Security Engineer, Product
Builds security primitives, platform mitigations, and leads vulnerability remediation for Ramp's financial platform. Partners with engineers for secure-by-design solutions. Requires 5+ years software experience, 2+ years in security/infrastructure.
About the job
What You’ll Do
- Build security-focused application primitives and integrate them into existing products
- Design and deploy platform-level mitigations to common security issues
- Lead remediation of prioritized issues across the technology stack: collaborating with engineers to triage and fix vulnerabilities from internal discoveries, penetration testing, and bug bounty program
- Partner with engineering teams to design and deploy inherently secure solutions
- Champion tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) to help engineers build secure systems quickly
What You Need
- Minimum of 5 years of experience building software
- Minimum of 2 years of experience focused on platform, infrastructure, and/or security
- Desire to work in a fast-paced environment, continuously grow, and master your craft
- Ability to turn business and product ideas into engineering solutions
- Alignment with Ramp’s core values of enabling businesses to grow more by spending less
Nice to Haves
- Experience with Python (Flask), Elixir, and AWS (ECS, as well as other core services)
- Experience analyzing and improving the security posture of infrastructure in AWS
Skills
Python, Flask, Elixir, AWS, ECS, Static Analysis, Linters, Security Scanning, Bug Bounty, Penetration Testing
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.