
Product Security Engineer
LaunchDarklyBase Salary
$116k - $187k/yr
Responsibilities
- Lead threat modeling engagements for appropriately risky features and services.
- Help evolve product security from on-request engagements into a repeatable practice with clear engagement criteria.
- Triage CNAPP findings end to end by investigating, prioritizing, routing to service owners, and closing the loop.
- Identify systemic fixes for recurring security findings rather than performing one-off cleanup.
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage.
- Review product engineering designs and pull requests, explain security concerns, and propose practical paths forward.
- Use AI to accelerate triage, summarize findings, draft threat models, scan code, and reduce operational toil.
- Develop durable patterns for safe and effective AI use in security work.
- Improve the security baseline through documentation, office hours, and small tooling improvements.
Requirements
- 2 to 4 years of full-time experience in a security-focused role, preferably in AppSec, ProdSec, or cloud security.
- Comfort reading and critiquing pull requests in a modern software stack and writing small tools when useful.
- Experience participating in or leading threat modeling exercises using STRIDE, attack trees, or an equivalent structured approach.
- Working knowledge of cloud security posture; CNAPP exposure is a strong plus.
- Strong fundamentals in the OWASP Top 10, authentication and authorization patterns, secrets management, and common cloud misconfigurations.
- Hands-on experience applying AI tooling to security or engineering work with specific examples of impact.
- Experience with developer tools, SaaS platforms, or feature management is a plus.
- Bug bounty triage experience with HackerOne or Bugcrowd is a plus.
- Familiarity with Go, Python, or TypeScript is a plus.
- Contributions to internal security tooling or open-source security projects are a plus.
Benefits
- Restricted Stock Units (RSUs)
- Health, vision, and dental insurance
- Mental health benefits
- Geographic pay zones within the United States
Tech Stack
Categories
About LaunchDarkly
LaunchDarkly is the runtime control layer for the AI era. For over a decade we have helped engineering teams control what ships in production, starting with feature management and evolving into the infrastructure that governs how software and AI agents behave after deploy. With CodeControl and AgentControl, teams can update agent behavior in milliseconds, automatically roll back when something drifts, and govern every agent and feature across the organization from one place. No redeploys required. LaunchDarkly processes more than 50 trillion flag evaluations per day and serves some of the most demanding engineering teams in the world, including over a quarter of the Fortune 500. Founded in 2014 in Oakland, California by Edith Harbaugh and John Kodumal, LaunchDarkly has been named to the Forbes Cloud 100 for five consecutive years, Fast Company's Most Innovative Companies list, and the Inc. 5000.