Skip to content
CloudflareCloudflareAustin, TX

Product Security Engineer

The Product Security Engineer builds AI-driven security automation, conducts threat modeling and security reviews, manages vulnerability remediation, and triages bug bounty findings. The role requires 5+ years of product or application security experience in cloud or SaaS environments plus hands-on AI/LLM engineering experience.

Salary not listed
Hybrid5+ YOESecurity Engineering

About the role

Responsibilities

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to automate code analysis, optimize triage, and streamline product security workflows.
  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions, including STRIDE, across product features; define security requirements early in the development lifecycle.
  • Product Vulnerability Management: Manage the operational lifecycle of product security findings. Verify vulnerabilities, map them to the correct engineering owner, and track mitigation in alignment with established SLAs.
  • Bug Bounty Triage: Technically triage and validate external bug bounty submissions by verifying exploitability and evaluating business risk.
  • Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies.
  • Engineering Collaboration: Partner with DevOps and product teams as a security point of contact, helping developers implement secure coding practices.

Requirements

  • 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Demonstrated ability to build production-grade automation scripts and tools.
  • Hands-on engineering experience leveraging AI and large language models to solve operational or technical challenges.
  • Competency in threat modeling methodologies and evaluating code flaws for engineering and security impact.
  • Experience tracking, routing, and driving software vulnerability remediation across engineering groups against defined SLAs.
  • Strong collaboration and communication skills, including the ability to communicate technical security risks to software engineers and resolve ownership ambiguity.

Nice-to-Haves

  • Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Experience scaling crowdsourced security programs such as HackerOne or Bugcrowd.
  • Experience optimizing agile project management workflows within JIRA.
  • Experience integrating hardware security features into production codebases.

Compensation & Benefits

  • Eligible to participate in the company equity plan.
  • Medical/Rx, dental, and vision insurance.
  • Flexible spending and commuter spending accounts.
  • Fertility and family-forming benefits.
  • On-demand mental health support and employee assistance program.
  • Global travel medical insurance.
  • Short- and long-term disability insurance.
  • Life and accident insurance.
  • 401(k) retirement savings plan.
  • Employee stock participation plan.
  • Flexible paid time off covering vacation and sick leave.
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave.

Skills

Application Securityproduct securityAILLMsThreat ModelingstrideVulnerability Managementbug bountyPenetration TestingDevOpssecure codingfuzzingJira
Zoox

Product Security Engineer - QRA

ZooxFoster City, CA +3

Conducts quantitative security risk assessments, threat modeling, and cybersecurity requirements development for autonomous vehicles and cloud services. Requires a master’s degree, 5+ years of experience, strong systems engineering and cybersecurity expertise, and familiarity with automotive security standards and interfaces.

191k – 271k/yrHybrid5+ YOESecurity Engineering
Front

Security Operations Engineer

FrontSan Francisco, CA

Protects the company’s customers, employees, and platform by leading incident response, improving detection coverage, automating security operations, and hardening cloud, endpoint, identity, and SaaS environments. Requires 5+ years of security operations or related experience and strong cross-functional communication.

180k – 260k/yrHybrid5+ YOESecurity Engineering
Palantir

Platform Engineer - Identity Infrastructure

PalantirPalo Alto, CA +2

Build and operate secure identity infrastructure, governance, authorization, and token-issuance systems across corporate and customer-facing cloud environments. Requires 3+ years in SRE, DevOps, or software engineering, production service experience, cloud and container expertise, infrastructure-as-code proficiency, and security focus.

Salary not listedHybrid5+ YOESecurity Engineering
Wiz

Threat Intelligence Researcher (Cloud)

WizUnited States

Researches and tracks sophisticated state-backed and financially motivated threats targeting cloud environments, using telemetry, infrastructure analysis, malware analysis, and threat intelligence techniques. Requires at least five years of security or threat research experience.

160k – 220k/yrRemote5+ YOESecurity Engineering
Pave

IT Manager

PaveSan Francisco, CA

Owns corporate security architecture and automation across identity, compliance, endpoint protection, SaaS, and internal IT systems. The role requires 5+ years of security engineering experience, deep IdP design expertise, audit control ownership, and a track record of impactful automation.

220k+/yrHybrid5+ YOESecurity Engineering