Skip to content
← Back to job listings

Staff Product Security Engineer

Greenlight · Atlanta, United States

External listingfull-timeabout 1 month ago

About The Role

Join our growing Security team as a Staff Product Security Engineer. In this role, you will be responsible for the end-to-end security of our consumer products, digital platform, and emerging hardware device line. You will lead security architecture/design reviews, conduct penetration testing, manage PSIRT operations, and champion secure AI adoption. This position offers a remote-friendly work environment and a comprehensive benefits package.

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams, translating threats into actionable, risk-rated engineering remediations.
  • Conduct hands-on penetration testing and security assessments across the full product stack, producing actionable reports for engineering and leadership.
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, and managing coordinated disclosure with external researchers.
  • PSIRT operational experience from vulnerability intake and triage. You are fluent in CVE, CVSS, FIRST PSIRT frameworks
  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware. You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red-team engagements
  • Strong programming ability and capability to review code, build security tools, automate workflows and be credible with the engineering teams you partner with
  • 10+ years of product security experience spanning application security, cloud security, and secure SDLC. you will have full SDLC experience from design through development, deployment and incident response
  • Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications
  • You understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development. You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic
  • Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor
  • Strong knowledge of programing language & frameworks (i.e. Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies and infrastructure (i.e. AWS, GCP, Kubernetes, Ambassador, Helm), and databases (i.e. MySQL, DynamoDB, Redis)
  • Ability to influence without authority, mentor without managing , and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance and executives alike
  • Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems
  • Deep hands down AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and have practical experience with MITRE
  • Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience
  • Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly

This is an external listing. JobSpring does not represent or verify the employer. Report this listing