Skip to content
MongoDBMongoDB

Senior Product Security Engineer, Server

Leads product security strategy and assessments for MongoDB’s server products, partnering with engineers on threat modeling, secure architecture, vulnerability research, and remediation. The role requires 7+ years of security experience and strong C++ expertise with low-level codebases.

About the job

Responsibilities

  • Own, define strategy for, and drive improvements across areas such as fuzzing, threat modeling, secrets management, and container security.
  • Advocate for and lead complex security projects from inception through completion.
  • Drive architecture, patterns, and processes across Server Engineering that make security the easiest path.
  • Partner with engineering teams to design and implement security controls across software and systems.
  • Research and proof-of-concept new attacks against systems.
  • Plan and perform product security assessments, including architecture reviews, threat modeling, code reviews, penetration testing, and security consulting.
  • Serve as a subject matter expert in software security and architecture.
  • Educate engineers through CTFs, lunch-and-learns, and one-on-one mentorship.

Requirements

  • 7+ years of experience in application security, software security, or product security.
  • Proven C++ programming experience and experience assessing low-level codebases.
  • Experience implementing remediation strategies for memory-related security flaws, including buffer overflows and memory leaks.
  • Programming ability and willingness to contribute code to engineering environments.
  • Track record of partnering with software engineers on threat models, security design reviews, and pragmatic security recommendations.
  • Ability to communicate complex technical issues clearly and build trust with varied audiences.
  • Demonstrated ownership of security initiatives and ability to deliver results autonomously or collaboratively.
  • Willingness to work occasional flexible hours to collaborate with US-based colleagues.

Nice to Haves

  • Subject matter expertise in database security or data security.
  • Knowledge of database engines, database internals, or applied cryptography.
  • Experience contributing or partnering with security researchers to identify vulnerabilities that led to published CVEs.
  • Experience with administrative responsibilities of a CNA.

Success in This Role

  • See projects through from conception to completion to deliver new services or capabilities.
  • Establish yourself as a go-to person for security topics.

Compensation and Benefits

  • Supportive and enriching culture.
  • Employee affinity groups.
  • Fertility assistance.
  • Generous parental leave policy.

Skills

C++, Fuzzing, Threat Modeling, Secrets Management, Container Security, Application Security, Code Review, Penetration Testing, Database Security, Applied Cryptography, Database Internals, Cves

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Stripe

Stripe

Dublin, Ireland

Forward Deployed Security Engineer
No salary listedOn-site10+ YOESecurity Engineering

Leads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.

Stripe

Stripe

Seattle, WA
Incident Response Manager - Abuse Operations
No salary listedOn-site10+ YOESecurity Engineering

Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.