Source Job

New Zealand

  • Lead product security engineering across key verticals, engaging with engineering leadership and technical teams.
  • Build and automate security design reviews, threat modeling, vulnerability management, and AI-assisted tools.
  • Serve as a subject matter expert for mobile, API, and cloud security, mentoring engineers and collaborating cross-functionally.

Application Security Security Engineering Threat Modeling SAST/DAST

20 jobs similar to Cybersecurity Lead | Product Security Engineering

Jobs ranked by similarity.

India

  • Lead security architecture reviews and threat modeling exercises for applications and platforms.
  • Partner with engineering and product teams to identify risks and recommend mitigation strategies.
  • Develop security standards, automation, and developer enablement materials to promote secure-by-design practices.

Our partner company is dedicated to building secure digital products through innovative security practices. They offer a collaborative, remote-friendly culture with opportunities for professional growth.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

Canada

  • Lead a team of Security Engineers, providing decision-making support and enabling them to deliver security consulting to the wider business.
  • Work directly with Product & Technology teams to assist in how our platform is built and how applications behave, supporting everything from user security to internet connectivity.
  • Have significant impact on security of systems used by thousands of firefighters, paramedics, and hospitals worldwide.

ESO is a data, technology, and research company passionate about improving community health and safety through the power of data. We serve thousands of customers out of our offices across the US, Canada and Northern Ireland, and we are small enough to be nimble and fun but big enough to be a great place to work.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

UK 5w PTO

  • Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
  • Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
  • Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.

Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.

Germany

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
  • Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.

Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

$129,500–$144,300/yr
Canada Unlimited PTO

  • Lead security architecture across AWS and colocation, defining secure patterns and controls.
  • Partner with engineering teams to threat model, review designs, and promote secure-by-design.
  • Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.

NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.

India

  • Advise product engineering teams on secure coding, vulnerability management, and secure-by-design practices.
  • Conduct threat modeling using established frameworks such as STRIDE, PASTA, and MAESTRO to identify risks.
  • Partner with architecture teams to embed security principles into product design and ensure regulatory compliance.

This is a global technology company focused on product development and security. It fosters a collaborative culture with an emphasis on innovation, continuous learning, and knowledge sharing across distributed teams.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

$166,600–$208,300/yr
North America

  • Design and implement cloud security posture and automation to protect customer trust.
  • Enable cyber resilience and lead zero trust initiatives across the infrastructure.
  • Collaborate with engineering teams to enhance reliability and security of cloud systems.

Mercury is a fintech company providing banking and financial services for startups, focusing on simplicity and security. With a team of around 500 employees, the culture is collaborative, innovative, and values diversity.

US

  • You will serve as a trusted security advisor, developing and implementing cybersecurity strategies aligned with business objectives.
  • You will design and implement advanced security controls, including SIEM, DLP, IDS/IPS, and identity management solutions.
  • You will lead secure architecture and integration projects across Microsoft cloud, AWS, GCP, and other platforms.

A partner company provides cybersecurity consulting services, helping organizations strengthen their security posture across cloud and enterprise technologies. They operate in a collaborative remote environment and seek independent, disciplined professionals.

Europe 5w PTO

  • Define and execute short- and long-term security strategy, governance, and operations across the organization.
  • Lead security initiatives covering monitoring, incident response, cloud protection, and application security.
  • Collaborate with engineering, compliance, and leadership teams to balance strong protection with seamless experiences.

A fast-growing global technology organization in the fintech sector. The company fosters a collaborative international environment with talented teams across multiple regions.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

$151,200–$189,000/yr
5w PTO

  • Build and lead Attio's Product Security function, securing their AI-native SaaS platform and sensitive customer data.
  • Work with Engineering Leadership to ensure security by design, mitigating unique risks from AI-driven features and AI-assisted development.
  • Lead production security incident response, recruiting and retaining a world-class team of Security Engineers and SecOps practitioners.

Attio is the CRM for agentic revenue, designed for ambitious go-to-market teams to understand every customer and automate at scale. They have raised $116M from top investors and hire builders who thrive on complex technical challenges, holding themselves to a high bar and delighting users.

EMEA

  • Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
  • Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
  • Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.

Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.

$217,000–$288,000/yr
US Unlimited PTO 18w maternity 18w paternity

  • Champion a secure by default culture, building defense in depth into frameworks and processes.
  • Develop security requirements and work directly with teams to build them into new applications.
  • Run security risk assessments, hands-on penetration testing, and threat modeling.

Grow Therapy is a three-sided marketplace that empowers therapists and patients by providing technology and insurance support. The company has raised over $328M in funding, employs roughly 145 engineers, and values a mission-driven culture.

US Unlimited PTO 18w maternity 18w paternity

  • Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
  • Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
  • Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.

Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.

Europe 5w PTO

  • Lead and grow a team of security specialists to manage day-to-day security operations, incident response, and threat intelligence.
  • Own the security strategy, policy framework, and controls while partnering with engineering on cloud and application security.
  • Drive security awareness across the organization and report on risks to senior leadership and governance forums.

Wayflyer provides fast, technology-driven financing to small businesses, assessing them in minutes and deploying capital within 24 hours. With over $6 billion deployed and backing from Tier 1 banks, the company has a global team across offices in Dublin, London, New York, Charlotte, Berlin, and Sydney, fostering an ambitious and collaborative culture.

UK

  • Improve and maintain AWS security configurations including IAM, GuardDuty, and CloudTrail.
  • Manage security tooling across the organization including EDR, MDM, DLP, and respond to SOC alerts.
  • Lead vulnerability management activities, coordinate patching, and support compliance assessments.

This company is a fully remote, international technology firm specializing in cloud and operational security. It has a diverse team of over 40 nationalities and a culture that values curiosity, ownership, and continuous improvement.