Source Job

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Product Security Application Security Secure Code Review Threat Modeling TypeScript/JavaScript

20 jobs similar to Senior Security Engineer - Product Security

Jobs ranked by similarity.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

$152,000–$175,000/yr
US Unlimited PTO

  • Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
  • Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.

RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.

US Unlimited PTO

  • Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
  • Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
  • Build, maintain, and improve application security tooling and participate in incident response activities.

The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.

$99,750–$137,250/yr
Canada

  • Partner with product and engineering teams to identify application security risks and recommend mitigations.
  • Read application code, configuration, and pull requests to understand security risks and suggest improvements.
  • Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.

Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

US

  • Provide strong leadership as a security thought leader across Delinea's product offerings.
  • Perform end-to-end security architecture reviews and threat modeling.
  • Maintain and mature Product Security tooling such as SAST, SCA, DAST, ASPM.

Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization. They are a global team of passionate problem-solvers, with a culture of innovation, respect, and fairness.

US 4w PTO

  • Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
  • Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.

ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.

Asia

  • Design and implement secure application architectures considering authentication, authorization, data protection, and vulnerability management.
  • Develop and maintain secure coding guidelines, conduct security reviews, and implement security controls.
  • Communicate security risks to stakeholders and provide guidance on secure coding practices.

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange. With over 300 million users in 100+ countries, it offers a diverse, fast-paced, and innovative work environment.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

Global

  • Own and mature the enterprise security program across identity, endpoint, and SaaS security.
  • Implement access control, vulnerability management, and secure configuration of cloud and developer infrastructure.
  • Collaborate with the CISO and operations teams to deliver security approaches that protect critical assets in a web3 environment.

Solana Foundation is a non-profit based in Zug, Switzerland, dedicated to the adoption, decentralization, and security of the Solana network. They are a global team looking for talented individuals who are willing to jump right in and use their expertise to help the ecosystem build.

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

US 5w PTO

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.

NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.

India

  • Lead security architecture reviews and threat modeling exercises for applications and platforms.
  • Partner with engineering and product teams to identify risks and recommend mitigation strategies.
  • Develop security standards, automation, and developer enablement materials to promote secure-by-design practices.

Our partner company is dedicated to building secure digital products through innovative security practices. They offer a collaborative, remote-friendly culture with opportunities for professional growth.

Asia

  • Conduct technical research on new blockchain and DeFi projects to identify architecture risks and security gaps.
  • Deconstruct attack logic and exploit techniques to develop actionable detection rules and security strategies.
  • Collaborate with the wallet team to implement security measures balancing robust protection with user experience.

Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. They are trusted by over 300 million people in 100+ countries and offer a diverse, inclusive work environment with a flat structure.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

Asia

  • Build production-grade security applications and services using Python.
  • Develop internal security platforms and tooling from scratch.
  • Design and enforce secure cloud architectures (AWS) and implement policy enforcement for IAM least-privilege models.

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. They are trusted by 300+ million people in 100+ countries and have a diverse workforce.

US Unlimited PTO

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
  • Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
  • Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.

Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.