Source Job

Europe

  • Champion and implement security best practices and automated tooling across Spotify's infrastructure and platforms.
  • Partner closely with teams to integrate security throughout the software development lifecycle from design to deployment.
  • Conduct threat modeling, security reviews, and risk assessments for both AI and non-AI systems.

Security Engineering Java Python Cloud Infrastructure Threat Modeling

20 jobs similar to Security Engineer- Product Security

Jobs ranked by similarity.

Spain

  • Play a key role in protecting and strengthening large-scale cloud-native applications that power next-generation AI infrastructure.
  • Work at the intersection of software engineering and cybersecurity, ensuring security is embedded throughout the software development lifecycle.
  • Collaborate cross-functionally to identify and remediate vulnerabilities in complex distributed systems.

Our partner is a company building large-scale cloud-native applications that power next-generation AI infrastructure. They have a high-impact security engineering environment with a collaborative and innovative culture focused on trust, learning, and impact.

US

  • Secure AI Systems and Use AI to Scale Security.
  • Deliver Application Security Reviews.
  • Advance CI/CD Pipeline Security.

Smartsheet helps people and teams achieve their goals with seamless work management and scalable solutions. They empower teams to automate tasks, uncover insights, and scale smarter, fostering a culture of innovation and impact with a focus on challenge and purpose.

$64,200–$74,900/yr
Europe

  • Define and own the security strategy: Oversee comprehensive security across cloud, network, and application layers. Partner with engineering on vulnerability management.
  • Secure AI & ML integrations: Establish and enforce security guardrails for AI pipelines and LLM deployments. Protect against AI-specific threats and ensuring model safety.
  • Risk & Incident Management: Assess security risks, monitor processes continuously, and coordinate effective incident response and recovery efforts.

Musixmatch is a leading music metadata company with the world’s largest lyrics catalog and a community of over 80M contributors. They are the trusted global partner of companies like Spotify, Apple, Amazon Music, and Google. They're a bunch of creatives who care about their work. They believe that participation and collaboration are key to getting things done well.

$175,000–$185,000/yr
US Canada

  • Work closely with development teams, product managers, and third-party groups to ensure AutoFi’s products, services, cloud environments, internal systems, and vendor ecosystem are secure.
  • Contribute to secure design reviews, application security standards, vulnerability management, security monitoring, incident response, threat hunting, and third-party security assessments.
  • Define, implement, and maintain security practices, standards, and controls across AutoFi’s products, services, cloud environments, and internal systems.

AutoFi is the leading provider of digital commerce technology that powers the sales and finance experiences for the most innovative brands and dealers in automotive. Their dynamic selling platform empowers dealers to sell vehicles more efficiently and profitably, both online and in the showroom. They are funded for years of future growth and backed by investors.

$155,000–$175,000/yr
US

  • Lead security architecture reviews for new and existing applications.
  • Develop, enforce, and continuously refine secure coding standards across engineering teams.
  • Continuously improve threat modeling frameworks across application components.

Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. They empower credit unions and banks by creating cutting-edge digital experiences. At Lumin, their culture is built on trust in expertise and decisions, respect for diverse perspectives and talents, and boldness in pursuing new ideas.

US 4w PTO 12w maternity 12w paternity

  • Partner with Product and Engineering teams to integrate security into application design and development, leading threat modeling and secure code reviews.
  • Develop and implement automated security guardrails across the SDLC, investigate and prioritize application security findings.
  • Promote secure coding practices through training and coaching, and create security standards and procedures that scale across teams.

Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions and builds a full-stack, flexible, digital & increasingly AI-native insurance platform. We are a remote-first company wholly owned and funded by State Farm, with a culture that prioritizes inclusivity and positive collaboration.

US Canada Unlimited PTO

  • Own and improve the secure software development lifecycle, perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features.
  • Drive vulnerability management across internal reviews, bug bounty, pentests, and other research signals, ensuring findings are validated, prioritized, and tracked through remediation.
  • Configure and improve AppSec tooling and integrations, and use AI to automate and scale security processes while validating outputs with strong engineering judgment.

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion.

UK Global

  • Lead and own the ongoing operation and maintenance of Samsara’s vulnerability management program.
  • Collaborate with engineering teams to track and support the remediation of identified vulnerabilities.
  • Champion Samsara’s cultural principles in daily work.

Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. As a recently public company with a global team, they foster a culture of rapid career development and encourage employees to architect their own careers.

Canada Unlimited PTO

  • Partner with engineering teams to design, build, and operate secure-by-default cloud infrastructure across AWS and Google Cloud.
  • Build reusable Terraform modules and policy-as-code guardrails to make secure implementation easier for engineering teams.
  • Operate CSPM/CNAPP tooling and drive remediation of cloud vulnerabilities and misconfigurations.

Fullscript is a health technology company that provides a platform for practitioners to access clinical insights, lab interpretations, and high-quality supplements, serving over 125,000 practitioners and 10 million patients. The company has a remote-first culture, emphasizes work-life balance, and values inclusivity and continuous learning.

UK Unlimited PTO 18w maternity 12w paternity

  • Embed security into CI/CD pipelines and product development as a technical leader.
  • Drive cross-team influence and own hard security challenges in a cloud-native environment.
  • Work in a remote-first culture focused on customer obsession and intentional action.

Chainguard provides hardened, secure, and production-ready builds of open source software to help organizations build faster and stay compliant. Backed by leading investors including Sequoia Capital and Kleiner Perkins, Chainguard serves Fortune 500 enterprises and global industry leaders.

Europe

  • Join the security team to build world-class security into products, focusing on operations, monitoring, and incident response.
  • Proactively improve security across codebase, product, cloud, and customer deployments.
  • Work as a generalist covering all facets of security, from application testing to threat modeling.

Sourcegraph builds the world's most powerful code intelligence platform, helping developers and agents navigate complex codebases. They are a globally distributed team backed by a16z, Sequoia, and Redpoint, with a culture of high agency and direct communication.

US

  • Enable software engineering teams to continuously improve the security posture of products and SaaS environments through AppSec and DevSecOps expertise.
  • Serve as the go-to AppSec expert, mentoring engineers on secure design patterns and coding practices while collaborating on threat models and design reviews.
  • Lead automation of vulnerability management tooling across CI/CD pipelines, perform security code reviews, and contribute to compliance strategies.

Hypori is a high-growth cybersecurity SaaS company transforming how organizations think about secure mobility. Backed by $55M in funding from investors including UBS and AE Industrial Partners, the company is expanding into new commercial and regulated markets.

$153,986–$192,482/yr
US

  • Design, develop, and implement cloud security architecture solutions in Microsoft Azure.
  • Build and maintain security automation using Infrastructure as Code (IaC) tools.
  • Collaborate with development teams to embed security into CI/CD pipelines.

Hanger, Inc. is the world's premier provider of orthotic and prosthetic (O&P) services and products, offering advanced O&P solutions. With 160 years of excellence, Hanger employs many to help people achieve new levels of mobility and freedom.

$140,000–$160,000/yr
US Canada Unlimited PTO

  • Build detections and security signal pipelines in Datadog.
  • Serve as the subject matter expert on AWS Cloud and on-prem infrastructure security.
  • Act as the technical lead during security incidents, including investigation and remediation.

Voltus is the leading platform connecting distributed energy resources to electricity markets, delivering less expensive, more reliable, and more sustainable electricity. Our company appears to be a remote-first company, and values diversity and inclusion.

US

  • Lead and mentor a high-performing team of security engineers, setting technical direction and standards for excellence.
  • Define and execute the security roadmap for infrastructure, remote access, endpoints, and M&A.
  • Design and implement security controls across cloud, production, and corporate environments.

Anduril Industries is a defense technology company transforming U.S. and allied military capabilities with advanced technology, powered by Lattice OS. They bring the expertise and business model of innovative companies to the defense industry, focusing on autonomy, AI, and networking.

US

  • Provide security automation and application development expertise.
  • Assist in detection and alerting through various security tools.
  • Evaluate new technologies and processes that enhance security capabilities.

Ivanti manages, automates, and protects data and technology to empower continuous innovation. Their AI-powered platform brings IT and Security teams together around a single, trusted system of record enabling smarter decisions. They serve 34,000 customers across 149 countries.

  • Design, implement, and manage the security posture for all AI and Machine Learning initiatives.
  • Collaborate with IT & Development teams to integrate advanced AI security tooling.
  • Develop and maintain a curated portfolio of approved AI tools and services.

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations. They leverage over 24 years of industry-leading expertise and its unified E360 RCM intelligent automation platform. They are a multi-year recipient the Top Workplaces award.

Latin America

  • Design and implement guardrails for agentic AI systems, including tool access controls and step-level validation.
  • Build runtime security controls like interceptors, policy enforcement, and kill-switches for AI behavior.
  • Implement non-human identity access controls, observability, and threat modeling for AI-driven activity.

Backblaze is the object storage leader in the open cloud movement, offering cloud storage built to unlock budgets and unburden administrators. Founded in 2007, the company has over $100m in revenue and manages over three billion gigabytes of data for 500K+ customers across 175+ countries, with a culture of innovation and inclusion.

Global Unlimited PTO

  • Conduct threat modelling reviews of Technical Design Documents (TDDs) and provide actionable security recommendations early in the design process.
  • Perform application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept development.
  • Investigate, triage, and respond to Bug Bounty program submissions, validating findings and driving timely remediation with engineering teams.

MoonPay is a unified payments platform for digital currency. Trusted by over 30 million customers and over 500 ecosystem partners, the company is committed to building a fairer, more open financial system with a culture of accountability and inclusivity.

United States

  • Perform penetration testing and design reviews to identify vulnerabilities and insecure designs.
  • Maintain and build internal tools to automate security efforts, including SAST and DAST testing.
  • Identify vulnerabilities, demonstrate business impact, and articulate risk to drive prioritization.

Brex is the intelligent finance platform that enables companies to spend smarter and move faster in over 200 markets. With tens of thousands of customers including DoorDash, Coinbase, and Zoom, Brex fosters a diverse and inclusive team culture where collaboration with some of the brightest minds in the industry is key.