Sr. Product Security Engineer
Job description
About the role
You will lead and collaborate on product security initiatives that strengthen our engineering practices and protect our customers' financial data. You will write and review customer facing code to resolve security concerns alongside product development engineers in a fast moving environment. You will conduct threat modeling exercises, architecture reviews, and offensive security engagements with product teams to identify and remediate risks before they impact users. You will innovate with modern cloud technologies to secure systems such as CI/CD pipelines, sensitive data storage, mobile design, and front end web services. You will provide mentorship and education for security and software engineering excellence across the organization. You will leverage deep expertise to ensure security is embedded into the full lifecycle of our technology decisions. You will act as a trusted advisor to cross functional partners who rely on security to enable their product goals.
Key facts
What you'll do
- Lead and evolve the security roadmap for critical products in collaboration with engineering leadership.
- Partner with product managers and senior engineers to define security requirements and acceptance criteria for new features.
- Write and review customer facing code to resolve security concerns while maintaining velocity and product usability.
- Conduct threat modeling, architecture reviews, and risk assessments to proactively identify weaknesses in system designs.
- Perform offensive security engagements including vulnerability discovery, exploitation, and validation of fixes.
- Build and maintain security tooling using Ruby, JavaScript, Java, and Python to automate detection and remediation.
- Secure cloud infrastructure on AWS including EC2, RDS, S3, and VPC configurations in production environments.
- Implement and monitor security controls across CI/CD pipelines, Kubernetes (EKS), and Terraform workflows.
- Analyze security events and anomalies using Datadog and Splunk to drive incident response and improvements.
- Mentor engineers and product teams on secure coding practices and emerging threats in the financial services sector.
Requirements
- 5+ years of experience building software in a professional setting with a track record of delivery.
- Deep experience and understanding of securing modern web applications including OWASP Top 10, CWEs, and language specific application security issues.
- Experience working in a product setting where business and user needs must be carefully weighed against security requirements and constraints.
- Experience with exploiting common security vulnerabilities and successfully guiding remediation efforts to a resolved state.
- Experience building high availability distributed systems and services using at least one Object Oriented Programming language.
- Comfort and proficiency with the Linux command line interface for debugging, scripting, and system administration tasks.
- Experience with securing AWS cloud infrastructure including EC2, RDS, S3, and VPCs in production workloads.
- Strong understanding of identity and access management, encryption in transit and at rest, and secure configuration baselines.
- Familiarity with infrastructure as code principles and tools such as Terraform, and container orchestration platforms like Kubernetes.
- Ability to communicate technical risk clearly to both technical and non-technical stakeholders including executives and regulators.
Nice to have
- Experience with any of these technologies is a plus: GraphQL, React, CircleCI, Kubernetes, Terraform, Postgres, and modern monitoring platforms.
- Background in financial services, fintech, or regulated environments where compliance and risk management are central.
- Contributions to open source security projects or public facing security research.
- Knowledge of security testing frameworks, SAST, DAST, and dependency scanning tools.
- Experience with incident response processes and post mortem driven improvement.
Practical notes
This role is based out of our NYC office. The position follows a hybrid schedule requiring four days per week in-office, with no required office days during the summer and winter holidays. New York City base salary range is $175,000-205,000. This job may also be eligible for variable compensation in the form of a company incentive bonus.