Staff Product Security Engineer
Leads design and delivery of secure frameworks, guardrails, and workflow-native controls to prevent vulnerabilities in production, especially for AI-assisted development. Requires 8+ years in software/product security, staff-level impact, and proficiency in Go, Python, or JS/TS.
About the job
What You'll Do
- Build and evolve secure frameworks, guardrails, and library-level controls that make common vulnerability classes harder to introduce.
- Design security controls for AI-assisted development — including reusable rule packs and skills that shape how engineers and coding agents generate, review, and ship code.
- Embed security into the workflows engineers already use.
- Drive product security reviews for new launches and major architectural changes.
- Identify and eliminate systemic security debt.
- Shape strategy, influence architecture, and drive execution across teams.
What We're Looking For
- 8+ years of experience in software engineering, product security, or application security, with at least 2 years operating at a staff level of scope and impact.
- Proficiency in one or more languages (Go, Python, JS/TS).
- Experience designing, building, and operating production-quality systems and developer-facing platforms.
- Experience building secure frameworks, libraries, or guardrails that improve security across many teams at once.
- Demonstrated ability to integrate security into developer workflows: CI/CD, code review, release processes, and internal platforms.
- Clear communicator who can explain technical detail and business impact to both engineers and leadership.
- Comfortable in fast-moving environments where AI-assisted development is reshaping how software is built and reviewed.
- Experience with vulnerability discovery and remediation pipelines, including bug bounty or researcher-reported findings.
- Track record of mentoring engineers and raising the technical bar across a security or platform engineering org.
Preferred Qualifications
- Experience securing AI/LLM systems, agentic workflows, or AI-assisted development tooling.
- Familiarity with authentication/authorization systems, cloud-native platforms, and how to secure them.
Skills
Go, Python, JavaScript, TypeScript, CI/CD, Ai-Assisted Development, LLMs, Vulnerability Remediation, Authentication, Authorization
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.