Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
Jobs in United States
Product Security Engineer in United States
15 active opportunities · Updated September 2026
Showing
15 jobs
Explore current product security engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
From $168K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As the Senior Manager of the Security Posture Management (SPM) team within the Product Security Department , you lead the team that secures GitLab's own software factory: the estate we build and ship from. Your team drives comprehensive, governed rollouts of GitLab's security capabilities across every project, applying our own product the way our customers do, and builds proactive software supply chain security as a first-class capability within Product Security. This is Customer Zero work with real reach. Where the team hits friction adopting our own features at scale, that signal goes straight to Produc
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Product Security team is responsible for managing the security processes, policies and controls to secure Plaid’s developer and consumer facing products.The product security team is focused on areas like Application Security, Vulnerability Management, Secure Development Lifecycle, Penetration Testing and Cloud Security. We build the services and components that protect Plaid’s products. We move security "left" by engineering common libraries, modules, and workflows that make the secure path the easiest path for all Plaid engineers. Plaid is looking for a Product Security Engineer who is a builder to join our Product Security team. Unlike traditional Product security roles, this position is for a Senior software engineer who wants to solve security challenges at scale by designing and building production-grade services, libraries, and frameworks. Our goal is to make the "secure path" the only path for Plaid developers. The Role You will lead, design and develop security capabilities to manage vulnerabilities lifecycle and automate workflows to reduce KTLO toil. You will own, maintain, and build Plaid’s VM Orchestration service and build solutions to eliminate the entire vulnerability classes. You
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Product Security team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information. Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Build security-focused application primitives and integrate them into our existing products Design and deploy platform-level mitigations to common security issues Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program Partner with engineering teams to design and deploy solutions which are inherently secure Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure system
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Staff Software Engineer, Product Security for our Security Foundations team. Product security sits at the center of the trust customers place in the Snowflake platform, and this role owns the hard technical problems that keep that trust intact. You will drive security architecture and secure-by-design practices across engineering teams, shaping how new products are built rather than reviewing them after the fact. AS A STAFF SOFTWARE ENGINEER, PRODUCT SECURITY AT SNOWFLAKE, YOU WILL: Set the technical direction for product security across multiple engineering teams, influencing architecture decisions before code is written Design and build security-critical services, frameworks, and controls that other engineering teams adopt as defaults Lead threat modeling and security design reviews for the platform's most complex and high-risk systems Partner with product and engineering leaders to embed secure-by-design principles into the development lifecycle Investigate and drive resolution of the highest-severity security issues, then eliminate the underlying class of problem, not just the instance Mentor senior and mid-level engineers, raising the security engineering bar across the organization Own initiatives end to end, from problem framing and scoping through de
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a member of the Infrastructure Security Team within the Product Security Department , you will work with teams across GitLab to ensure that the components that comprise our public cloud infrastructure are built from the beginning with resiliency and set security expectations that our customers rely on to power their DevSecOps goals. As a Staff Security Engineer, you will serve as a technical lead across the topics the Infrastructure Security team owns, including our SaaS Platforms (e.g. GitLab Dedicated, Cells) and Self-Managed offerings. You will define the technical direction for how the team approac
Senior Security Engineer, Vulnerability Management Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever. We are looking for a Senior Security Engineer who can combine vulnerability-management judgment with hands-on engineering to help us scale and improve our vulnerability lifecycle across Datadog’s multi-cloud products and services. In this role, you will turn ambiguous security problems into clear solutions, and work with engineering teams to address root causes and develop technical controls that reduce vulnerabilities earlier in the SDLC. You’ll use AI and automation to help scale the overall vulnerability lifecycle across Datadog. You will use data and sound technical judgment to prioritize risk, and partner with security, product, platform, and compliance teams to bring scalable solutions into practice. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do Work across the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification. Use AI and automation to build tools, services, and workflows that make security ideas concrete, validate them quickly, and create alignment for scalable implementation. Reduce engineering toil through a “PRs, not tickets” approach, using automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes. Analyze recurring vulnerabilities and remediation failures to identify root causes and opportunities to prevent issues earlier in the SDLC. Partner with SDLC Security, Product Security, platform teams, and engineering teams to balance technical constraints, busin
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
$3.3M – $3.6M/yr
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat
About the Team The Ona team at OpenAI is helping build the software factory for the enterprise. We build infrastructure that enables AI agents to work in secure, customer-controlled cloud environments, with the context, tools, and controls they need to make progress across the software lifecycle—beyond a single developer’s laptop or active session. Our focus is helping enterprises move from experimenting with agents to using them reliably in production. That means solving challenging problems in cloud environments, orchestration, security, and collaboration, while making the experience straightforward for the people directing and reviewing the work. We’re a team that values initiative, close relationships with customers, and exceptional engineering craft. We take ownership, learn quickly, and communicate directly and kindly. About the Role We’re hiring backend-focused Product Engineers across our platform and security product teams. You’ll build infrastructure and customer-facing workflows that let developers and AI agents work reliably in parallel. You’ll work primarily in Go on APIs, complex networking, development environments, and orchestration for long-running tasks. You’ll own outcomes from understanding a user’s problem and choosing an approach through shipping, operating, and improving the solution, working closely with frontend, infrastructure, and security engineers. In this role, you will: Work directly with customers to build developer and security workflows, from getting a project running to investigating findings, reviewing agent-generated changes, and verifying fixes. Build Go services and APIs for provisioning cloud environments, running agents in customer infrastructure, and integrating with source control, CI, and other developer tools. Design reliable orchestration for long-running, parallel work, including durable state, retries, cancellation, and recovery. Build security into execution workflows through clear permissions, credential handling, is
From $326.1K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a pivotal role in shaping the growth of Information Security's (InfoSec) Application Security team, collaborating with engineering teams early in their processes to provide secure design solutions and establish security standards. Your responsibilities will include threat modeling, secure system design, automation, and penetration testing. As a key member of the team, you will drive company-wide projects across diverse tech stacks, working with engineering leaders to remediate security challenges. You will define and evolve the technical vision for scaling application security practices across the organization. You will: Lead company-wide security initiatives to address critical security challenges. Build and nurture cross-company relationships to achieve security objectives. Provide guidance on product security processes and standards. Define and expand partnerships with key engineering teams across Roblox. Apply critical thinking and analytical skills to develop security protocols and communicate effectively with stakeholders. Re
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. The Product Security team ensures that Snowflake products are built and shipped with the highest level of security. Our team drives the security posture of Snowflake products and is responsible for embedding security into every stage of the product lifecycle, from design through deployment and beyond. We design and build frameworks, systems and services that keep Snowflake secure. As a Principal Software Engineer II on the Product Security team, you will be the senior technical authority for Product Security and play a critical leadership role in shaping and advancing Snowflake’s security. This is a unique opportunity to define and influence our long-term security strategy and have a direct impact on the security of the Snowflake platform and the trust of our customers. You will operate across organizational boundaries, guiding major security initiatives, influencing architectural decisions at the highest levels, setting the technical direction for the organization, and ensuring consistent security excellence across all product teams while working closely with business leaders to advance Snowflake’s business. The role requires deep expertise in security, software engineering, distributed systems, software infrastructure, AI/ML, applied cryptography, threat modeling and clou
🚀 About WRITER WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI. Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI. 📐 About the role This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems powering some of the world's most recognizable brands. You'll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy. The opportunity is massive: you'll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn't about saying "no"—it's about finding creative ways to say "yes, and here's how we do it securely." You'll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn
🚀 About WRITER WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI. Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI. 📐 About the role Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated detection systems that identify attacks targeting our AI platform, training data, and model deployments while creating automated response capabilities that scale with our explosive growth. This isn't just traditional security work – you're defending cutting-edge AI/AGI systems against adversaries who are evolving their tactics as fast as AI itself advances. This role combines hands-on security engineering with strategic thinking to stay ahead of novel threats that don't exist in textbooks yet. You'll be the operational arm of our security function, translating threat intelligence into real-time detections, coordinating incident response across multiple teams, and hunting for sophisticated attacks across GPU clusters and distributed training environments. If you're excited by the challen
Other cities to consider
More places hiring for this role
1,216 live jobs · steady
349 live jobs · steady
196 live jobs · steady
180 live jobs · steady
32 live jobs · steady
37 live jobs · watch
30 live jobs · watch
126 live jobs · watch
Get new product security engineer jobs in United States by email
Daily job updates · Unsubscribe anytime