Close

Senior Product Security Engineer (USA Only, 100% Remote)

Close
Apply
9 hours ago
Remote, United StatesSenior

Responsibilities

  • Build a recurring product security review program covering threat modeling, high-risk code review, safe proof-of-concepts, backend, frontend, APIs, and integrations.
  • Improve static, dependency, secrets, dynamic, container, and cloud security testing while tuning tools and building focused automation.
  • Own vulnerability intake and remediation from bug bounty reports, scanners, penetration tests, audits, customers, and internal research.
  • Reproduce vulnerabilities, assess exploitability and impact, prioritize findings, track remediation, and verify fixes.
  • Serve as technical lead for the HackerOne bug bounty program.
  • Automate security alert ingestion, deduplication, enrichment, prioritization, and routing.
  • Improve dependency remediation workflows and protect credentials from untrusted packages and build steps.
  • Partner with Infrastructure on secrets inventory, graceful rotation, Vault-backed dynamic credentials, and AWS security guardrails.
  • Support audits, external assessments, documentation, security training, and efforts to raise the engineering security baseline.
  • Contribute to security incident investigation, containment, remediation, root-cause analysis, and follow-up improvements.

Requirements

  • Application security engineering experience with the ability to read unfamiliar code, reproduce exploits, and ship production-quality fixes.
  • Strong Python or TypeScript experience; fluency across backend and frontend systems is especially useful.
  • Experience finding vulnerabilities beyond conventional scanner results, including authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business-logic flaws.
  • Ability to threat-model designs, perform white-box code review, test running systems, and create safe reproductions without mishandling customer data or production systems.
  • Experience with some combination of SAST, DAST, software composition analysis, container scanning, secrets scanning, and cloud posture tooling.
  • Ability to tune security tools, integrate them into engineering workflows, reduce noise, and automate repetitive vulnerability-management work.
  • Experience assessing reachability, existing controls, customer impact, attack chains, exploitability, and business priority.
  • Ability to collaborate with engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers while retaining ownership through remediation.
  • Comfort working independently in a remote environment and turning ambiguous security problems into measurable plans.
  • Experience using coding agents and LLMs responsibly for investigation, code review, and engineering work while verifying their output.

Benefits

  • Competitive pay plus an organization-wide goal-based bonus.
  • Approximately five weeks of PTO initially, a one-week company winter holiday break, paid US holidays, and additional PTO accrual over time.
  • Choice of a standard five-day workweek or a four-day week at 80% pay, in agreement with the manager.
  • Paid parental leave for primary and secondary caregivers.
  • A one-month paid sabbatical every five years.
  • For US residents, medical plans with Close covering 99% of premiums, plus dental, vision, HSA, FSA, and company-paid long-term disability.
  • For US residents, a 401(k) match up to 6% with immediate vesting.
  • 100% remote role for candidates in the USA; the entire company meets in person annually.

Tech Stack

AnsibleApache KafkaAWSDockerElasticsearchFastAPIFlaskGitHub ActionsGraphQLKubernetesMongoDBPostgreSQLPythonReactReact NativeRedisTerraformTypeScriptVault

Categories

Close

About Close

201-500 employees

Close builds a sales CRM for founders, startups, and small businesses, combining pipeline management with built-in calling, email, SMS, automation, and AI (including its Chloe agent). It sells subscription SaaS that helps inside sales teams communicate with prospects and manage deals from one platform. Founded in 2013 and headquartered in Austin, Texas, Close is privately held, bootstrapped, and profitable.

Contact me