# Senior Product Security Engineer

**Company:** [Function Health](https://hotfix.jobs/companies/function-health)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Python, FastAPI, LangChain, CI/CD, SAST, Sca, Secrets Scanning, Infrastructure As Code, Threat Modeling, Application Security, Api Security, Owasp Top 10, Red Teaming, HIPAA, Security Architecture
**Posted:** 2026-08-06

> Build and operate product security systems across applications, APIs, infrastructure, and CI/CD, including AI-assisted code review and automated security controls. The role requires 5+ years in product or application security or software engineering, strong Python skills, and hands-on vulnerability assessment experience.

## Job Description

## Responsibilities
- Design and deploy AI-powered security agents into CI/CD for automated code review, risk classification, escalation logic, and, where possible, auto-remediation.
- Build and operate security tooling across pipelines, including SAST, SCA, secrets scanning, IaC validation, and supply chain integrity checks.
- Conduct threat modeling, secure design reviews, and manual security assessments across applications, APIs, and infrastructure.
- Find vulnerabilities through proactive testing and drive them through remediation.
- Partner with engineering teams as an embedded security advisor without becoming a blocker.
- Own the rollout of secure-by-default development frameworks and controls.
- Connect application-level telemetry to detection and response systems.
- Contribute to incident response and postmortems involving product security.
- Shape the long-term product security strategy and roadmap.

## Requirements
- 5+ years of experience in product security, application security, software engineering, or a combination.
- Experience building or operating AI-assisted security tooling, such as code-review agents, automated triage pipelines, or custom security automation.
- Strong Python experience.
- Deep expertise identifying and exploiting web, API, and application vulnerabilities beyond the OWASP Top 10.
- Experience embedding security into CI/CD.
- Ability to guide engineers through secure design decisions.
- Strong documentation and design-documentation skills.

## Nice-to-Haves
- Familiarity with FastAPI, LangChain, or agentic frameworks.
- Experience with HIPAA or healthcare data.
- Red-team experience.
- Security architecture experience at scale.

## Compensation and Benefits
- Competitive salary and benefits package.
- Flexible working hours.
- Dynamic work environment encouraging creativity and innovation.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/a989d256-334c-4b46-a990-6ed27876a93f
**Canonical:** https://hotfix.jobs/jobs/a989d256-334c-4b46-a990-6ed27876a93f