Product Security Engineer
Job description
Product Security Engineer
About the role
Join LaunchDarkly to enhance the security of our core platform, which empowers developers worldwide. You will contribute to a focused team, applying your security expertise to protect critical infrastructure. Your work will enable engineers to innovate rapidly while maintaining strong security practices.
Key facts
What you'll do
- Lead threat modeling for features and services where risk is identified.
- Develop repeatable processes for security engagements, defining clear criteria for their necessity.
- Manage the complete lifecycle of Cloud Native Application Protection Platform (CNAPP) findings, from investigation and prioritization to resolution and systemic improvement.
- Contribute to the development of Secure Software Development Lifecycle (SDLC) tools, Static Application Security Testing (SAST), and Software Composition Analysis (SCA) workflows.
- Act as a trusted security advisor to product engineering teams, identifying issues early, providing clear explanations, and proposing solutions.
- Integrate artificial intelligence tools to streamline security tasks, accelerate analysis, and enhance coverage.
- Elevate the overall security posture through documentation, guidance, and proactive improvements that prevent incidents.
Requirements
- 2 to 4 years of experience in a security-focused role, such as application security, product security, or cloud security.
- Proficiency in reviewing and critiquing code in modern technology stacks, understanding code logic, and developing small utility tools.
- Experience with threat modeling methodologies like STRIDE or attack trees.
- Familiarity with cloud security posture management, with exposure to CNAPP tools being a significant advantage.
- Solid understanding of security fundamentals, including OWASP Top 10, authentication/authorization patterns, secrets management, and common cloud misconfigurations.
- Demonstrated hands-on experience using AI tools for security or engineering tasks, with specific examples of impact.
Nice to have
- Experience with developer tools, SaaS platforms, or feature management systems.
- Background in bug bounty triage, such as on HackerOne or Bugcrowd.
- Familiarity with Go, Python, or TypeScript programming languages.
- Contributions to internal security tools or open-source security projects.
Skills & tools
- CNAPP
- SDLC
- SAST
- SCA
- OWASP Top 10
- STRIDE
- Go
- Python
- TypeScript
Practical notes
Compensation ranges vary by US geographic zone:
Zone 1 (SF Bay Area, NYC Metro, Boston, Seattle): $136,000 - $187,000
Zone 2 (Irvine, LA, Austin, Portland, Chicago, etc.): $122,000 - $168,000
Zone 3 (All other US locations): $116,000 - $159,000
This salary range is in addition to Restricted Stock Units (RSUs), comprehensive health, vision, and dental insurance, and mental health benefits. Exact compensation is determined by skills, experience, and location.