FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAndroidCloudIoT
About the role
Key responsibilities & impact- Own day-to-day execution of the product security program across cloud backend, mobile apps, and Android platform
- Own vulnerability management end to end, including intake, triage, prioritization, and driving fixes to closure against remediation SLAs
- Write and ship security fixes directly in backend, mobile, and Android codebases
- Own and evolve AI security scanning and verification, reducing false positives, extending repository coverage, and integrating it into CI
- Run the HackerOne bug bounty program, including report triage, finding validation, researcher collaboration, payout decisions, and vendor relationship management
- Manage third-party penetration testing engagements from scoping through remediation
- Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products handling children's data
- Review and advise on device and firmware security work
- Provide metrics and data on findings, remediation, and SLA adherence for compliance and leadership reporting
- Serve as a subject matter expert during product security incidents
- Work closely with the Head of Security and serve as hands-on security expertise for engineering teams
Requirements
What you’ll need- 6+ years in application or product security, with a software engineering background
- Ability to ship production code, not just review it
- Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling
- Experience building and maintaining security tooling and automation, including static analysis, CI integrations, and custom scanners
- Comfort working with LLM-based systems
- Hands-on experience running or triaging a bug bounty program
- Track record of getting engineering teams to prioritize and fix security issues through influence and good judgment
- Clear written communication and ability to explain risk to engineers and non-technical stakeholders
- Mobile application security experience (OWASP MASVS) [nice to have]
- Android platform or app security experience [nice to have]
- Experience assessing AI/LLM features for prompt injection and data leakage [nice to have]
- Familiarity with children's privacy requirements such as COPPA or other sensitive consumer data [nice to have]
- Exposure to embedded, IoT, or firmware security [nice to have]
- Familiarity with the EU Cyber Resilience Act or UK PSTI [nice to have]
- Incident response experience [nice to have]
Benefits
Comp & perks- Competitive Salary + Equity Package
- 401K matching
- Wellness, learning, and home-office budgets
- Health, Dental & Vision Medical Plans
- Tremendous autonomy to set the direction of your work
- Unlimited PTO
- Company holidays on the first Friday of every month (Except November, December. & January)
- Paid time off
