← Back to job listings
LA
Product Security Engineer
LaunchDarkly · United States
About The Role
Join LaunchDarkly's Product Security team as a Product Security Engineer. In this role, you will focus on threat modeling and cloud security posture, while also contributing to various aspects of product security. You will work closely with software engineers, product managers, and other security engineers, and report to the Director of Security. Your work will help developers move quickly without sacrificing security, and you will have the opportunity to leverage AI in your work.
- Lead threat modeling engagements on features and services, evolving the practice from on-request to repeatable.
- Own day-to-day triage of CNAPP findings, investigating, prioritizing, routing to service owners, and closing the loop.
- Partner with product engineering teams as a trusted reviewer, catching issues early and proposing paths forward.
- You're proactive by default. You'd rather spot drift early and fix the cause than chase symptoms after an incident
- You know security work moves at the speed of trust
- You treat AI as part of the toolkit. You're skeptical where you should be, aggressive where it pays off, and you want to work somewhere that's serious about both
- You're a good partner. You're helpful and direct, you say no with reasons and alternatives, and you don't mistake gatekeeping for rigor
- You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs
- You invest in relationships with the engineering, product, and leadership teams you work with
- You're security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what's wrong with them
- 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred
- Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus
- Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, and common cloud misconfigurations
- Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated
- Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent)
- Comfortable reading and critiquing pull requests in a modern stack. You don't need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps
- Experience with developer tools, SaaS platforms, or feature management
- Bug bounty triage experience (HackerOne, Bugcrowd)
- Contributions to internal security tooling or open-source security projects
- Familiarity with Go, Python, or TypeScript
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring