# Product Security Engineer

**Company:** [StackAI](https://hotfix.jobs/companies/stackai)
**Location:** Warsaw, Poland
**Role:** Security Engineering
**Salary:** PLN260k – PLN350k/yr
**Experience:** 4+ years
**Skills:** Cryptography, Key Management, Kms, Byok, Envelope Encryption, Python, TypeScript, Node.js, CI/CD, Threat Modeling, Multi-Tenant Isolation, GCP, AWS, Azure, Api Security
**Posted:** 2026-06-30

> Hands-on product security engineer responsible for encryption, key management, customer data protection, tenant isolation, threat modeling, and secure delivery practices. Requires 4+ years building security-critical production systems and strong Python and TypeScript/Node.js skills.

## Job Description

## Responsibilities
- Own encryption and signing systems, including KMS, key management, BYOK, envelope encryption, and signing pipelines across cloud and on-premises deployments.
- Protect sensitive customer data by extending PHI/PII scrubbing and strengthening data-protection foundations.
- Own encryption at rest and tenant isolation for the storage layer.
- Maintain and expand secure-by-default templates and reference implementations in the software development lifecycle.
- Lead threat modeling across execution engines, connector trust boundaries, and multi-tenant isolation.
- Improve security scanning coverage, signal quality, and CI enforcement to prevent critical findings from reaching production.
- Translate audit, compliance, and incident-response requirements into implementation in the codebase.

## Requirements
- 4+ years building security-critical systems in production, with substantial hands-on implementation experience.
- Practical depth in cryptography and key management, including encryption, KMS, secrets handling, and signing.
- Ability to design and reason about secure architectures and collaborate as a technical peer with senior engineers.
- Experience with multi-tenant SaaS isolation and data-isolation requirements for regulated customers.
- Strong secure-coding skills in Python and TypeScript/Node.js.
- Experience integrating security checks and gates into CI/CD pipelines.

## Nice to Have
- Cloud and API security fundamentals on Google Cloud, Azure, or AWS.
- Experience securing on-premises, self-hosted, or air-gapped deployments.
- Experience in regulated domains such as healthcare/PHI or finance.
- Familiarity with AI/LLM platform security, including agent execution, connector trust boundaries, prompt risks, and tool-call risks.
- Startup or growth-stage experience.

## Similar jobs

- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Compliance Engineer](https://hotfix.jobs/jobs/63197ba5-a12d-497a-a0b9-91e5e7050ac1) - Retell AI - Remote - $72k – $90k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr

**Apply:** https://hotfix.jobs/jobs/9247f3a8-720a-4e51-9794-6ef6b450cbe1
**Canonical:** https://hotfix.jobs/jobs/9247f3a8-720a-4e51-9794-6ef6b450cbe1