Senior Product Security Engineer

🔥 12 hours ago

🇺🇸 United States – Remote

💵 $200k - $250k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 4%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Skylight

Skylight

11 - 50 employees

Founded 2015

🏭 Manufacturing

📣 Marketing

💼 Consulting

💰 Venture Round on 2020-09

Manufacturing • Marketing • Consulting

Skylight is a company that offers digital picture frames and calendar devices designed to bring families together and simplify household organization. Their products include a Skylight Frame, which allows users to share photos and videos with loved ones through an anti-glare touchscreen display, and the Skylight Calendar, which displays everyone's schedules in one interactive device. These products are easy to set up, do not require a subscription, and aim to keep users connected and organized. Skylight frames and calendars are touted as great gifts, especially for keeping family memories alive and ensuring ease of communication among multiple family members.

📋 Description

• Own day-to-day execution of the product security program across cloud backend, mobile apps, and Android platform • Own vulnerability management end to end, including intake, triage, prioritization, and driving fixes to closure against remediation SLAs • Write and ship security fixes directly in backend, mobile, and Android codebases • Own and evolve AI security scanning and verification, reducing false positives, extending repository coverage, and integrating it into CI • Run the HackerOne bug bounty program, including report triage, finding validation, researcher collaboration, payout decisions, and vendor relationship management • Manage third-party penetration testing engagements from scoping through remediation • Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products handling children's data • Review and advise on device and firmware security work • Provide metrics and data on findings, remediation, and SLA adherence for compliance and leadership reporting • Serve as a subject matter expert during product security incidents • Work closely with the Head of Security and serve as hands-on security expertise for engineering teams

🎯 Requirements

• 6+ years in application or product security, with a software engineering background • Ability to ship production code, not just review it • Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling • Experience building and maintaining security tooling and automation, including static analysis, CI integrations, and custom scanners • Comfort working with LLM-based systems • Hands-on experience running or triaging a bug bounty program • Track record of getting engineering teams to prioritize and fix security issues through influence and good judgment • Clear written communication and ability to explain risk to engineers and non-technical stakeholders • Mobile application security experience (OWASP MASVS) [nice to have] • Android platform or app security experience [nice to have] • Experience assessing AI/LLM features for prompt injection and data leakage [nice to have] • Familiarity with children's privacy requirements such as COPPA or other sensitive consumer data [nice to have] • Exposure to embedded, IoT, or firmware security [nice to have] • Familiarity with the EU Cyber Resilience Act or UK PSTI [nice to have] • Incident response experience [nice to have]

🏖️ Benefits

• Competitive Salary + Equity Package • 401K matching • Wellness, learning, and home-office budgets • Health, Dental & Vision Medical Plans • Tremendous autonomy to set the direction of your work • Unlimited PTO • Company holidays on the first Friday of every month (Except November, December. & January) • Paid time off

Apply Now

Similar Jobs

🔥 17 hours ago

Neo4j

501 - 1000

☁️ SaaS

🤖 Artificial Intelligence

🏢 Enterprise

Product Counsel guiding product, privacy, security, and open-source legal strategy for Neo4j’s graph intelligence platform. Enabling compliant innovation across enterprise software, cloud, and AI products.

🔥 17 hours ago

Ballard Spahr LLP

1001 - 5000

📋 Compliance

⚖️ Legal

Cloud Security Administrator securing Ballard Spahr’s national law-firm cloud infrastructure. Managing Azure security controls, access, monitoring, audits, and incident response.

🔥 17 hours ago

Gordon Rees Scully Mansukhani, LLP

1001 - 5000

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Cybersecurity and privacy litigation attorneys handling data breach, technology, and class action cases. Joining Gordon Rees Scully Mansukhani, a national full-service law firm.

🔥 18 hours ago

U.S. Small Business Administration

1001 - 5000

🤝 B2B

🏛️ Government

💸 Finance

Cloud Security Administrator securing Ballard Spahr’s law-firm cloud infrastructure. Monitoring Azure security controls, access, vulnerabilities, audits, and incident response.

🔥 18 hours ago

Foresite Cybersecurity

51 - 200

💼 Consulting

🔒 Cybersecurity

☁️ SaaS

Security Engineer helping Foresite, a global SecOps and MDR provider, deploy and optimize Google Cloud security solutions. Advising clients on threat detection, security posture, and product strategy.