Source Job

$175,000–$200,000/yr
US Canada Unlimited PTO

  • Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
  • Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
  • Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.

Product Security Cloud Security Python Threat Modeling

20 jobs similar to Product Security Engineer

Jobs ranked by similarity.

US

  • Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
  • Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
  • Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.

Global

  • Define the security architecture for Theo.
  • Secure agent identity and authority.
  • Lead threat modelling and secure design.

FirstPrinciples is a research company building AI for scientific discovery. We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally.

US

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
  • Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.

Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

Global 6w PTO 26w maternity 26w paternity

  • Lead security reviews of architecture, code, and security-sensitive changes.
  • Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
  • Threat model new capabilities and build scalable guardrails that reduce recurring risks.

Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

Global

  • Build and deploy security tooling across endpoint management, supply-chain, infrastructure, and application layers.
  • Identify and remediate security gaps across production systems and development pipelines.
  • Lead incident response end-to-end and partner with engineering on secure design reviews.

Tempo is a layer-1 blockchain built for stablecoins and real-world payments, leveraging expertise from Stripe and Paradigm. We are a team of crypto-optimists moving fast to build infrastructure for onchain economic flows.

US

  • Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
  • Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
  • Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.

$120,000–$180,000/yr
US

  • Be a technical contributor on a global software engineering team in Product Security, building robust and scalable systems.
  • Design and implement software and automation tools for security use cases like software supply chain security and AI-powered vulnerability discovery.
  • Own SRE excellence, CI/CD, and datastore operations for mission-critical security services, ensuring flawless performance.

CrowdStrike is a global leader in cybersecurity, protecting organizations with an AI-native platform to stop breaches. Founded in 2011, the company fosters a culture of flexibility, autonomy, and responsible AI adoption, with a large-scale distributed system processing trillions of events daily.

$250,000–$275,000/yr
US

  • Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
  • Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
  • Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.

Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.

Europe

  • Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
  • Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
  • Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.

Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.

$149,200–$214,500/yr
US

  • Apply practical security principles and AI-native workflows to deliver technical solutions to end users and internal teams.
  • Lead and deliver impactful enhancements for the Data Security team, enforcing security and privacy standards.
  • Design and implement customer data governance solutions that enable security and privacy by design.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. Over 4,500 enterprises trust their behavioral AI platform.

Canada

  • Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
  • Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.

LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.

$97,090–$133,590/yr
Canada

  • Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
  • Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
  • Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.

US 4w PTO 16w maternity 16w paternity

  • Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
  • Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
  • Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.

Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.

North America Unlimited PTO

  • Lead the design and implementation of secure enterprise solutions for Professional Services clients across AMER.
  • Assess complex security architectures and guide migrations to GitLab security capabilities, including CI/CD and compliance frameworks.
  • Provide technical leadership throughout the engagement lifecycle, from pre-sales scoping to delivery and enablement.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With more than 50 million registered users and 50% of the Fortune 100 as customers, GitLab fosters a high-performance, all-remote culture driven by values and continuous learning.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

$180,000–$200,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
  • You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
  • You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.

Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

$108,000–$140,000/yr
US

  • Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
  • Build and deploy cloud infrastructure using Infrastructure as Code technologies.
  • Collaborate with the research team to support targeting and collection of new data sources.

SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.