Senior or Staff Product Security Engineer
Core
Own the end-to-end product security program across cloud backend, mobile apps, and Android platforms, including vulnerability management, bug bounty operations, and security design reviews.
Role type
Senior/Staff Product Security Engineer (hands-on IC)
Builds
Security fixes, AI-powered security scanning pipelines, and threat models for new features.
Domain
Consumer technology, family life management apps, cloud security
Deliverable
production ML models | product features
Required skills
Application/product security, software engineering, backend/API security (OAuth 2.0/OIDC, PKCE, MFA, session management), security tooling automation, bug bounty program management, influence without escalation
Preferred skills
Mobile application security (OWASP MASVS), Android platform security, AI/LLM security (prompt injection, data leakage), children's privacy compliance (COPPA), embedded/IoT/firmware security, incident response
Technologies
OAuth 2.0, OIDC, PKCE, MFA, CI/CD integrations, static analysis tools, LLM-based systems, HackerOne
Responsibilities
Own vulnerability management pipeline (intake, triage, prioritization, remediation), write and ship security fixes in codebases, evolve AI security scanning pipeline, run bug bounty program, manage third-party penetration testing, lead security design reviews and threat modeling, provide security metrics, serve as SME during security incidents
Seniority
Senior/Staff, hands-on IC