Senior Product Security Engineer II
Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.
Responsibilities
- Design and conduct offensive security operations / engagements for product and internal tools across Instacart
- Deploy and operationalize a variety of open-source and commercially available security tools that can scale out and be maintained long term
- Collaborate with cross-functional teams, including engineering and product, to integrate security testing into their SDLC cycle
- Share knowledge and mentor other team members, promoting a culture of continuous learning and growth
Requirements
- 7+ years of experience in Security Engineering or Penetration Testing, demonstrating a strong grasp of product security concepts and principles
- Experience in mobile app penetration testing, AI security testing or cloud penetration testing
- Experience with threat modeling, security assessments, product security concepts, and security architecture reviews
- Ability to make data-driven decisions & prioritize initiatives that improve key security metrics
- Ability to balance a sense of urgency with shipping high-quality and pragmatic solutions
- Solid self-management and organizational skills
- In-depth knowledge of the best remediation techniques for different application vulnerabilities and the ability to explain them to product teams
- Ability to create written work products and detailed technical documents to work effectively with cross-functional teams and drive alignment on security objectives and plans
Nice-to-Haves
- Bachelor’s degree in Computer Science, Engineering, Math, or related work experience
- Bug bounty research experience
Product Security Engineer
Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.
Staff Software Engineer, Security
Staff Security Software Engineer designing and building scalable security infrastructure, identity systems, and compliance automation platforms. Requires 8+ years software engineering experience with deep Kubernetes, Go/Rust, and cloud platform expertise.
Senior Security Engineer, GRC
Senior GRC engineer owning customer security questionnaires, compliance automation, risk assessments, and policy management across SOC 2, ISO 27001, and HIPAA. Requires 8+ years experience, scripting skills, and strong customer-facing communication.