Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Close

Senior Product Security Engineer

Close

. Build a recurring product security review program across backend, frontend, APIs, and customer-facing integrations .

Posted 10/6/2026full-timeRemote • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security, including vulnerability assessment, threat modeling, and secure coding practices. Proficient in Python and TypeScript, with a strong understanding of security tools and cloud infrastructure.

Highest-signal resume keywords
Application Security EngineeringPython ProgrammingThreat ModelingStatic Analysis ToolsVulnerability Remediation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityVulnerability AssessmentThreat ModelingCode ReviewExploit ReproductionStatic AnalysisDynamic TestingSecurity Tool TuningBusiness Logic SecurityCloud Security
Soft Skills
CollaborationSelf-Directed WorkProblem Solving
Tools & Technologies
PythonTypeScriptAWSDockerKubernetesVaultGitHub ActionsMongoDBPostgreSQLElasticsearch
Industry Keywords
SASTDASTSecurity Incident ResponseSOC 2Bug Bounty Program

Tech Stack

Tools & technologies
AWSCloudDockerElasticSearchFlaskGraphQLKafkaKubernetesMongoDBPostgresPythonReactRedisTypeScriptVault

About the role

Key responsibilities & impact
  • Build a recurring product security review program across backend, frontend, APIs, and customer-facing integrations
  • Threat-model new features, audit high-risk areas, review code, and build safe proof-of-concepts in isolated development environments
  • Improve application security testing using static analysis, dependency and secrets scanning, dynamic testing, and focused automation
  • Own vulnerability intake and remediation from HackerOne, scanners, penetration tests, audits, customers, and internal research
  • Reproduce issues, assess exploitability and impact, track remediation, and verify fixes
  • Serve as technical lead for the bug bounty program
  • Automate security-alert ingestion, deduplication, enrichment, prioritization, and routing
  • Improve dependency scanning and create safer upgrade and pull-request workflows
  • Inventory application secrets, add rotation paths, document runbooks, and automate rotation where appropriate
  • Expand Vault-backed dynamic credentials and reduce emergency secret rotations
  • Partner with Infrastructure to strengthen AWS security across identity, networking, compute, storage, containers, and registries
  • Create secure defaults, just-in-time access patterns, infrastructure guardrails, and actionable remediation
  • Support external assessments, audits, SOC 2 goals, documentation, paved roads, and engineering training
  • Take a key technical role in security incident response, including investigation, containment, remediation, root-cause analysis, and follow-up improvements
  • Report to the Backend Platform team manager within Engineering, Product, and Design while working across the product and infrastructure surface

Requirements

What you’ll need
  • USA-only role; must be legally able to work in the US
  • Application security engineer who writes code and can move from code analysis to exploit reproduction and production-quality fixes
  • Strong Python or TypeScript experience; fluency across backend and frontend systems is advantageous
  • Ability to find vulnerabilities conventional scanners may miss
  • Experience with authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business logic security
  • Ability to threat-model designs, conduct white-box code reviews, and test running systems
  • Ability to test like an attacker while protecting customer data and production systems
  • Experience with SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling
  • Ability to tune security tools, connect them to engineering workflows, and reduce noise
  • Experience using coding agents and LLMs while verifying their output
  • Ability to assess exploitability, business impact, reachability, existing controls, and attack chains
  • Ability to collaborate with product engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers
  • Ability to work self-directed in a remote environment and turn ambiguous security surfaces into practical plans
  • Knowledge of Python, TypeScript, React, Flask, FastAPI, GraphQL, Docker, Kubernetes, AWS, Vault, GitHub Actions, MongoDB, PostgreSQL, Redis, Kafka, Elasticsearch, or related security tooling

Benefits

Comp & perks
  • Competitive pay plus an organization-wide goal-based bonus
  • ~5 weeks of PTO to start
  • 1-week all-company Winter Holiday Break
  • Paid US holidays
  • 2 extra PTO days for every year with Close
  • Choice of a standard 5-day week or a 4-day week at 80% pay
  • Paid leave for primary and secondary caregivers
  • 1-month paid sabbatical every 5 years with the team
  • Two medical plans for US residents with Close covering 99% of the premium
  • Dental coverage
  • Vision coverage
  • HSA
  • FSA
  • Company-paid Long-Term Disability
  • 401(k) matching up to 6% for US residents, vested immediately
  • Annual in-person company team gatherings/offsites