# Senior Product Security Engineer

**Company:** [Anyscale](https://hotfix.jobs/companies/anyscale)
**Location:** Unspecified
**Role:** Security Engineering
**Salary:** $180k – $210k/yr
**Experience:** 8+ years
**Skills:** Threat Modeling, Secure Design, Vulnerability Management, Software Composition Analysis, Secret Scanning, SAST, Software Supply Chain Security, Sbom, Cvss, Container Security, Image Scanning, Security Architecture
**Posted:** 2026-08-26

> Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

## Job Description

## Responsibilities
- Own and operate a scalable secure software development lifecycle (SSDL), including threat modeling, security requirements, secure design practices, and scanning.
- Partner with engineering on security features and secure-by-design architecture from early design through implementation.
- Review the security of existing systems and new initiatives, turning findings into prioritized, actionable work.
- Own vulnerability management for shipped products: enumerate components, map known vulnerabilities, and provide accurate posture reporting.
- Drive vulnerabilities to resolution with engineering against defined SLAs.
- Own software composition analysis, secret scanning, and SAST across product repositories.
- Mentor engineers and raise the organization’s security bar.

## Requirements
- 8+ years of product or application security experience, ideally in a high-growth startup.
- Demonstrated ownership of an SSDL at scale, including threat modeling and secure design review.
- Hands-on experience partnering with engineering on security features and architecture.
- Deep experience with software composition analysis, secret scanning, SAST, or secure-development tooling.
- Understanding of software supply chain security and component enumeration, including SBOM approaches.
- Experience triaging vulnerabilities using CVSS and business context and driving remediation with engineering.
- Strong communication and seniority to set direction, review work, and mentor others.

## Nice to Have
- Experience producing vulnerability or security posture reporting for enterprise or regulated customers.
- Familiarity with container artifact security, including image scanning, signing, and SBOM generation.
- Experience building or maturing an SSDL program at scale.
- Background in AI or ML platforms or distributed systems.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Threat & Offensive Security](https://hotfix.jobs/jobs/9e88bf55-b93e-4acd-ae0b-a8850f2c805e) - Valon - Remote - $180k – $230k/yr
- [Compliance Manager](https://hotfix.jobs/jobs/90cc18a6-7467-4675-96aa-770c09c5a6ee) - Anyscale - San Francisco, CA - $180k – $230k/yr
- [Senior Application Security Engineer](https://hotfix.jobs/jobs/4bd73e3b-28a6-4dae-956a-f38222e41da3) - Siftstack - Marina Del Rey, CA - $180k – $230k/yr
- [Security Operations Lead](https://hotfix.jobs/jobs/6494f34e-ec68-46c4-a932-f070ac908ddf) - Fireworks AI - Remote - $180k – $210k/yr

**Apply:** https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99
**Canonical:** https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99