Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TRM Labs

Product Security Engineer

TRM Labs

. Lead application security reviews and threat modeling, including secure code review, architectural design, and testing .

Posted 10/1/2026full-timeRemote • United StatesSeniorLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in application security, including secure code reviews, threat modeling, and vulnerability management. Proficient in integrating security practices within the software development lifecycle and fostering a culture of security across engineering teams.

Highest-signal resume keywords
Application Security ReviewsSecure Software Development LifecycleVulnerability ManagementThreat ModelingSecurity Testing Tools

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
PythonNodeJSReactEncryption ProtocolsAuthentication ProtocolsAuthorization ProtocolsOWASPCWECode Security ReviewsAgile Software Development
Soft Skills
Strong Written CommunicationStrong Verbal Communication
Tools & Technologies
GitHub Advanced SecurityBurp SuiteOWASP ZAPOWASP Threat DragonCI/CD Pipelines
Certifications & Qualifications
OSCPCEHGWAPT
Industry Keywords
Cloud Security SolutionsNIST SP 800-171SSDFPenetration TestingSecurity Best Practices

Tech Stack

Tools & technologies
AWSBootstrapCloudGoogle Cloud PlatformNode.jsPythonReactSDLC

About the role

Key responsibilities & impact
  • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing
  • Develop automated testing and mature the Secure SDLC
  • Own and perform application security vulnerability management
  • Coordinate penetration testing engagements
  • Develop application security best practices for software engineers and product teams
  • Develop and maintain the bug bounty program
  • Bootstrap platform security initiatives that protect TRM data
  • Foster security champions within engineering teams
  • Coordinate secure code training and inspire a culture of security across engineering
  • Perform rapid threat assessments and triage vulnerabilities based on business risk
  • Integrate security testing and reviews into the Product Shipping Framework and CI/CD pipelines
  • Provide just-in-time security training, real-time advice, and code reviews
  • Optimize lightweight security tools for efficient development and deployment
  • Collaborate closely with engineering and engineering leadership

Requirements

What you’ll need
  • Minimum 8 years of experience in Software Development and testing
  • BS (or equivalent) in Computer Science, Computer Engineering, or related field
  • Proficiency in Python, NodeJS, and React
  • Strong understanding of encryption, authentication, and authorization protocols
  • Deep experience with OWASP, CWE, testing methodologies, and security testing tools
  • Experience with security solutions for cloud providers such as GCP and AWS
  • Experience with secure software development lifecycles, threat modeling, and security best practices
  • Experience conducting comprehensive code security reviews
  • Experience triaging and remediating vulnerabilities in software packages or libraries
  • Experience with GitHub Advanced Security or other SAST, DAST, and SCA tools
  • Experience with web application testing frameworks such as Burp Suite and OWASP ZAP
  • Experience with threat modeling tools such as OWASP Threat Dragon
  • Experience working in an agile-based software development role
  • Experience red teaming or penetration testing applications and infrastructure
  • Strong written and verbal communication skills
  • Security certifications such as OSCP, CEH, and GWAPT are a plus
  • Familiarity with security frameworks such as NIST SP 800-171 and SSDF is a plus
  • Ability to work in a distributed environment across EST, PST, and CEST time zones

Benefits

Comp & perks
  • Competitive benefits, wellness programs, and time away from work, varying by country and local employment requirements
  • Distributed-first remote work environment
  • Reasonable accommodations for applicants with disabilities
  • Professional growth and development through meaningful, mission-driven work