
Product Security Engineer
LaunchDarkly7 hours ago
Remote, United StatesMid Level
H1B sponsor
Base Salary
$116k - $188k/yr
Responsibilities
- Lead threat modeling engagements for higher-risk features and services.
- Help create repeatable Product Security processes and criteria for threat modeling engagements.
- Own end-to-end triage of CNAPP findings, including investigation, prioritization, routing, and closure.
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage.
- Review product engineering work, identify security issues, and recommend practical remediation paths.
- Use AI to accelerate security triage, threat-model drafting, code scanning, and other work while developing durable safe-use patterns.
- Improve security practices through documentation, office hours, and tooling improvements.
Requirements
- Require 2 to 4 years of full-time experience in a security-focused role, preferably AppSec, Product Security, or cloud security.
- Comfort reading and critiquing pull requests and writing small tools when useful.
- Experience participating in or leading threat modeling exercises using STRIDE, attack trees, or an equivalent structured approach.
- Working knowledge of cloud security posture; CNAPP exposure is a strong plus.
- Strong fundamentals in OWASP Top 10, authentication and authorization patterns, secrets management, and common cloud misconfigurations.
- Hands-on experience applying AI tooling to security or engineering work with specific examples of impact.
- Preferred experience with developer tools, SaaS platforms, feature management, bug bounty triage, internal security tooling, or open-source security projects.
- Familiarity with Go, Python, or TypeScript is preferred.
Benefits
- Geographic base pay ranges are provided for three US zones: $116,000–$159,500, $122,800–$168,850, and $136,500–$187,660.
- Benefits include restricted stock units, health insurance, vision insurance, dental insurance, and mental health benefits.
Tech Stack
Categories
About LaunchDarkly
LaunchDarkly sells a feature management platform for software teams, providing feature flags, experimentation, observability, and runtime controls for code and AI agents. Its SaaS products help release safely, target rollouts, and adjust behavior after deploy without redeploys. Founded in 2014 and headquartered in Oakland, CA, the company processes tens of trillions of flag evaluations daily and is used by over a quarter of the Fortune 500.