Senior Product Security Engineer
Designs and builds secure frameworks for AI workflows, microservices, and developer tools. Conducts security reviews and implements auth systems for SaaS offerings, requiring 7+ years experience in Golang/Node.js and distributed systems security.
About the job
What You’ll Be Working On
- Design and build secure frameworks and patterns for high-performance AI workflows, agents, and models to protect our clients
- Create reusable security patterns for product microservices, focusing on service-to-service authorization, API security, and multi-tenant data isolation that scales across product lines
- Create developer-facing tools and automation that catch security issues early in the development cycle without slowing teams down
- Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe’s fleet of SaaS offerings
What You’ll Bring to the Team
- 7+ years of experience shipping production software with strong system design skills
- Deep expertise in Golang and Node.js/JavaScript, with experience building and debugging distributed systems
- Hands-on experience securing gRPC services, REST APIs, and microservice architectures
- Strong background implementing authentication and authorization systems using OAuth2, OIDC, SAML, JWT, and RBAC/ABAC models
- Production experience with application security tooling (SAST, DAST, SCA) and CI/CD integration (e.g., Semgrep, OWASP ZAP, Burp, GitLab)
- Knowledge of runtime application security and observability tools
- Solid understanding of cloud-native and containerized environments (Docker, Kubernetes) and network security fundamentals
- Strong grasp of OWASP Top 10, secure coding practices, cryptography, and secure design principles
Bonus Points
- Experience building reusable security frameworks or internal developer platforms
- Background in platform or infrastructure-adjacent security engineering
- Experience influencing security practices across multiple engineering teams
- Familiarity with supply chain security and dependency risk management
Benefits
- Competitive compensation
- Restricted Stock Units
- Paid time off & paid holidays
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match up to 4% of salary
Compensation Range
Compensation will be paid in the range of up to $175,000 - $215,000 + Bonus. Restricted Stock Units are included in all offers.
Skills
Go, Node.js, JavaScript, gRPC, REST APIs, Oauth2, OIDC, SAML, Jwt, RBAC, Abac, Kubernetes, Docker, Semgrep, Owasp Zap
Similar jobs
Security Engineering jobsOwn and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.