Source Job

$217,000–$288,000/yr
US Unlimited PTO 18w maternity 18w paternity

  • Champion a secure by default culture, building defense in depth into frameworks and processes.
  • Develop security requirements and work directly with teams to build them into new applications.
  • Run security risk assessments, hands-on penetration testing, and threat modeling.

Application Security Product Security Microservices Threat Modeling Secure Coding

20 jobs similar to Product Security Engineer

Jobs ranked by similarity.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

$130,000–$185,000/yr
US

  • Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
  • Build security tooling and automation, contributing to development of internal applications and scripts.
  • Execute incident response efforts by identifying, investigating, and remediating security incidents.

BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.

$99,750–$137,250/yr
Canada

  • Partner with product and engineering teams to identify application security risks and recommend mitigations.
  • Read application code, configuration, and pull requests to understand security risks and suggest improvements.
  • Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.

Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

Canada Unlimited PTO 18w maternity 12w paternity

  • Build and harden secure CI/CD pipelines with security gates to catch issues before production.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
  • Harden container images, Kubernetes configurations, and cloud IAM to minimize attack surface.

Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises, with a culture that values customer obsession, intentional action, and trust.

US

  • Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
  • Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
  • Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.

Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$138,677–$182,296/yr
US

  • Integrate security into the SDLC through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.

US Unlimited PTO

  • Own the Application Security product strategy and roadmap, from tooling to governance.
  • Drive delivery of security solutions with engineering and cross-functional teams.
  • Lead tool procurement, risk prioritization, and executive communication.

Zeta Global is an AI-powered marketing cloud that helps marketers acquire and retain customers using advanced AI and consumer data. Founded in 2007, the company is headquartered in New York City with offices worldwide, employing a diverse team focused on innovation and inclusion.

$180,000–$210,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Threat model new product features and integrations, hardening systems with effective controls.
  • Operate and evolve the application security toolchain, keeping it high-signal for developers.
  • Own day-to-day security operations across the detection stack, triaging and resolving incidents.

Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

UK Unlimited PTO

  • Protect applications trusted by millions of users in the Web3 ecosystem.
  • Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
  • Embed security throughout the software development lifecycle to build resilient products.

This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.

India

  • Lead security architecture reviews and threat modeling exercises for applications and platforms.
  • Partner with engineering and product teams to identify risks and recommend mitigation strategies.
  • Develop security standards, automation, and developer enablement materials to promote secure-by-design practices.

Our partner company is dedicated to building secure digital products through innovative security practices. They offer a collaborative, remote-friendly culture with opportunities for professional growth.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

$105,000–$123,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
  • Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
  • Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.

Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.

India

  • Advise product engineering teams on secure coding, vulnerability management, and secure-by-design practices.
  • Conduct threat modeling using established frameworks such as STRIDE, PASTA, and MAESTRO to identify risks.
  • Partner with architecture teams to embed security principles into product design and ensure regulatory compliance.

This is a global technology company focused on product development and security. It fosters a collaborative culture with an emphasis on innovation, continuous learning, and knowledge sharing across distributed teams.

Brazil

  • Identify and remediate high-impact security risks across applications, infrastructure, and production systems.
  • Integrate security practices into CI/CD pipelines and infrastructure-as-code workflows.
  • Collaborate with engineering teams to embed security into development and delivery workflows.

The company develops software and AI-powered solutions to support critical business workflows. It is a remote-first, fast-moving organization with a culture focused on ownership, transparency, and continuous improvement.