Skip to content
GreenlightGreenlight

Staff Product Security Engineer

Lead end-to-end product security for consumer products, digital platform, and hardware devices. Drive threat modeling, penetration testing, PSIRT operations, and AI security guardrails in a regulated financial services environment.

About the job

Responsibilities

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA and attack tree methodologies
  • Translate threats into actionable, risk-rated engineering remediations prioritized by severity
  • Conduct hands-on penetration testing and security assessments across the full product stack producing actionable reports for engineering and leadership
  • Red-team AI powered products and development tools to test for prompt injection, data exfiltration, MCP server exploitation, and tool misuse
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on-call incidents
  • Shape the posture of AI assisted development environment defining and enforcing enterprise policies for Claude and Cursor
  • Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers and collaborating with the AI team on securing ML pipelines
  • Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products

Requirements

  • 10+ years of product security experience spanning application security, cloud security, and secure SDLC
  • Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems
  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware
  • PSIRT operational experience from vulnerability intake and triage; fluent in CVE, CVSS, FIRST PSIRT frameworks
  • Deep hands-on AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and practical experience with MITRE
  • Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor
  • Strong programming ability and capability to review code, build security tools, automate workflows
  • Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications
  • Strong knowledge of programming languages & frameworks (Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies and infrastructure (AWS, GCP, Kubernetes, Ambassador, Helm), and databases (MySQL, DynamoDB, Redis)
  • Ability to influence without authority, mentor without managing, and communicate complex risks

Nice-to-Haves

  • Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience
  • Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly

Compensation & Benefits

  • Medical, dental, vision, and HSA match
  • Paid life insurance, AD&D, and disability benefits
  • Traditional 401k with company match
  • Unlimited PTO
  • Paid company holidays and pop-up bonus holidays
  • Professional development stipends
  • Mental health resources
  • 1:1 financial planners
  • Fertility healthcare
  • 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
  • Flexible WFH, both remote and in-office opportunities

Skills

Threat Modeling, Penetration Testing, Psirt, SAST, DAST, Sca, Burp Suite, Metasploit, Kali Linux, Node.js, Java, Kotlin, React, Redux, SwiftUI

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.