Product Security Engineer

Sundayyworld — United States · Posted ~2 hours ago

Senior Full-time

Skills

product security application security security engineering threat modeling cloud security

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An experienced security engineer is needed to help protect digital products and connected technologies. The role focuses on securing platforms, improving security practices, and collaborating with engineering teams to address evolving threats.

Highlights

Work on end-to-end security for consumer products with opportunities to influence security strategy, emerging technologies, and cross-functional engineering practices.

Description

About The Company Greenlight is a family-oriented technology company dedicated to empowering families to raise financially smart kids and navigate life's challenges together. Its comprehensive suite of products includes the Greenlight app, debit card, Safe Family GPS trackers, and Family Hub, which integrate financial management, safety features, and household organization into a seamless connected experience. Designed for busy families seeking convenience without sacrificing security or control, Greenlight continually innovates to meet the evolving needs of modern life. Trusted by over 6.5 million family members, Greenlight strives to make daily life easier and more secure, fostering brighter futures for families worldwide. About The Role We are seeking an experienced and motivated Staff Product Security Engineer to join our expanding Security team. This pivotal role is responsible for ensuring the end-to-end security of our consumer products, digital platform, and emerging hardware devices. The ideal candidate will lead security review processes, develop threat modeling programs, and conduct comprehensive penetration testing. They will manage Product Security Incident Response Team (PSIRT) operations, champion secure AI adoption, and establish security guardrails for AI-powered products and development workflows within a highly regulated financial environment. Reporting to the Senior Manager of Product Security, this role requires a strategic thinker with hands-on expertise in security architecture, vulnerability management, and AI security, capable of collaborating across teams to embed security into every aspect of our product lifecycle. Qualifications 10+ years of experience in product security, including application security, cloud security, and secure SDLC practicesExpertise in threat modeling methodologies such as STRIDE, PASTA, or equivalent across web, mobile, cloud, embedded, and AI systemsHands-on penetration testing skills across applications, APIs, cloud infrastructure, and hardware/firmwareProven experience managing PSIRT operations, vulnerability triage, and incident response frameworks (CVE, CVSS, FIRST PSIRT)Deep knowledge of AI security, OWASP Top 10 for LLMs, API, Web, Mobile, and practical experience with MITRE frameworksExperience with security tools such as SAST, DAST, SCA, and securing AI development tools like Claude and CursorUnderstanding of MCP security risks and enterprise guardrail architecture for safe AI-assisted developmentStrong programming skills with the ability to review code, automate workflows, and develop security toolsKnowledge of CI/CD pipelines, web/mobile frameworks (Node.js, Java/Kotlin, React, Swift), and cloud technologies (AWS, GCP, Kubernetes)Excellent communication skills to influence stakeholders and mentor junior team members Responsibilities Lead security architecture and design review sessions, utilizing threat modeling methodologies to identify vulnerabilitiesTranslate identified threats into prioritized, risk-rated engineering remediationsConduct hands-on security assessments and penetration tests across the entire product stack, delivering actionable insightsPerform red-team exercises on AI-powered products and development tools to evaluate guardrail effectiveness and identify vulnerabilitiesManage PSIRT operations, including vulnerability intake, investigation, severity scoring, coordinated disclosure, and remediation trackingDefine and enforce security policies for AI development environments, including Claude and Cursor, to ensure safe and compliant AI-assisted workflowsCollaborate with design, product, and engineering teams during review processes to incorporate security and compliance considerationsAdvise executives on emerging AI security threats and industry best practicesMentor junior security engineers and promote a security-first culture within the organizationDevelop and deliver secure coding training for developers, emphasizing secure AI integration and product security principles Benefits Comprehensive medical, dental, and vision insurance with HSA matchingPaid life insurance, AD&D, and disability benefitsTraditional 401(k) plan with company matchUnlimited paid time off and paid company holidays, including bonus holidaysProfessional development stipends and training resourcesMental health resources and access to 1:1 financial planning servicesFertility healthcare benefitsPaid parental and caregiving leave, with additional support such as cleaning services and meals during leaveFlexible remote and in-office work arrangementsFully stocked kitchens, catered lunches, and occasional in-office social eventsEmployee resource groups fostering diversity and inclusion Equal Opportunity Greenlight is an equal opportunity employer committed to fostering an inclusive workplace. We do not discriminate against any employee or applicant based on age, race, color, national origin, gender, gender identity or expression, sexual orientation, religion, physical or mental disability, medical condition, genetic information, marital status, veteran status, or any other characteristic protected by law. We encourage candidates from all backgrounds to apply and provide reasonable accommodations throughout the hiring process. If you require accommodations, please contact your recruiter or email accommodations@greenlight.me.