Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Skylight

Senior Product Security Engineer

Skylight

. Own day-to-day execution of the product security program across cloud backend, mobile apps, and Android platform .

Posted 9/26/2026full-timeRemote • United StatesSenior💰 $200,000 - $250,000 per yearWebsite

Tech Stack

Tools & technologies
AndroidCloudIoT

About the role

Key responsibilities & impact
  • Own day-to-day execution of the product security program across cloud backend, mobile apps, and Android platform
  • Own vulnerability management end to end, including intake, triage, prioritization, and driving fixes to closure against remediation SLAs
  • Write and ship security fixes directly in backend, mobile, and Android codebases
  • Own and evolve AI security scanning and verification, reducing false positives, extending repository coverage, and integrating it into CI
  • Run the HackerOne bug bounty program, including report triage, finding validation, researcher collaboration, payout decisions, and vendor relationship management
  • Manage third-party penetration testing engagements from scoping through remediation
  • Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products handling children's data
  • Review and advise on device and firmware security work
  • Provide metrics and data on findings, remediation, and SLA adherence for compliance and leadership reporting
  • Serve as a subject matter expert during product security incidents
  • Work closely with the Head of Security and serve as hands-on security expertise for engineering teams

Requirements

What you’ll need
  • 6+ years in application or product security, with a software engineering background
  • Ability to ship production code, not just review it
  • Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling
  • Experience building and maintaining security tooling and automation, including static analysis, CI integrations, and custom scanners
  • Comfort working with LLM-based systems
  • Hands-on experience running or triaging a bug bounty program
  • Track record of getting engineering teams to prioritize and fix security issues through influence and good judgment
  • Clear written communication and ability to explain risk to engineers and non-technical stakeholders
  • Mobile application security experience (OWASP MASVS) [nice to have]
  • Android platform or app security experience [nice to have]
  • Experience assessing AI/LLM features for prompt injection and data leakage [nice to have]
  • Familiarity with children's privacy requirements such as COPPA or other sensitive consumer data [nice to have]
  • Exposure to embedded, IoT, or firmware security [nice to have]
  • Familiarity with the EU Cyber Resilience Act or UK PSTI [nice to have]
  • Incident response experience [nice to have]

Benefits

Comp & perks
  • Competitive Salary + Equity Package
  • 401K matching
  • Wellness, learning, and home-office budgets
  • Health, Dental & Vision Medical Plans
  • Tremendous autonomy to set the direction of your work
  • Unlimited PTO
  • Company holidays on the first Friday of every month (Except November, December. & January)
  • Paid time off