Source Job

US Canada Germany

  • Embed security into Firefox, Mozilla VPN, and other mission-critical products.
  • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation.
  • Partner with engineers to integrate security throughout the software development lifecycle as a core design principle.

Python Go Java JavaScript AWS

20 jobs similar to Staff Security Engineer, Product Security

Jobs ranked by similarity.

$136,595–$189,000/yr
US Unlimited PTO

  • Define and drive the strategic roadmap for proactive security vulnerability analysis.
  • Establish the technical vision and program for integrating robust security controls at every stage of the SDLC.
  • Lead collaborative and cross-functional threat modeling initiatives for core systems, new features, and evolving services.

Modern Health is a mental health benefits platform for employers, offering access to resources for emotional, professional, social, financial, and physical well-being. They are a fully remote workforce known for their culture centered around empathy and accountability, with a drive to win.

$200,000–$250,000/yr
US

  • Partner with Product teams to ensure that products are designed, built, and operated securely.
  • Conduct threat modeling activities with Product teams to ensure product threats are understood, documented, and mitigated.
  • Review and analyze product source code to identify security vulnerabilities and providing recommendations for secure implementation.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm is a remote-first company and offers competitive benefits anchored to their core value of people come first.

  • Responsible for designing and implementing security best practices at each stage of the system development lifecycle.
  • Works in partnership with cross-functional teams to act as a security subject matter expert, while supporting and advancing the security of ConnectWise applications.
  • Conducts security assessments, threat modeling, and vulnerability reporting and develops security architecture patterns for implementing new solutions and products.

ConnectWise is a community-driven software company dedicated to the success of technology solution providers, with a suite that helps over 45,000 of their partners manage their businesses better. The company has over 3,000 colleagues in North America, EMEA and APAC and has an inclusive and positive culture.

Europe 5w PTO

  • Conduct regular security assessments, vulnerability scanning, and penetration testing of Veeam products and services
  • Work with development teams to integrate secure development practices into the software development lifecycle
  • Collaborate on the design and implementation of security within public cloud environments

Veeam is the #1 global market leader in data resilience, believing businesses should control all their data whenever and wherever they need it. Based in Seattle, Veeam protects over 550,000 customers worldwide who trust Veeam to keep their businesses running.

Canada 4w PTO

  • Design and drive security solutions across product and internal applications
  • Conduct threat modeling for existing systems and new product initiatives
  • Partner with engineering teams to embed security into development and delivery workflows

Shakepay is reimagining financial services to give every Canadian their fair shake by making buying and earning bitcoin fast, easy, and secure. Since 2015, more than one million Canadians use Shakepay to grow their bitcoin savings; they are regulated across all Canadian provinces and territories, and backed by renowned venture capitalists with a funding of $44M.

$184,000–$252,000/yr
US

  • Lead secure design reviews and threat modeling for AI-driven products.
  • Build and maintain security automation and governance frameworks.
  • Drive software supply chain security and vulnerability reduction.

AlphaSense empowers companies to make smarter decisions by providing market intelligence and search functionality driven by AI. With over 2,000 employees globally and offices in multiple countries, they foster a collaborative and innovative environment.

  • Conduct browser security audits.
  • Execute on SERP security mitigations.
  • Manage application security scanning infrastructure setup.

DuckDuckGo is an online protection company committed to raising the standard of trust online. The team of 300+ is remote-first and has a culture of trust, inclusivity, and empowered project management.

Global

  • Integrate security activities across all SDLC phases: requirements, design, implementation, testing, deployment, and maintenance.
  • Run threat modeling sessions (e.g. STRIDE) for new and existing systems; identify threats, attack paths, misconfigurations, and insecure design patterns.
  • Perform security-focused code reviews to identify vulnerabilities and risky implementations; provide clear, actionable guidance on secure coding patterns and best practices.

Infiterra's B2B SaaS platform helps IT Distributors and Managed Service Providers (MSPs) automate and grow their subscription business. With 100+ customers in 75 countries, they're recognized for innovation and global impact. Infiterra fosters a collaborative and growth-oriented culture, allowing you to be part of a dynamic, forward-thinking team.

$170,000–$190,000/yr
US Unlimited PTO 13w maternity 9w paternity

  • Engineer and deploy clever controls so security incidents stay rare.
  • Lead incident response efforts and security tool deployments.
  • Embrace AI and automation to protect the enterprise at machine speed.

Chainguard provides a secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains. They value customer obsession, prioritize intentional action, and trust each other.

Canada

  • Design, develop, and deliver security-focused features.
  • Collaborate with engineering teams for secure decisions.
  • Maintain and enhance security-critical components.

Jobgether is a platform connecting job seekers with partner companies. They foster a remote, collaborative environment that encourages transparency, continuous learning, and innovation.

Canada 4w PTO

  • Concevoir et piloter des solutions de sécurité pour les produits et les applications internes
  • Réaliser des exercices de modélisation des menaces pour les systèmes existants et les nouvelles initiatives produit
  • Collaborer avec les équipes d’ingénierie afin d’intégrer la sécurité dans les flux de développement et de livraison

Shakepay aims to reimagine financial services and give every Canadian their fair share by introducing the golden age of Bitcoin. They have built their culture around doing work that matters, winning as a team, and celebrating successes.

US 4w PTO

  • Lead a high-performing engineering team, managing hiring, performance, and career growth while fostering an inclusive culture.
  • Build the security modular platform, driving architecture, design, and implementation with emphasis on scalability, reliability, and low latency.
  • Execute technical strategy, partnering with architects and principal engineers to shape long-term vision, modernization, AI integration, and security best practices.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. They operate across a range of markets and invest in new advanced technologies to unlock the power of data and to innovate. A FTSE 100 Index company, they have a team of 23,300 people across 32 countries.

Canada

  • Architect, develop, and scale automation frameworks, integrations and agentic workflows across Mozilla’s workplace technology ecosystem.
  • Lead end-to-end engineering of lifecycle workflows (onboarding, off-boarding, access provisioning) using APIs, event-driven architectures and intelligent agentic flows that reduce manual touchpoints and accelerate user access.
  • Build and maintain reusable libraries, connectors, SDKs and agent orchestration layers that enable faster, safer AI-enabled productivity at scale.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. They make pioneering brands like Firefox, the privacy-minded web browser and are focused on making the internet better for people. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

$205,000–$275,000/yr
US Unlimited PTO

  • Establish and execute a vision and strategy for Product Security, AppSec, and Privacy Engineering across all product lines.
  • Define and enforce Security and Privacy standards and policies within the Software Development Lifecycle (SDLC) and CI/CD pipelines.
  • Drive incident response and vulnerability management processes for all product-related issues.

Flock Safety is the leading safety technology platform, helping communities thrive by taking a proactive approach to crime prevention and security.

US Unlimited PTO

  • Architect and implement secure AWS configurations.
  • Embed security into CI/CD pipelines and repos using policy-as-code tools.
  • Conduct threat modeling sessions and risk‑driven design reviews early in development.

OnePay is an all-in-one financial platform driven by a simple mission: better money makes life better. They are backed by Walmart and Ribbit Capital, and deeply embedded with the distribution of the world’s largest omnichannel retailer.

$20–$22/hr
Global

  • Develop automated security testing for centralized security libraries which scale directly with developer needs and enable them to write secure code more easily.
  • Participate in the review and improvement of secure software development lifecycle (SDLC) processes.
  • Have significant ownership in and evangelize security training with development teams.

ATPCO is the world's primary source for air fare content, holding over 200 million fares across 160 countries. Every day, the travel industry relies on ATPCO's technology and data solutions to help millions of travelers reach their destinations efficiently. They have a remote-first culture rooted in trust, transparency, and belonging where your wellbeing comes first.

$100,649–$174,459/yr

  • Design and implement security solutions across enterprise platforms and cloud environments.
  • Perform threat modeling and security risk assessments for new features and platforms.
  • Partner with product teams to embed security requirements early in the SDLC.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. As a FTSE 100 Index company listed on the London Stock Exchange, they have a team of 22,500 people across 32 countries and are committed to investing in their people.

Europe Middle East Africa

  • Work with diverse business and technology owners
  • Participate in offensive security engagements including external adversarial emulation.
  • Perform security audits to discover, communicate, and recommend remediation activities for vulnerabilities

ServiceNow is a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work.

$78,522–$98,684/yr
US

  • Implement disciplined software engineering practices to design, develop, and maintain secure, scalable application components.
  • Contribute to technical design and documentation, maintain source code, and execute enhancements with clear acceptance criteria.
  • Perform testing and quality activities, supporting defect resolution, and partnering with security and operations stakeholders.

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Their specialties include cybersecurity, cloud modernization, software development, and data analytics.

Global 6w PTO

  • Build and ship security features for North, our AI workspace platform
  • Develop autonomous agents that talk to sensitive enterprise data
  • Write and ship minimal code that runs in low-resource environments, and has highly stringent deployment mechanisms

Cohere's mission is to scale intelligence to serve humanity, training and deploying frontier models for developers and enterprises building AI systems. They are a team of researchers, engineers, and designers passionate about their craft, believing that a diverse range of perspectives is a requirement for building great products.