Product Security Engineer

Cybersecurity Jobs

San Francisco (CA)

Hybrid

USD 232,000 - 318,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Comprehensive benefit plan
Hybrid work location

Job summary

Cybersecurity Jobs is seeking a hands-on Product Security Engineer in San Francisco to make secure outcomes the default across the codebase and delivery workflow. You will identify security gaps, build tooling, and lead threat modeling for new features.

You’ll review code, shape architectural security decisions, and drive AI-assisted security practices at scale. Hybrid work and a strong focus on practical security outcomes are offered.

Qualifications

  • 5+ years of hands-on application security and security engineering experience.
  • Ability to operate independently in a fast-moving environment.
  • Communication style that makes security legible to engineers.
  • Proven track record shipping security tooling or automation.
  • Deep engineering capability to read, reason about, and review code.

Responsibilities

  • Identify systemic security gaps in the codebase and engineering workflows and partner with teams to ship durable fixes.
  • Build security tooling, automation, and code-level controls addressing vulnerability classes.
  • Conduct in-depth code reviews and security design reviews for major initiatives.
  • Drive threat modeling and security assessments for new features and translate requirements into guidance.
  • Evolve security approach for AI-assisted development and impact on risk discovery at scale.
  • Triaging and tracking vulnerabilities with product teams and contributing to pen testing/bug bounty programs.

Skills

TypeScript
Python
AppSec fundamentals
Threat modeling
Security tooling
Code review

Tools

Retool platform
SAST pipelines

Job description

Work as a hands-on Product Security Engineer to make secure outcomes the default across the codebase and delivery workflow.

Responsibilities
  • Identify systemic security gaps in the codebase and engineering workflows, then partner with engineering teams to design and ship durable fixes
  • Build security tooling, automation, and code-level controls that address vulnerability classes (for example: custom linters, static analysis rules, and automated checks)
  • Conduct in-depth code reviews and security design reviews for major product initiatives, engaging on architectural tradeoffs rather than only flagging issues
  • Drive threat modeling and security assessments for new features, translating security requirements into practical engineering guidance
  • Help evolve the team’s security approach as AI-assisted development scales internally, including how higher-volume code production affects risk discovery, prioritization, and remediation
  • Triaging and tracking vulnerabilities with product engineering teams, and contribute to penetration testing and bug bounty programs
Requirements
  • 5+ years of hands-on application security and security engineering experience (built security solutions, not mainly consulting, audit, or compliance work)
  • Ability to operate independently with strong judgment in a fast-moving environment, including knowing when to move quickly, when to slow down, and when to esc*late or request help
  • Communication style that earns trust, making security legible to engineers without being preachy, and measuring impact by business support rather than issue volume
  • Proven track record shipping security tooling or automation that improved outcomes for more than one team
  • Deep engineering capability to read, reason about, and review code to find real bugs and understand root causes
  • Comfort working with TypeScript and Python (Retool platform is TypeScript; security tooling leverages Python)
  • Strong AppSec fundamentals including threat modeling and secure code review, plus a practical understanding of common vulnerability classes and how to address them durably
  • Pragmatic approach to AI tooling: use it where it improves results, remain skeptical where it does not, and consider how developer-side AI adoption compounds security risk at scale
Technologies
  • TypeScript
  • Python
Benefits
  • Comprehensive benefit plan including medical, dental, vision, and 401(k)
  • Generous benefits for all employees and hybrid work location
Nice to Have
  • Offensive security experience such as bug bounty, CTF participation, redteam, or pentesting
  • Experience building or contributing to SAST pipelines, custom static analysis rules, or automated security testing infrastructure
  • Prior experience at a startup or high-growth scaleup where security programs are not fully predefined and priorities change
Location and Salary
  • Location: San Francisco, CA (hybrid)
  • Salary: USD 231,900 - 318,250 per year (base salary range for non-commissionable roles or on-target earnings for commissionable roles)
  • Additional compensation: equity and/or commission may apply depending on the position offered
  • Eligibility notes: Retool is set up to employ roles in the US and specific roles in the UK
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer San Francisco, United States
Application Security Engineer San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 231,900 - 318,250
Medical insurance
Dental insurance
Vision insurance
+1
Product Security Engineer
Product Security Engineer

Retool • San Francisco (CA)

Hybrid
USD 232,000 - 318,000
Hybrid work location
Medical, dental, vision
Software Engineer, Governance
Software Engineer, Governance

Retool • San Francisco (CA)

Hybrid
USD 164,000 - 306,000
Health insurance
401(k) matching
Hybrid work location
Software Engineer, Apps San Francisco, United States
Software Engineer, Apps San Francisco, United States

Retool, Inc. • San Francisco (CA), Northern (KY)

On-site
USD 164,000 - 306,000
Hybrid work location
Medical, Dental, Vision, 401(k)
Software Engineer, Core Services San Francisco, United States
Software Engineer, Core Services San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 163,800 - 306,000
Comprehensive benefit plan
Medical, dental, vision insurance
401(k) plan
+1
Software Engineer San Francisco, United States
Software Engineer San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 163,800 - 306,000
Medical insurance
Dental insurance
Vision insurance
+2
Software Engineer, Enterprise Expansion San Francisco, United States
Software Engineer, Enterprise Expansion San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 164,000 - 306,000
Medical, dental, vision
401(k) plan
Hybrid work location
Software Engineer, Cloud Platform San Francisco, United States
Software Engineer, Cloud Platform San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 163,710 - 306,000
Medical benefits
Dental benefits
Vision benefits
+2
Software Engineer, Cloud Platform
Software Engineer, Cloud Platform

Retool • San Francisco (CA)

On-site
USD 164,000 - 306,000
Hybrid work
Benefits package
Software Engineer, Automations
Software Engineer, Automations

Retool Inc. • San Francisco (CA)

On-site
USD 164,000 - 306,000