Skip to content
RedditReddit

Staff Product Security Engineer

Leads design and delivery of secure frameworks, guardrails, and workflow-native controls to prevent vulnerabilities in production, especially for AI-assisted development. Requires 8+ years in software/product security, staff-level impact, and proficiency in Go, Python, or JS/TS.

About the job

What You'll Do

  • Build and evolve secure frameworks, guardrails, and library-level controls that make common vulnerability classes harder to introduce.
  • Design security controls for AI-assisted development — including reusable rule packs and skills that shape how engineers and coding agents generate, review, and ship code.
  • Embed security into the workflows engineers already use.
  • Drive product security reviews for new launches and major architectural changes.
  • Identify and eliminate systemic security debt.
  • Shape strategy, influence architecture, and drive execution across teams.

What We're Looking For

  • 8+ years of experience in software engineering, product security, or application security, with at least 2 years operating at a staff level of scope and impact.
  • Proficiency in one or more languages (Go, Python, JS/TS).
  • Experience designing, building, and operating production-quality systems and developer-facing platforms.
  • Experience building secure frameworks, libraries, or guardrails that improve security across many teams at once.
  • Demonstrated ability to integrate security into developer workflows: CI/CD, code review, release processes, and internal platforms.
  • Clear communicator who can explain technical detail and business impact to both engineers and leadership.
  • Comfortable in fast-moving environments where AI-assisted development is reshaping how software is built and reviewed.
  • Experience with vulnerability discovery and remediation pipelines, including bug bounty or researcher-reported findings.
  • Track record of mentoring engineers and raising the technical bar across a security or platform engineering org.

Preferred Qualifications

  • Experience securing AI/LLM systems, agentic workflows, or AI-assisted development tooling.
  • Familiarity with authentication/authorization systems, cloud-native platforms, and how to secure them.

Skills

Go, Python, JavaScript, TypeScript, CI/CD, Ai-Assisted Development, LLMs, Vulnerability Remediation, Authentication, Authorization

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Harvey

Harvey

San Francisco, CA

Staff Security Software Engineer, IAM
$231k+/yrHybrid10+ YOESecurity Engineering

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

Illumio

Illumio

Sunnyvale, CA

Staff Engineer - Container Security
$194k+/yrOn-site8+ YOESecurity Engineering

Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.