LaunchDarkly
Product Security Engineer
Rol remoto de Technology con fit claro de ubicación del candidato.
PublicadoAgregado recientemente
Países elegibles1 país aceptado
Señal de seniorityNivel abierto
Modelo de trabajoRemoto
Ubicaciones aceptadas para candidatos
Estados Unidos
Resumen del rol
Product Security Engineer
Requisitos y responsabilidades
Contenido del rol extraído en secciones para revisar más rápido.
Responsibilities:
- Lead threat modeling engagements on the features and services where the risk warrants it.
- Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.
- Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.
- Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.
- Bring AI to your work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.
- Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.
About You:
- You're proactive by default. You'd rather spot drift early and fix the cause than chase symptoms after an incident.
- You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.
- You invest in relationships with the engineering, product, and leadership teams you work with.
- You know security work moves at the speed of trust.
- You're a good partner. You're helpful and direct, you say no with reasons and alternatives, and you don't mistake gatekeeping for rigor.
- You're security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what's wrong with them.
- You treat AI as part of the toolkit. You're skeptical where you should be, aggressive where it pays off, and you want to work somewhere that's serious about both.
Qualifications:
- 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.
- Comfortable reading and critiquing pull requests in a modern stack. You don't need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.
- Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).
- Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus.
- Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, and common cloud misconfigurations.
- Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated.
Qualifications:
- Experience with developer tools, SaaS platforms, or feature management
- Bug bounty triage experience (HackerOne, Bugcrowd)
- Familiarity with Go, Python, or TypeScript
- Contributions to internal security tooling or open-source security projects
Qualifications:
- Zone 1: San Francisco/Bay Area or NYC Metropolitan Area, Boston, Seattle - $136,000 - $187,000**
- Zone 2: Irvine, LA, Monterey, Santa Barbara, Santa Rosa, Austin, Portland, Philadelphia, Chicago - $122,000 - $168,000**
- Zone 3: All other US locations - $116,000 - $159,000**
About LaunchDarkly:
- Improving the velocity and stability of software releases, without the fear of end customer outages
- Delivering targeted experiences by easily personalizing features to customer cohorts
- Maximizing the business impact of every feature through the ability to experiment and optimize
- Coordinating the release and optimization of software to provide consistent experiences across mobile platforms and device types
- Improving the effectiveness and productivity of engineering teams, by providing insights into engineering cadence and stability
Roles similares
Mantén una lista de respaldo.
Python, TypeScript 5 países aceptados
Senior Full Stack EngineerIndeedVer rol REST, TypeScript 1 país aceptado
Senior/Lead Full Stack EngineerTeamviewerVer rol TypeScript USA
Staff Backend Engineer- Session Replay| USA| RemoteGrafana LabsVer rol TypeScript USA
Staff Backend Engineer- Session Replay| Canada| RemoteGrafana LabsVer rol Stack
Usa estas tags para comparar roles remotos similares.
Elegibilidad de ubicación
Candidatos deberían aplicar solo cuando el país del perfil aparece aquí.
Tu perfilPaís no definidoInicia sesión para comparar tu país con este rol.
Flujo de contratación
WithMira muestra el rol y luego envía candidatos a la aplicación de la empresa.
1Revisa fit del rol, stack y elegibilidad de ubicación en WithMira.
2Abre la página de aplicación de la empresa desde el link rastreado.
3Guarda el rol o suscríbete a oportunidades similares antes de salir.