Product Security Engineer

Bugcrowd Inc.

United States

Remote

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bugcrowd is looking for security engineers who own problems end to end, help make security a default property of everything we build, and work closely with engineering. You will shape a culture where security enables teams to succeed, not just point out problems.

In this role, you will partner with product and engineering to refine architecture, drive secure defaults, and tune tools (SAST/DAST/SCA) to focus on real risk.

Qualifications

  • 3+ years in product security, application security, or secure software development.
  • Ability to review code, automate tasks, and build security tooling in at least one modern language.
  • Experience with threat modeling, secure code review, and automated testing (SAST/DAST/SCA).

Responsibilities

  • Partner closely with engineering to refine architecture and drive security investment.
  • Contribute to secure defaults and libraries to reduce vulnerabilities.
  • Tune security tooling (SAST/DAST/SCA) to reduce noise and focus on key issues.
  • Support Bugcrowd's bug bounty program and provide feedback on platform features.
  • Lead cross‑functional security projects from scoping to delivery.
  • Scale coverage using automation and secure‑by‑default practices.

Skills

Threat modeling
Secure code review
SAST/DAST/SCA
Automated testing
Programming languages

Education

Bachelor's degree in engineering/CS

Tools

AWS
GCP
Kubernetes
Docker
Terraform

Job description

Founded in 2012, Bugcrowd is the preemptive security platform that unifies exposure discovery and assessment, offensive testing, and intelligence shaped by AI and human insight to help organizations avoid, discover, and validate real-world risk. Bugcrowd helps security teams move faster by identifying the exposures that matter most so they can act first and stay ahead of attackers. By combining the power of humans and AI, teams can preempt attack paths and prevent breaches. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others. Visit https://www.bugcrowd.com.

Job Summary

If you like owning problems end to end, making security a default property of everything we build, and working closely with engineering, we want to meet you. Bugcrowd is looking for security engineers who move beyond standard tooling and drive measurable security outcomes our customers can rely on. You will help us shape a culture where security helps others succeed, not just points out problems.

Essential Duties and Responsibilities
  • Partner Closely with Engineering: Refine architecture, validate new features, and drive security investment while prioritizing engineering velocity
  • Build Security Paved Roads: Contribute to the secure defaults, libraries, and "paved roads" that systematically eradicate entire classes of vulnerabilities rather than fixing bugs one by one
  • Create Feedback Loops: Tune security tooling such as SAST, DAST, SCA, and secret scanning to reduce noise and focus on what matters
  • Be our Best Customer: Ensure our bug bounty program can be a model for other customers. Experiment with new ways to leverage the creativity of the crowd. Provide feedback on new platform features to engineering and product
  • Own Projects End to End: Lead cross-functional product security projects from scoping through delivery, influencing product and engineering roadmaps and clearly communicating risk to both technical and non-technical stakeholders
  • Amplify our Impact: Use code and automation as a lever to scale coverage and eliminate repetitive work. Build systems based on incentives and accountability rather than just bureaucratic process
Education, Experience, Knowledge, Skills, and Abilities
  • 3+ years of experience in product security, application security, or secure software development
  • Can review code, automate tasks, and build security tooling in at least one modern programming language (e.g., Python, Go, Ruby, Java)
  • Hands-on experience with core application security practices — threat modeling, secure code review, and automated testing (SAST, DAST, SCA) — and a solid grasp of common vulnerability classes (e.g., OWASP Top 10)
  • Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product.
  • Bachelor's degree in engineering, computer science or relevant field, or equivalent practical experience
Bonus Points (Preferred but not required)
  • Previous experience with Bug Bounty or vulnerability disclosure programs
  • A background in building "paved roads" or secure-by-default internal libraries to eliminate entire classes of vulnerabilities
  • Hands-on experience securing cloud-native platforms and Infrastructure as Code (e.g., Terraform, AWS, GCP, Kubernetes, Docker)
  • Experience working within a fast-paced, high-growth security or SaaS company
Working Conditions and Physical Requirements

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

  • Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
  • Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
  • Environment - remote, work-from-home 100% of the time
ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Additional Requirements

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, education verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Equal Opportunity Employer

Bugcrowd is an Equal Opportunity and Affinitive Action employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Culture
  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Equal Employment Opportunity

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Architect
Software Architect

Bugcrowd • United States

On-site
USD 156,800 - 293,535
Discretionary bonus program
Flexible work environment
Inclusivity and diversity programs
Reinforcement Learning Engineer
Reinforcement Learning Engineer

Bugcrowd Inc. • United States

Remote
USD 176,000 - 243,000
Customer Experience Manager (CEM) - Fed
Customer Experience Manager (CEM) - Fed

Bugcrowd Inc. • Northern (KY)

Remote
USD 83,000 - 104,000
Customer Experience Manager (CEM) - Fed
Customer Experience Manager (CEM) - Fed

Bugcrowd • United States

On-site
USD 83,000 - 104,000
Remote work
Senior Product Security Engineer
Senior Product Security Engineer

Cloudflare • Austin (TX)

On-site
USD 180,000 - 230,000
Equity plan
Health insurance
401(k) Retirement Savings Plan
+1
Senior Product Security Engineer, Application Security (Remote)
Senior Product Security Engineer, Application Security (Remote)

CrowdStrike • United States

On-site
USD 160,000 - 250,000
Product Security Analyst
Product Security Analyst

hackerone • Washington

On-site
USD 120,000 - 155,000
Health insurance
Equity stock options
Unlimited PTO
Product Security Analyst
Product Security Analyst

DaParrot Ltd • Northern (KY)

On-site
USD 120,000 - 140,000
Health insurance
Equity stock options
Retirement plans
+3
Product Security Engineer, Vulnerability Intelligence
Product Security Engineer, Vulnerability Intelligence

CrowdStrike Inc. • Nebraska

On-site
USD 120,000 - 180,000
Competitive compensation
Comprehensive wellness programs
Generous vacation and holidays
+4
Security Engineer (Red Team)
Security Engineer (Red Team)

United States Digital Space LLC • Starbase (TX)

On-site
USD 120,000 - 180,000