Source Job

US 4w PTO 16w maternity 16w paternity

  • Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
  • Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
  • Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.

Application Security Threat Modeling Penetration Testing OWASP Secure Coding

20 jobs similar to Senior Product Security Engineer (Contract)

Jobs ranked by similarity.

UK 5w PTO

  • Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
  • Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
  • Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.

Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.

US

  • Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
  • Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
  • Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

United States Canada Dominican Republic Unlimited PTO

  • Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
  • Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
  • Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.

Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.

$250,000–$275,000/yr
US

  • Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
  • Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
  • Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.

Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.

$109,000–$156,000/yr
US

  • Define and implement secure software development practices including secure coding standards and CI/CD integration.
  • Lead Shift Left security initiatives and threat modeling to embed security early in the development lifecycle.
  • Drive application security for AI and LLM applications through red teaming, guardrails, and risk assessments.

$217,000–$288,000/yr
US Unlimited PTO 18w maternity 18w paternity

  • Champion a secure by default culture, building defense in depth into frameworks and processes.
  • Develop security requirements and work directly with teams to build them into new applications.
  • Run security risk assessments, hands-on penetration testing, and threat modeling.

Grow Therapy is a three-sided marketplace that empowers therapists and patients by providing technology and insurance support. The company has raised over $328M in funding, employs roughly 145 engineers, and values a mission-driven culture.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

$180,000–$180,000/yr
US Unlimited PTO

  • Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
  • Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
  • Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.

YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

UK Unlimited PTO

  • Penetration test web applications, APIs, and mobile applications for clients across various industries.
  • Work with technical and non-technical stakeholders to identify vulnerabilities and recommend remediations.
  • Collaborate closely with developers and teams to strengthen application security and drive continuous improvement.

Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing. They are a small team with big plans, recently securing Series A funding.

US

  • Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
  • Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
  • Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.

Canada Unlimited PTO

  • Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
  • Partner with engineering to embed security controls into production.
  • Lead vulnerability management and incident response activities.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.

Global 6w PTO 26w maternity 26w paternity

  • Lead security reviews of architecture, code, and security-sensitive changes.
  • Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
  • Threat model new capabilities and build scalable guardrails that reduce recurring risks.

Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.

US Unlimited PTO 18w maternity 18w paternity

  • Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
  • Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
  • Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.

Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

US

  • Assist customers with application security testing tool configurations and triage support.
  • Lead AppSec Program maturity assessments using frameworks like BSIMM and SSDF.
  • Develop Strategic Roadmaps and deliver presentations to executive leadership.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. It is a recognized pioneer in application security, providing SAST, SCA, and DAST solutions.

$170,000–$190,000/yr
US Unlimited PTO

  • Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
  • Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
  • Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.

Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

Global Unlimited PTO

  • Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.

Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.