Product Security Engineer
The job description
Tech stack. Threat modeling (STRIDE), secure design review, SAST/DAST/SCA tooling, bug bounty triage, OWASP ASVS, Python or JavaScript, security champions programs, design documentation
About the role
You will be the dedicated security partner embedded with product teams at a SaaS company, shaping features from initial design sketches through launch and into maintenance. Unlike a consulting reviewer who appears at the end, you sit with engineers, learn the roadmap, and make security a natural part of how the product gets built. You will run threat models, triage external reports, and grow a network of security champions. This role matters because products designed securely require far less heroic remediation later, and you are the person who makes secure-by-design the default rather than the exception teams aspire to. You will also run the security champions program that embeds trained advocates in every product squad, multiplying your reach far beyond what one engineer can review alone.
What you will achieve
- Threat-model every significant product initiative, with security requirements written into the design documents engineers genuinely read and reference.
- Triage bug bounty submissions within 48 hours, maintaining strong researcher relationships and keeping duplicate rates low.
- Build the security champions program to 20+ embedded engineers who carry secure practices back into their own teams independently.
- Drive remediation of product security findings to 85 percent closure within SLA each quarter, with stragglers escalated early.
- Ship reusable security components, such as authentication libraries and input validation patterns, that teams adopt voluntarily because they save development time.
What you will bring
Must-haves
- 2 to 5 years in product security, application security, or software engineering with deep, sustained security involvement.
- Ability to threat-model complex distributed systems and prioritize the attack paths that genuinely matter to adversaries.
- Strong web security fundamentals: authentication design, session management, injection flaws, and access control failures.
- Experience triaging external security reports with fairness, technical rigor, and prompt researcher communication.
- Communication skills to influence engineers without formal authority, through guidance that is genuinely useful.
- Familiarity with modern SDLC tooling and how security gates fit naturally into CI/CD pipelines developers own.
- Product sense: you understand that security recommendations must survive contact with ship dates.
Nice-to-haves
- Experience running or scaling a security champions program across a large engineering organization.
- Background in privacy engineering or data protection requirement implementation.
- Public bug bounty participation or published security advisory authorship.
- Familiarity with mobile or client-side security concerns.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta