Skip to content
StackAIStackAI

Product Security Engineer

Hands-on product security engineer responsible for encryption, key management, customer data protection, tenant isolation, threat modeling, and secure delivery practices. Requires 4+ years building security-critical production systems and strong Python and TypeScript/Node.js skills.

About the job

Responsibilities

  • Own encryption and signing systems, including KMS, key management, BYOK, envelope encryption, and signing pipelines across cloud and on-premises deployments.
  • Protect sensitive customer data by extending PHI/PII scrubbing and strengthening data-protection foundations.
  • Own encryption at rest and tenant isolation for the storage layer.
  • Maintain and expand secure-by-default templates and reference implementations in the software development lifecycle.
  • Lead threat modeling across execution engines, connector trust boundaries, and multi-tenant isolation.
  • Improve security scanning coverage, signal quality, and CI enforcement to prevent critical findings from reaching production.
  • Translate audit, compliance, and incident-response requirements into implementation in the codebase.

Requirements

  • 4+ years building security-critical systems in production, with substantial hands-on implementation experience.
  • Practical depth in cryptography and key management, including encryption, KMS, secrets handling, and signing.
  • Ability to design and reason about secure architectures and collaborate as a technical peer with senior engineers.
  • Experience with multi-tenant SaaS isolation and data-isolation requirements for regulated customers.
  • Strong secure-coding skills in Python and TypeScript/Node.js.
  • Experience integrating security checks and gates into CI/CD pipelines.

Nice to Have

  • Cloud and API security fundamentals on Google Cloud, Azure, or AWS.
  • Experience securing on-premises, self-hosted, or air-gapped deployments.
  • Experience in regulated domains such as healthcare/PHI or finance.
  • Familiarity with AI/LLM platform security, including agent execution, connector trust boundaries, prompt risks, and tool-call risks.
  • Startup or growth-stage experience.

Skills

Cryptography, Key Management, Kms, Byok, Envelope Encryption, Python, TypeScript, Node.js, CI/CD, Threat Modeling, Multi-Tenant Isolation, GCP, AWS, Azure, Api Security

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Retell AI

Retell AI

United States
Compliance Engineer
$72k+/yrRemoteSecurity Engineering

Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.