Skip to content
HarveyHarvey

Staff Software Engineer, Product Security

Staff Software Engineer builds security into AI platform, owns product security roadmap, reviews critical code like authentication/access control, leads cross-functional initiatives, and mentors engineers on secure practices. Requires 8+ years in product/application/offensive security with proven vulnerability remediation track record.

About the job

What You'll Do

  • Define and own the product security roadmap, prioritizing initiatives based on risk, business impact, and engineering org maturity.
  • Establish and evolve security posture across the engineering organization, setting standards that scale with the company.
  • Partner with Product Engineering, Infrastructure, and Platform teams to incorporate secure design principles at every stage of development.
  • Own and review security-critical code across key parts of the product, including authentication and access control.
  • Architect secure-by-default libraries and tools that make the secure path the easiest choice for developers.
  • Drive mitigation strategies during security-related incident responses, coordinating cross-functional efforts.
  • Mentor engineers and raise the security bar across teams through code reviews, design reviews, and technical guidance.

What You Have

  • 8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering.
  • Long track record of identifying and remediating software vulnerabilities, demonstrated through CVEs, bug bounty awards, published research, or prior work experience.
  • Track record of leading complex cross-functional security initiatives and delivering measurable improvements, with demonstrated ability to influence engineering teams without direct authority.
  • Experience mentoring senior engineers and developing security talent within an engineering organization.
  • Strong programming skills with demonstrated experience writing high-quality, production software.
  • Excellent communication and collaboration skills, particularly when translating security risks into business terms for non-security stakeholders.

Nice to Have

  • Experience building security programs or practices at hyper-growth startups.
  • Background with cloud environments (Azure, GCP, AWS) and cloud-native security patterns.
  • Experience with AI/ML systems and emerging security considerations for LLM-based applications.

Compensation

$220,000 - $330,000

Skills

Product Security, Application Security, Offensive Security, Authentication, Access Control, Cloud Security, AWS, Azure, GCP, Ai/Ml Security, Llm Security, Penetration Testing, Vulnerability Remediation, Secure Coding, Incident Response

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Harvey

Harvey

San Francisco, CA

Staff Security Software Engineer, IAM
$231k+/yrHybrid10+ YOESecurity Engineering

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.