Skip to content

Product Security Engineer

Product Security Engineer II responsible for leading threat modeling, triaging CNAPP findings, contributing to SDLC tooling, and partnering with engineering teams to embed security practices. Requires 2-4 years in security roles with strong cloud security and AI tooling experience.

About the job

Responsibilities

  • Lead threat modeling engagements on the features and services where the risk warrants it.
  • Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.
  • Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.
  • Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.
  • Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.
  • Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.
  • Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.

Requirements

  • 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.
  • Comfortable reading and critiquing pull requests in a modern stack. You don't need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.
  • Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).
  • Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus.
  • Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations.
  • Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated.

Nice to Haves

  • Experience with developer tools, SaaS platforms, or feature management
  • Bug bounty triage experience (HackerOne, Bugcrowd)
  • Familiarity with Go, Python, or TypeScript
  • Contributions to internal security tooling or open-source security projects

Compensation

  • Target pay ranges based on Geographic Zones for Level 2:
    • Zone 1: San Francisco/Bay Area or NYC Metropolitan Area, Boston, Seattle - $136,000 - $187,000
    • Zone 2: Irvine, LA, Monterey, Santa Barbara, Santa Rosa, Austin, Portland, Philadelphia, Chicago - $122,000 - $168,000
    • Zone 3: All other US locations - $116,000 - $159,000
  • RSUs, health, vision, and dental insurance, and mental health benefits in addition to salary.

Skills

Threat Modeling, Stride, Attack Trees, Cnapp, SAST, Sca, Owasp Top 10, Authentication, Authorization, Secrets Management, Cloud Security, AI Tools

Applied Intuition

Applied Intuition

Sunnyvale, CA

Cybersecurity Software Engineer - New Grad
$130k+/yrOn-siteSecurity Engineering

Build security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.

Flexport

Flexport

United States

Security Engineer, Corporate Security
$131k+/yrOn-site2+ YOESecurity Engineering

Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.

Coinbase

Coinbase

United States

Threat Intelligence Platform Engineer
$145k+/yrRemote2+ YOESecurity Engineering

Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.

Axle

Axle

United States

Cybersecurity Research Assistant
$85k+/yrRemote1+ YOESecurity Engineering

Early-career cybersecurity professional implementing and monitoring security controls across Linux, Kubernetes, database, and AI infrastructure. Requires 1–3 years of hands-on technical experience, Linux and scripting skills, and interest in federal authorization and security engineering.

Hover

Hover

San Francisco, CA
Security Software Engineer
$148k+/yrHybrid1+ YOESecurity Engineering

Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.