Source Job

Global

  • Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
  • Review cloud application architectures, build automation for security controls, and participate in incident response.
  • Communicate security risks to technical and non-technical audiences and champion improvements to security processes.

Application Security Cloud Security Java Python Go

20 jobs similar to Product Security Engineer

Jobs ranked by similarity.

Europe

  • Own cloud and product security across AWS and GCP, setting baselines for IAM, networking, data protection, and workload configuration.
  • Partner with platform, SRE, and product teams to embed practical security controls into developer workflows and automate guardrails in delivery pipelines.
  • Perform security architecture reviews, threat modeling, and incident response, and drive systemic improvements with meaningful security metrics.

We create intelligent software development tools used by more than 15 million users and 300,000 companies, including 88 of the Fortune Global Top 100. Our mission is to make development teams more productive and AI adoptable at scale, and we foster an open and inclusive workplace.

$175,000–$200,000/yr
US Canada Unlimited PTO

  • Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
  • Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
  • Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.

Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

$97,090–$133,590/yr
Canada

  • Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
  • Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
  • Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.

Europe Africa

  • Own and execute application, cloud, and API security across the platform.
  • Build detection, response, and hardening for a high-scale SaaS environment.
  • Collaborate with engineers to embed security into the SDLC and enterprise client requirements.

YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.

Global 6w PTO 26w maternity 26w paternity

  • Lead security reviews of architecture, code, and security-sensitive changes.
  • Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
  • Threat model new capabilities and build scalable guardrails that reduce recurring risks.

Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.

$120,000–$180,000/yr
US

  • Be a technical contributor on a global software engineering team in Product Security, building robust and scalable systems.
  • Design and implement software and automation tools for security use cases like software supply chain security and AI-powered vulnerability discovery.
  • Own SRE excellence, CI/CD, and datastore operations for mission-critical security services, ensuring flawless performance.

CrowdStrike is a global leader in cybersecurity, protecting organizations with an AI-native platform to stop breaches. Founded in 2011, the company fosters a culture of flexibility, autonomy, and responsible AI adoption, with a large-scale distributed system processing trillions of events daily.

$168,000–$238,000/yr
Global Unlimited PTO

  • Partner with engineering and product leadership to anticipate security problems and lead security architecture for strategic initiatives.
  • Identify and prioritise systemic security risks, codify security decisions into reusable artifacts, and conduct security architecture reviews.
  • Threat model systems, mentor security engineers, and anticipate emerging challenges to propose architectural responses.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and improve operational efficiency. With more than 50 million registered users and over 50% of the Fortune 100 as clients, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.

Europe

  • Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
  • Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
  • Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.

Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.

$104,300–$193,700/yr
US

  • Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
  • Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
  • Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.

Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.

Americas Unlimited PTO

  • Assess ServiceNow instance configurations against security baselines and identify misconfigurations.
  • Triage and validate customer-reported security findings related to instance configuration.
  • Partner with cross-functional teams to resolve complex security issues and drive systemic improvements.

ServiceNow is the AI control tower for business reinvention, enabling AI-powered workflows for enterprises. The company serves 85% of the Fortune 500 and fosters an AI-native culture focused on innovation and talent.

North America Unlimited PTO

  • Lead the design and implementation of secure enterprise solutions for Professional Services clients across AMER.
  • Assess complex security architectures and guide migrations to GitLab security capabilities, including CI/CD and compliance frameworks.
  • Provide technical leadership throughout the engagement lifecycle, from pre-sales scoping to delivery and enablement.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With more than 50 million registered users and 50% of the Fortune 100 as customers, GitLab fosters a high-performance, all-remote culture driven by values and continuous learning.

US

  • Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
  • Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
  • Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.

US

  • Design, build, and maintain production features with a strong product security focus.
  • Own vulnerability response from initial triage through coordinated disclosure and patched releases.
  • Conduct threat modeling and security-sensitive design reviews to help engineers make informed security decisions.

This company builds cloud-native infrastructure software with a strong focus on Kubernetes security. They operate as a remote-first, globally distributed team that values engineering ownership and autonomous work.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

$98,000–$116,000/yr
US

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.

Europe 16w maternity 16w paternity

  • Own identity, SSO, and device management across Google Workspace and macOS, automating joiner and leaver flows from day one.
  • Secure cloud and SaaS environments by managing IAM, cloud guardrails, and vulnerability management end to end.
  • Bring a security perspective to incidents and audits, using AI-assisted workflows to reduce manual work.

Maze is a user research platform that helps product teams build the right products faster by making user insights accessible. With less than 150 team members and a global remote workforce, Maze fosters a culture of transparency and inclusion.

US

  • Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
  • Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
  • Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.

Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.

$116,019–$145,024/yr
US 4w PTO 4w maternity 4w paternity

  • Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
  • Perform security assessments, vulnerability remediation, and lead key security programs.
  • Automate security processes and integrate DevSec practices into the software development lifecycle.

Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.

EMEA

  • Lead the Application Security program across all products, embedding security throughout the SDLC.
  • Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
  • Automate security testing pipelines and mentor engineers on secure coding and threat modeling.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.