Staff Application & Product Security Engineer

Job not on LinkedIn

🔥 13 hours ago

🇺🇸 United States – Remote

💵 $160k - $180k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 7%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Council on Legal Education Opportunity (CLEO)

Council on Legal Education Opportunity (CLEO)

1 - 10 employees

Founded 1968

📚 Education

🤝 Non-profit

🌍 Social Impact

Education • Non-profit • Social Impact

The Council on Legal Education Opportunity (CLEO) is a national non-profit organization established in 1968 with the mission of increasing access to legal education for underrepresented student communities. As a 501(c)(3), CLEO is focused on preparing students to successfully enter law school and achieve success in the legal profession through various support programs. These include pre-law pipeline programs, LSAT preparation, academic support, and networking opportunities through its extensive alumni network. CLEO's overarching goal is to foster diversity, equity, and inclusion within the legal field, thus promoting social justice and equality in the profession.

📋 Description

• Own and mature Cleo’s secure software development lifecycle, including security requirements, threat modeling, and design reviews • Run and tune SAST, SCA, secrets detection, container, and IaC scanning • Build reusable secure patterns, reference implementations, and policy-as-code controls • Lead developer security enablement through Security Champions, training, remediation guidance, office hours, and self-service capabilities • Run risk-based triage, remediation, verification, SLAs, escalations, and exceptions for application and product vulnerabilities • Reproduce externally reported vulnerabilities and validate patches before release • Own and coordinate penetration-testing engagements and targeted testing • Run the Vulnerability Disclosure Program and coordinate researcher communications and disclosure • Coordinate the CVE lifecycle and support product-security incident response • Own application and product-security controls in Cleo’s NIST CSF 2.0 program, tracking maturity, closing gaps, and producing audit evidence • Own the security posture of SaaS and customer-hosted products, including secure defaults, authentication, session controls, RBAC, tenant isolation, admin data access, configuration, and hardening guidance • Own the Product Security Roadmap with Product Management, the CTO, and Architecture • Prioritize and ship security features including SSO/SAML upgrades, RBAC redesign, endpoint-level access control, and customer-requested controls • Represent security in RTE Sync and Boundary Review • Triage customer vulnerability-scan findings and penetration-test reports • Answer security RFIs and enhancement requests • Author customer-facing advisories, security release notes, and hardening documentation • Own threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows • Build controls for prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply-chain risk • Apply OWASP Top 10 for LLM Applications and NIST AI Risk Management Framework across product and engineering • Report to the CISO and partner with Engineering and the Cloud Security team

🎯 Requirements

• 6+ years in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams • Strong proficiency in an object-oriented programming language; Java preferred • Ability to read, debug, and write production-quality code • Comfort working across TypeScript, Python, or Go • Deep knowledge of authentication, authorization, API security, business-logic flaws, and modern service architectures • Hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines • Hands-on exploit reproduction and patch validation against running Java web applications • Coordinated disclosure experience with external security researchers and customers, including driving a CVE to publication • Product security experience on shipped software with an installed base • Experience running threat modeling, design reviews, and manual security testing • Ability to work directly with developers through remediation • Ability to translate technical risk into engineering guidance for developers and executives • Ability to hold release-gating decisions with Engineering leadership • Nice-to-have: securing LLM applications, AI agents, or AI-assisted development tools • Nice-to-have: SBOM, CycloneDX/SPDX, VEX, artifact signing, and SLSA • Nice-to-have: AWS, Kubernetes/EKS, Terraform, Jenkins • Nice-to-have: Snyk, GitHub Advanced Security, Semgrep, Burp Suite • Nice-to-have: NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, SOC 2 or ISO 27001 audits • Nice-to-have: CSSLP, OSWE, GWAPT, AWS Security, or comparable certifications • Nice-to-have: SaaS and customer-hosted deployment models; SSO/SAML, RBAC design, multi-tenant isolation; MFT/EDI or other B2B integration products

🏖️ Benefits

• Bonus Opportunity • Great Healthcare + Dental + Vision • Flexible PTO • Culture of support, encouraging Life-Work balance • 401k match • FSA and HSA options • Employee Assistance Program • Paid Parental Leave • Remote work environment • Accelerated title and salary growth potential • Fun and energetic work environment

Apply Now

Similar Jobs

🔥 14 hours ago

CDW

10,000+ employees

💼 Consulting

🏥 Healthcare

📚 Education

Security professional services director leading CDW’s cyber and physical security teams. Driving customer satisfaction, financial performance, talent development, and new technology services.

🔥 15 hours ago

Cisco

10,000+ employees

🔧 Hardware

🔐 Security

🏢 Enterprise

Security Consulting Engineer delivering Cisco firewall, VPN, and cloud security solutions for enterprise customers. Leading deployments, automation, troubleshooting, workshops, and customer advisory engagements.

🔥 16 hours ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Director leading GuidePoint Security’s OT/IoT cybersecurity practice for critical infrastructure clients. Owning delivery quality, service catalog, team growth, and P&L.

🕒 Yesterday

CACI International Inc

10,000+ employees

🎖️ Defense

🏛️ Government

🔒 Cybersecurity

Information System Security Officer securing CACI’s DHS information systems through RMF and ATO compliance. Maintaining SSPs, controls, assessments, and cybersecurity documentation.

🇺🇸 United States – Remote

💵 $90.3k - $189.6k / year

🔥 Funding within the last year

💰 $500M Post-IPO Debt on 2026-02

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🕒 Yesterday

TRM Labs

201 - 500

₿ Crypto

📋 Compliance

🤝 B2B

Product Security Engineer securing TRM Labs’ AI-powered intelligence platforms used to investigate crime and disrupt illicit activity. Leading threat modeling, secure SDLC, vulnerability management, and application security initiatives.