10 days ago
Remote, United StatesSenior
Base Salary
$180k - $180k/yr
Responsibilities
- Perform threat modeling and security design reviews for new products and features.
- Assess application architecture, APIs, authentication, authorization, data flows, cloud services, containers, serverless technologies, and third-party integrations.
- Identify, validate, prioritize, and help remediate vulnerabilities in partnership with engineers.
- Own and improve SAST, DAST, dependency scanning, secret scanning, and infrastructure-as-code scanning tools and workflows.
- Build automation for repetitive product security work using Python, JavaScript, or a similar language.
- Create secure design patterns, coding guidance, standards, and documentation.
- Support product security incident response from investigation and containment through root cause analysis and long-term remediation.
- Evaluate emerging risks in cloud and AI-enabled products, including agents, large language model applications, and MCP integrations.
Requirements
- Experience in product security, application security, software engineering, penetration testing, or a comparable role involving how applications are built and broken.
- Ability to analyze complex systems, trace data flows, identify trust boundaries, and assess practical security risks.
- Experience with threat modeling, architecture reviews, vulnerability validation, and application security assessments.
- Comfort working with APIs, cloud services, containers, serverless technologies, and CI/CD pipelines.
- Experience with SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning and tuning their results.
- Ability to read and write code and automate security work using Python, JavaScript, or a similar language.
- Experience securing AI-enabled products, agents, large language model applications, or MCP integrations.
- Deep experience with identity, authentication, authorization, or multi-tenant application security.
- Real-world experience applying OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST frameworks.
- Strong judgment and communication skills for working with technical and non-technical stakeholders across multiple products and engineering teams.
Benefits
- Flexible work hours and flexible vacation.
- 401(k) match, parental leave, team events, wellness budget, and learning reimbursement.
- Fully remote work is available within the United States, or the role may be based in NYC or another office hub.
- Most employees on the team work East Coast hours.
- Remote work outside company offices may be subject to New York State tax withholding.
