Staff Software Engineer, Product Security
Staff Software Engineer builds security into AI platform, owns product security roadmap, reviews critical code like authentication/access control, leads cross-functional initiatives, and mentors engineers on secure practices. Requires 8+ years in product/application/offensive security with proven vulnerability remediation track record.
About the job
What You'll Do
- Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
- Establish and evolve security posture across the engineering organization, setting standards that scale with the company.
- Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development.
- Own and review security-critical code across key parts of the product, including authentication and access control.
- Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers.
- Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts.
- Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance.
What You Have
- 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering.
- Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience.
- Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.
- Experience mentoring senior engineers and developing security talent within an engineering organization.
- Strong programming skills with demonstrated experience writing high-quality, production software.
- Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders.
Nice to Have
- Experience building security programs or practices at hyper-growth startups.
- Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns.
- Experience with AI/ML systems and emerging security considerations for LLM-based applications.
Compensation
$220,000 - $330,000
Skills
Product Security, Application Security, Offensive Security, Authentication, Access Control, Cloud Security, AWS, Azure, GCP, Ai/Ml Security, Llm Security, Penetration Testing, Vulnerability Remediation, Secure Coding, Incident Response
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.