GrepJob
Lattice

Product Security Engineer

Lattice
Apply
about 3 hours ago
Toronto, Canada
Mid Level / Senior
H1B Sponsor

Responsibilities

  • Partner with engineers to identify, triage, and remediate security issues in product features and services.
  • Participate in security reviews and threat modeling for new features and systems.
  • Perform security-focused code reviews and help identify common vulnerabilities.
  • Contribute to secure-by-default patterns, libraries, and tooling in our TypeScript-based stack.
  • Help implement and operate security tooling (SAST, DAST, dependency scanning, etc.).
  • Support vulnerability management workflows, including internal findings and bug bounty reports.
  • Assist in investigating security issues and assessing risk and impact.
  • Collaborate with platform and infrastructure teams to improve application and cloud security posture.
  • Contribute to improving security practices in AWS-based environments.
  • Assist in identifying and mitigating risks in AI/LLM-powered features.
  • Contribute to security guidance, documentation, and training for engineering teams.
  • Help improve how security is integrated into the development lifecycle.

Requirements

  • 1–3+ years of experience in product security, application security, or software engineering.
  • Experience writing and maintaining code in JavaScript/TypeScript (or similar languages like Python or Ruby).
  • Familiarity with common web and API vulnerabilities (e.g., OWASP Top 10).
  • Exposure to security testing tools (SAST, DAST, dependency scanning, etc.).
  • Experience working in or with cloud environments (AWS or similar).
  • Ability to identify common security risks and suggest practical mitigations.
  • Understanding of secure coding practices and basic security controls.
  • Strong communication skills and ability to work closely with engineering teams.
  • Willingness to ask questions, learn quickly, and take ownership of well-scoped problems.

Benefits

  • Medical, dental, and vision insurance.
  • Life, AD&D, and disability insurance.
  • Emergency weather support and wellness apps.
  • Paid parental leave and paid time off inclusive of holidays and sick time.
  • Commuter and parking accounts.
  • Lunches in the office and internet/phone stipend.
  • One-time WFH office set-up stipend.
  • 401(k) retirement plan and financial planning.
  • Learning and development budget.

Tech Stack

AWSGraphQLJavaScriptKubernetesNestJSNext.jsPythonRubyTypeScript

Categories

AI & MLSecurity