Product Security Engineer

Apply

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

TRM Labs is seeking an experienced Application Security Engineer to build mission-critical security for our AI-powered platforms. You will lead reviews, threat modeling, secure code practices, and work closely with engineering leadership to raise the bar for protection across products.

You will drive automated testing, manage vulnerability programs, and mentor developers with secure coding training across multiple time zones in a distributed team.

Qualifications

  • BS or equivalent in CS/Engineering or related field.
  • 8+ years of experience in software development and testing.
  • Proficiency in Python, NodeJS, and React.
  • Strong knowledge of encryption, authentication, and authorization.
  • Experience with OWASP/CWE and security testing methodologies.

Responsibilities

  • Lead app security reviews and threat modeling across products.
  • Develop automated security testing and mature our Secure SDLC.
  • Manage application security vulnerability program and remediation.
  • Coordinate penetration testing engagements.
  • Create security best practices for engineers and product teams.
  • Maintain bug bounty program and security training.

Skills

Python
NodeJS
React
Security testing
Threat modeling
CI/CD security
OWASP/CWE
AWS
GCP
BurpSuite
OWASP ZAP
Threat Dragon
Red Teaming
Communication

Education

BS in Computer Science/Engineering or related field

Tools

GitHub Advanced Security
SAST
DAST
SCA tools
BurpSuite
OWASP ZAP

Job description

Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Team

The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.

The impact you will have here:

  • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing

  • Develop automated testing and mature our Secure SDLC

  • Own and perform application security vulnerability management

  • Coordinate penetration testing engagements

  • Support software engineers and product teams by developing application security best practices

  • Develop and maintain the bug bounty program

  • Bootstrap platform security initiatives that help protect TRM data

  • Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.

What we’re looking for:

  • Minimum 8 years of experience in Software Development and testing.

  • BS (or equivalent) in Computer Science, Computer Engineering, or related field.

  • Proficiency in software development languages: Python, NodeJS, React

  • Strong understanding of encryption, authentication, and authorization protocols

  • Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.

  • Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.

  • Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis

  • Experience triaging and remediating vulnerabilities in software packages or libraries

  • Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools

  • Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.

  • Experience with Threat modeling tools such as OWASP Threat Dragon, etc.

  • Experience working in a previous agile-based software development role required

  • Experience Red Teaming or penetration testing applications and infrastructure

  • Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.

  • Strong written and verbal communication skills.

  • Security certifications such as OSCP, CEH, GWAPT are a plus.

  • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus

About the Team:

  • The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.

  • We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.

  • Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.

  • Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.

Team’s Time Zones:

  • Eastern Standard Time (EST - GMT-4)

  • Pacific Standard Time (PST - GMT-7)

  • Central European Summer Time (CET - GMT+2)

Learn about TRM Speed in this position:

  • Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.

  • Integrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.

  • Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.

  • Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.

Life at TRM

We are building a safer world. That promise shows up in how we work every day.

TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

At TRM, you should expect:

  • Priorities and targets to change quickly as we experiment and iterate

  • Work that often requires operating with a high degree of ambiguity

  • A high level of personal ownership and accountability

  • Close collaboration across teams and functions

  • Frequent, high-touch communication

  • Creative problem solving and out-of-the-box thinking

  • A pace that rewards urgency, adaptability, and outcomes

This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.

We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.

At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more about Interviewing at TRM

AI Fluency at TRM

AI fluency is a baseline expectation at TRM.

We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.

At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:

  • Accelerate repeatable workflows

  • Structure and solve problems

  • Improve output quality

  • Increase speed and leverage

You will be evaluated on applied AI fluency during the interview process.

Leadership Principles

We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.

  • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

  • Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday.

  • Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset — giving and receiving feedback to make the team stronger.

Join our Mission

At TRM, we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.

TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Learn more about building tools for defenders

Privacy Policy and Additional Information

By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy.

We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.

Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information from up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at privacy@trmlabs.com.

To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form.

Recruitment agencies

TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third‑party agency or company without a signed agreement.

Learn More: Company Values | Interviewing | FAQs
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Data Product - SF Only
Senior Software Engineer, Data Product - SF Only

Trm-Labs • California (MO)

On-site
USD 190,000 - 220,000
Staff Data Platform Engineer - AI Platform
Staff Data Platform Engineer - AI Platform

TRM Labs • San Francisco (CA)

On-site
USD 180,000 - 280,000
Cloud Security Engineer
Cloud Security Engineer

Apply • Northern (KY)

Hybrid
USD 150,000 - 210,000
Senior Data Platform Engineer - AI Platform
Senior Data Platform Engineer - AI Platform

TRM Labs • San Francisco (CA)

On-site
USD 150,000 - 210,000
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

Apply • Washington

Hybrid
USD 120,000 - 180,000
Content Marketing Lead
Content Marketing Lead

Apply • Northern (KY)

Hybrid
USD 140,000 - 188,000
Equity plan
Tech Lead, Staff Software Engineer, Data Product (US)
Tech Lead, Staff Software Engineer, Data Product (US)

Trm-Labs • San Francisco (CA)

On-site
USD 200,000 - 250,000
Account Director - National Security
Account Director - National Security

TRM Labs • United States

Remote
USD 180,000 - 300,000
Senior Cyber Threat Response Advisor
Senior Cyber Threat Response Advisor

Apply • Northern (KY)

Hybrid
USD 140,000 - 180,000
Forward Deployed Engineer - US National Security
Forward Deployed Engineer - US National Security

TRM Labs • United States

Hybrid
USD 170,000 - 240,000