  • Holidays: 8 paid holidays annually
  • Sick leave
  • Parental support: Paid parental leave
  • Employee
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Product Security Engineer in United States vacancy
  • $169.15k - $191.25k

     ...data. Come be a part of our journey! About the team The Security Team is responsible for providing key security capabilities...  ...processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and... 
    Suggested
    Full time
    Local area
    Remote work
    Home office
    Flexible hours

    ClickHouse

    United States
    20 hours ago
  • $106k - $209k

    Want to secure the future of data management and AI/ML? At MongoDB we are transforming...  ...America. Who You Are With a strong security engineering background, you’re looking for a role...  ...customers by strengthening our core database products. You’re passionate about solving hard... 
    Suggested
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    MongoDB

    New York, NY
    1 day ago
  •  ...Product Security Engineer VARITE is looking for qualified Product Security Engineer. An American computer software company that offers a...  ...comprehensive scientific, engineering, technical, and non-technical staff augmentation and talent acquisition services. Job Title:... 
    Suggested
    Contract work
    Remote work

    Varite

    United States
    4 days ago
  • $67.61 - $84.51 per hour

     ...Description Product Security Engineer Full-time Lehi, UT You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave... 
    Suggested
    Hourly pay
    Permanent employment
    Full time
    Contract work

    NextDeavor

    Lehi, UT
    1 day ago
  •  ...Product Security Engineer Software Guidance & Assistance, Inc., (SGA), is searching for a Product Security Engineer for a contract assignment with one of our premier SaaS clients in San Jose, CA or McLean, VA. This role is open to remote in these locations. The ideal... 
    Suggested
    Contract work
    Remote work

    SGA

    United States
    2 days ago
  •  ...Senior Product Security Engineer At StackAI, security is how we earn the trust of the enterprises building AI assistants on our platform. We're hiring a hands-on (Senior) Product Security Engineer to design, build, and harden the secure architecture at the core of the... 
    Remote work

    Stack AI

    United States
    3 days ago
  •  ...Senior Product Security Engineer The Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Product Security function at CBIZ. As the first dedicated hire in this domain, this... 

    CBIZ

    Nashville, TN
    2 days ago
  •  ...Product Security Engineer Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping... 
    Self employment
    Work at office
    Remote work
    Flexible hours

    Collective

    San Francisco, CA
    1 day ago
  • $96k - $132k

     ...find purpose and pride. Job Description Your role at Baxter At Baxter Healthcare Corporation, we invite a driven Senior Product Security Engineer who is passionate about contributing to healthcare improvements. This opportunity puts you on the frontline of... 
    Temporary work
    Local area
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Baxter

    Deerfield, IL
    4 days ago
  • $137.86k - $250k

     ...creating abundance for all. Your Charter Secure NEO end-to-end. You will analyze the...  ...before adversaries do, and partner with engineering teams to design and ship the fixes. This...  ...matter most Design and contribute production code for security-critical components such... 
    Temporary work
    Local area
    Remote work
    Work from home
    Flexible hours

    1X

    San Carlos, CA
    1 day ago
  •  ...Persona Identity Verification Engineer Persona is the configurable identity platform...  ...identity verification infrastructure where security isn't a layer we add later, it's core to...  .... What You'll Work On This is a product security role embedded in a generalist security... 
    Full time
    For contractors
    Internship
    Relocation package

    Persona

    San Francisco, CA
    2 days ago
  • $100k - $110k

     ...00 To $110,000.00 Annually We are seeking an experienced Product Security Lead for safeguarding Cartamundi’s customers’ most sensitive...  ...product security-sensitive environment. Bachelor/Master in engineering, product security or equal through experience. Additional... 
    Full time
    Temporary work
    For subcontractor
    Work at office
    Local area
    Worldwide
    Flexible hours

    Cartamundi

    East Longmeadow, MA
    20 hours ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) ~ Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Louisiana, MO
    20 hours ago
  • $108.24k - $151.48k

     ...your work location, balancing what your work requires. What's in it for you: The Residential HVAC team is adding a Product Security Engineering position to focus on embedded systems, services, applications and the associated product development processes used in... 
    Hourly pay
    Local area
    Work from home

    Trane Technologies

    Tyler, TX
    4 days ago
  • $188k - $282k

     ...inflection point. With 2400+ customers in 70+ countries, strong product-market fit, and world-class investor support, we're...  ...started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you'll be a key technical contributor shaping... 
    Work experience placement

    Harvey

    San Francisco, CA
    13 hours ago
  • $74.16 - $92.7 per hour

     ...Description Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave... 
    Hourly pay
    Permanent employment
    Full time
    Contract work
    Remote work

    NextDeavor

    San Jose, CA
    3 days ago
  • $123.55k - $142k

     ...Peace of Mind by Pioneering Safety and Security At Allegion, we help keep the people...  ...brands, 14,000+ employees globally and products sold in 130 countries, we specialize in...  ...lifecycle.? The Senior Product Security Engineer will have a strong ownership stake to ensure... 
    Temporary work
    Flexible hours

    Allegion

    Indianapolis, IN
    12 hours ago
  • $180k - $258k

     ...Product Security Engineer We are looking for a Product Security Engineer to join our team and act as a champion for security within our product engineering organization. You will be responsible for ensuring our products are designed, developed, and maintained with security... 
    Shift work

    Candid Health

    Denver, CO
    2 days ago
  • $208k - $312k

     ...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now...  ...is manual penetration testing. A software engineer with a strong desire to move into security, or... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel Corp

    San Francisco, CA
    12 hours ago
  • $175k - $215k

     ...and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures... 
    Temporary work

    Crusoe

    San Francisco, CA
    1 day ago
  •  ...lifecycle development and manufacturing and production of embedded systems for weapons...  ...Required Skills: Cybersecurity or engineering related degree, Cybersecurity IAT/IAM Level...  ..., SSCP, IAM Level 2 – CAP, GISF, GSLC, Security+ Job Duties: Support the decomposition... 

    Software Technology Inc

    Saint Louis, MO
    4 days ago
  • $250k - $400k

     ...The role of a Product Security Engineer is pivotal in shaping the future of AI-native security engineering. This position operates at the intersection of application security, machine learning, and developer productivity, focusing on the design of autonomous security systems... 
    Full time
    Remote work

    SaidGig

    United States
    20 hours ago
  •  ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on...  ...and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform... 
    Local area
    Worldwide
    Flexible hours

    DataRobot

    San Francisco, CA
    2 days ago
  • $220k - $330k

     ...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We're...  ...'re just getting started. Role Overview As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in... 
    Work experience placement

    Harvey

    San Francisco, CA
    12 hours ago
  • $30 - $50 per hour

    Role Overview As a Product Security Engineer, you will embed security into the software lifecycle for platforms that handle AI/ML data operations. You will help secure services supporting data labeling, content safety labeling, RLHF evaluation, and model evaluation tooling... 
    Hourly pay
    Remote work

    Rex.zone

    New York, NY
    20 hours ago
  • $125.64k

    Join to apply for the Product Security Engineer role at Chime About The Role We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiatives... 
    Full time
    Local area

    Chime

    San Francisco, CA
    20 hours ago
  •  ...healthier lives everywhere, every day. Our DevSecOps Engineering Center of Excellence (R&D) department is looking for a Security Engineer experienced in medical device or...  ...in building and enhancing security in our products and services! As a Product Security Engineer 3... 

    Hologic

    San Diego, CA
    20 hours ago
  •  ...global ocean transportation market. Our products provide ships and workboats the intelligence...  ...by an experienced team of  mariners, engineers, coders, and autonomy scientists. Sea...  ...Job Summary We are seeking a Product Security Engineer with strong networking... 
    Full time
    Remote work
    Flexible hours

    Sea Machines

    Boston, MA
    20 days ago
  • $235k - $275k

    Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00... 
    Full time

    Code Red Partners

    San Francisco, CA
    20 hours ago
  • $160k - $250k

     ...and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal...  ...CrowdStrike’s products. As a Senior Application Security Engineer you will: ~Dig deep into web applications, find... 
    Full time
    Work at office

    CrowdStrike

    Remote
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!