Product Security Engineer III

Github

British Columbia

Hybrid

CAD 140,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GitHub is seeking a Product Security Engineer III to join our Product Security Engineering team. This hands-on role focuses on building internal security platforms, tooling, and automation that protect GitHub's products at scale.

You will design, build, and maintain systems for static analysis pipelines, agentic tooling, and developer-facing security controls. The ideal candidate is a strong software engineer passionate about application security and will partner with product and engineering

Qualifications

  • 5+ years in security analysis, security research, cyber security, security engineering, or related area.
  • 1+ year of experience in building security tooling and implementing solutions in complex environments.
  • 3+ years programming experience in Ruby, Go, or Python.

Responsibilities

  • Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems.
  • Contribute to scalable solutions that reduce recurring vulnerability patterns, focusing on preventing classes of vulnerabilities.
  • Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings.
  • Develop security libraries, CI/CD integrations, and developer‑facing tools that make the secure path the default path for engineering teams.
  • Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain.
  • Collaborate with teams across the organization to address security risks and define new requirements and feature sets.
  • Analyze key metrics and KPIs to identify trends in security issues, evaluate the effectiveness of security tooling and automation, and recommend improvements to address gaps in measurement.

Skills

Security engineering
Ruby
Go
Python

Education

Bachelor's Degree in Computer Science or related field
Master's Degree in related field
Associate's Degree in related field

Tools

SAST/DAST tools
Code scanning frameworks

Job description

Locations

In this role you can work from Remote, Canada | Remote, Ontario Canada | Remote, Alberta Canada | Remote, British Columbia Canada

Overview

GitHub is transforming how the world builds secure software, and we are looking for a Product Security Engineer III to join our Product Security Engineering team. This is a hands‑on engineering role focused on building internal security platforms, tooling, and automation that protect GitHub's products at scale.

You will design, build, and maintain the systems that make GitHub's security program run: static analysis pipelines, agentic security tooling, supply chain defenses, and developer‑integrated security controls. The ideal candidate is a strong software engineer who is passionate about application security and wants to solve security problems through code. You will partner closely with product and engineering teams to ship security improvements that scale with the organization.

Responsibilities
  • Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems.
  • Contribute to scalable solutions that reduce recurring vulnerability patterns, focusing on preventing classes of vulnerabilities rather than addressing individual instances.
  • Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings.
  • Develop security libraries, CI/CD integrations, and developer‑facing tools that make the secure path the default path for engineering teams.
  • Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain.
  • Collaborate with teams across the organization to address security risks and define new requirements and feature sets.
  • Analyze key metrics and KPIs to identify trends in security issues, evaluate the effectiveness of security tooling and automation, and recommend improvements to address gaps in measurement.
Qualifications

Required Qualifications:

  • 5+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Associate's Degree in a related field AND 4+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Bachelor's Degree in a related field AND 3+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Master's Degree in a related field AND 1+ year(s) experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR equivalent experience.
  • 1+ year(s) of experience in building security tooling and implementing solutions in complex environments.
  • 3+ years experience programming in at least 2 of these 3 coding languages: Ruby, Go, Python.

Preferred Qualifications:

  • Experience with static analysis tools (SAST/DAST), code scanning frameworks, or custom rule authoring.
  • Experience building agentic or AI‑driven security tooling (e.g., automated triage, classification, or remediation).
  • Familiarity with software supply chain security concepts and tooling.
  • Experience working in large‑scale monolith or distributed service codebases.
  • Familiarity with GitHub's products, platform, and developer ecosystem.
  • Strong expertise in security principles, including the Security Development Lifecycle (SDL), and experience in vulnerability management.
EEO Statement

GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Senior Product Security Engineer - Build Secure Tooling & Pipelines
Remote Senior Product Security Engineer - Build Secure Tooling & Pipelines

Github • British Columbia

Hybrid
CAD 140,000 - 170,000
Staff Software Engineer, Elasticsearch
Staff Software Engineer, Elasticsearch

GitHub • Canada

Remote
CAD 140,000 - 190,000
Staff Software Engineer
Staff Software Engineer

GitHub, Inc. • Canada

Hybrid
CAD 140,000 - 190,000
Staff Software Engineer, Front End Web UI Platform
Staff Software Engineer, Front End Web UI Platform

GitHub, Inc. • Canada

Remote
CAD 180,000 - 240,000
Remote work
Learning opportunities
Competitive pay
Intermediate Software Engineer, Security Factory: Vulnerability Management
Intermediate Software Engineer, Security Factory: Vulnerability Management

Far Coder • Canada

Hybrid
CAD 160,000 - 240,000
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock-P
+2
Staff Software Engineer, Front End Web UI Platform
Staff Software Engineer, Front End Web UI Platform

Github • Canada

Remote
CAD 170,000 - 230,000
Principal Engineer, Software Supply Chain Security
Principal Engineer, Software Supply Chain Security

GitLab • Canada

Remote
CAD 157,000 - 339,000
Benefits to support health and well-being
Flexible Paid Time Off
Equity Compensation & Employee Stock Purchase Plan
+1
Product Security Engineer
Product Security Engineer

Movable Ink • Toronto

On-site
CAD 133,000 - 173,000
Full range of medical benefits
Financial benefits
Bonus eligibility
GitHub Automation Engineer
GitHub Automation Engineer

United States Digital Space LLC • Toronto

On-site
CAD 90,000 - 130,000
Comprehensive Benefits Coverage – 100%
RRSP with matching employer
Virtual Health Care and EFAP
+2
Principal Security Engineer
Principal Security Engineer

Portage Ventures GP Inc. • Toronto

On-site
CAD 220,000 - 280,000