Search Remote Jobs

Senior Security Engineer, Product Security

🔥 14 hours ago

🇺🇸 United States – Remote

đź’µ $146k - $185k / year

⏰ Full Time

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

đź‘» Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GoodLeap

GoodLeap

501 - 1000 employees

Founded 2020

🏗️ Construction

🏥 Healthcare

đź’¸ Finance

Construction • Healthcare • Finance

GoodLeap is a tech company delivering best-in-class financing and software products for sustainable solutions. It supports homeowners and businesses nationwide by providing solar loans, energy efficiency loans, and other financing solutions to promote green energy adoption. GoodLeap is committed to a sustainable future, having facilitated $58B in cumulative financing and offsetted 14M metric tons of CO2. The company offers solutions like solar and storage systems, energy-efficient upgrades, and smart home technologies, primarily catering to the green energy sector. Their partnerships and initiatives aim to expand access to clean energy and support environmental sustainability.

đź“‹ Description

• Adversarially test AI- and LLM-backed features, including prompt injection, jailbreaks, tool abuse, and data exfiltration • Build and operate production security services and internal tooling using TypeScript, Node.js, .NET, or Python • Identify opportunities to automate manual security work and prototype improved solutions • Review and triage pull-request vulnerability findings, investigate authentication paths and high-risk changes, and improve security tooling • Threat model product requirements and technical designs by identifying trust boundaries, data flows, and security questions • Manually test web applications and APIs, assess exploitability, retest fixes, and support bug bounty and penetration-testing programs • Operate and improve AppSec tooling, including SAST/dependency scanning, finding triage and routing, SSO, and access management • Secure tooling infrastructure through least-privilege IAM, secrets management, container/network lifecycle management, infrastructure as code, and drift checks • Create practical security training and documentation for engineers • Evaluate security products through structured bake-offs and help define AI/agent production standards • Support investigations, threat hunting, incident response, vulnerability management, and security analytics

🎯 Requirements

• Strong backend engineering in at least one modern language • At least one production service built that others depend on • Familiarity with async patterns, HTTP APIs, and streaming transports • Ability to read code across more than one language and stack • Knowledge of identity and authorization failures, including token exchange, scope handling, session lifetime and revocation, request signing, OAuth pitfalls, SSRF, and DNS rebinding • Practical knowledge of REST and GraphQL, OpenAPI, schema contracts, input validation, rate limiting, gateway-level authentication, and webhook/service-to-service verification • Hands-on manual testing of web applications and APIs • Threat modeling from written product and technical designs • Working AWS and infrastructure-as-code competence, including IAM, secrets management, containers/compute, network egress control, and drift checks • Practical exposure to AI/LLM security through work, CTF, published research, or a personal lab • Ability to write and speak clearly for engineers, product managers, executives, and Legal • Preferred: AppSec tooling ownership, vendor evaluations, security policy or AI standards, security training, cryptography and key management, detection engineering, incident response, threat hunting, SaaS product development understanding, or product/engineering management experience

🏖️ Benefits

• Salary bonus eligibility • Reasonable accommodations for known disabilities as required by law

Apply Now

Similar Jobs

🔥 14 hours ago

6sense

1001 - 5000

đź’Ľ Consulting

📦 Logistics

🤖 Artificial Intelligence

Senior Security Assurance Engineer automating AWS security controls, evidence, and AI-native GRC workflows at 6sense. Improving continuous monitoring, audit readiness, and risk remediation.

🔥 14 hours ago

Vultr

201 - 500

🤖 Artificial Intelligence

🤝 B2B

đź”§ Hardware

Physical security systems designer engineering access control, CCTV, and intrusion systems for Vultr’s global cloud data centers. Coordinating designs, integrations, commissioning, and ongoing technical support.

🔥 14 hours ago

Vultr

201 - 500

🤖 Artificial Intelligence

🤝 B2B

đź”§ Hardware

Physical Security Evaluator assessing data-center security for Vultr, a global cloud infrastructure provider. Identifying vulnerabilities, driving mitigations, and guiding physical security strategy.

🇺🇸 United States – Remote

đź’µ $80k - $100k / year

đź’° $329M Debt Financing - Vultr on 2025-06

⏰ Full Time

🟡 Mid-level

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

🔥 15 hours ago

Zeiders Enterprises, Inc.

1001 - 5000

đź’Ľ Consulting

🏥 Healthcare

🎖️ Defense

Information System Security Officer supporting Zeiders’ cloud-hosted federal digital services platforms. Managing cybersecurity controls, compliance, authorization, and secure system operations.

🔥 15 hours ago

Zeiders Enterprises, Inc.

1001 - 5000

đź’Ľ Consulting

🏥 Healthcare

🎖️ Defense

Cybersecurity Engineer securing Zeiders’ cloud-hosted digital services platform. Implementing controls, vulnerability remediation, monitoring, and DevSecOps security practices for military and family support programs.