Product Security Engineer

SailPoint

United States

Remote

USD 145,000 - 245,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health and wellness coverage
Disability coverage
Life insurance
401(k) with company matching
Flexible vacation policy

Job summary

SailPoint is seeking a Product Security Engineer to advance secure software development across our products. You will partner with Engineering to identify risks, drive remediation, and embed security throughout the SDLC, including leveraging AI tools and securing CI/CD pipelines.

The role emphasizes threat modeling, secure architecture design, vulnerability management, and collaboration with Security Operations. Remote within the continental US offered.

Qualifications

  • 4-5 years of experience in product security, application security, software engineering, or a related field.
  • Experience with security testing tools such as SAST, SCA, DAST, container security scanners.
  • Experience with CI/CD security controls and DevSecOps practices.
  • Familiarity with programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby.
  • Demonstrated ability to use AI-powered tools to enhance security productivity, research, analysis, and remediation.

Responsibilities

  • Partner with Engineering teams to identify and mitigate security risks throughout the SDLC.
  • Support threat modeling activities and help implement security controls
  • Define and promote secure coding standards, policies, and secure-by-design principles
  • Participate in AI initiatives across the Cyber organization and SSDLC
  • Coordinate internal and external application and penetration testing initiatives
  • Validate vulnerability findings and prioritize remediation by risk
  • Perform root cause analysis and recommend long-term improvements
  • Collaborate with Security Operations on monitoring and detection capabilities
  • Triage and oversee remediation for bug bounty disclosures
  • Develop security training, guidance, and technical documentation
  • Interact with other SailPoint organizations as a security consultant

Skills

Product security
Threat modeling
Secure architecture
Vulnerability management
AI/ML security
Cross-team influence

Tools

SAST
SCA
DAST
Container scanners
CI/CD security
DevSecOps
Python
Go
Java
JavaScript/TypeScript
Ruby

Job description

Product Security Engineer Overview

SailPoint’s Cybersecurity organization is seeking a Product Security Engineer with a passion for cybersecurity and protecting the organization. The ideal candidate combines strong application security expertise with practical software engineering experience and can effectively influence to build secure, resilient products at scale. This position reports to the Director of Cyber Product Security (CPS) and the successful candidate will join a team of security engineers who collaborate with stakeholders across the organization. This role will partner closely with Engineering and the other security teams within the Cyber organization to identify security risks, drive remediation efforts, and embed security throughout the product development process. Central to SailPoint’s product security program is the implementation of a shared security model that impacts all software developed by SailPoint. Under this model, CPS is responsible for multiple key areas affecting product security and collaborates with SailPoint's Engineering Product Security (EPS) team on areas of mutual responsibility. The shared responsibility model was developed to shift product security left, moving security checks to the earliest phases of our secure software development lifecycle. The product security engineer will have the opportunity to shape our future through process and technology optimization, capability acquisition and development, and maturation of our existing activities. They’ll already be comfortable with the 4 I’s at SailPoint (individual, Impact, Innovation, and Integrity) even if they’re new to the concept. They will embrace new challenges and will be a positive contributor to an already positive work culture and environment.



Location is remote with the ability to work from anywhere within the continental United States.



Key Responsibilities


  • Partner with Engineering teams throughout the software development lifecycle to identify and mitigate security risks, and implement secure deployment practices

  • Support threat modeling activities and help engineering teams implement appropriate security controls

  • Define and promote secure coding standards, security policies, best practices, and secure-by-design principles

  • Participate in the Cyber organization’s efforts to leverage AI across the team, as well as the use of AI in our SSDLC

  • Partner with Engineering on improving security testing programs

  • Coordinate internal and external application and penetration testing initiatives

  • Validate vulnerability findings and prioritize remediation based on risk

  • Perform root cause analysis and recommend long-term security improvements

  • Collaborate with the Security Operations team on security monitoring and detection capabilities for applications and services

  • Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty program

  • Develop security training, guidance, and technical documentation

  • Interact with other organizations at SailPoint as a consultant on security-related matters



Required Qualifications


  • 4-5 years of experience in product security, application security, software engineering, or a related field

  • Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners

  • Experience with CI/CD security controls and DevSecOps practices

  • Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby

  • Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts

  • Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows

  • Deep expertise in threat modeling, secure architecture design, and vulnerability management

  • Experience influencing engineering organizations and driving security initiatives across multiple teams

  • Knowledge of artificial intelligence software security frameworks is strongly preferred, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework.



Core Competencies


  • Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues

  • Have a continuous learning mindset and passion for security

  • Have strong analytical and problem-solution skills

  • Be flexible, with the ability to balance security vs the needs of the business

  • Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation

  • Be able to translate technical risks into business impact

  • Be collaborative and able to foster relationships with teams we partner with



First 90 Days: Discovery, Strategic Alignment, and Partnership

Strategic Alignment & Planning


  • Deepen collaboration with key engineering and tooling leads by Day 90, reinforcing recurring touchpoints to integrate product security proactively into early planning cycles, roadmaps, and feature designs.


SDLC Optimization Assessment


  • Review the end-to-end Software Development Life Cycle (SDLC) by Day 60 to identify enhancement opportunities, accelerate shift-left practices, and further standardize secure-by-design deployment pipelines.


Asset & Dependency Inventory


  • Refine and centralize the inventory of supported products, underlying architecture, and third-party dependencies by Day 90 to deliver a highly visible, comprehensive single source of truth.



First 6 Months

Modernizing Tool Stack & AI Integration


  • Evaluate the current security tooling and implement state-of-the-art AI-assisted scanning across product code to further automate and scale security workflows.


Optimized Remediation & Board Metrics


  • Formalize a highly scalable, risk-based vulnerability prioritization framework, optimizing Time to Remediate (TTR) metrics to provide clear, actionable risk visibility for executive leadership and the Board.


Security Champions & Developer Empowerment


  • Elevate developer security education and revamp "Security Champions" program by Day 180, embedding security advocates across core product lines to champion secure development practices.



First 12 Months

Systemic Architecture Enhancements


  • Conduct comprehensive reviews of the production environment (including Kubernetes and containerized applications) to systematically address complex architectural security opportunities and build long-term environment resilience.


Standardizing "Paved Road" Configurations


  • Define, document, and roll out standardized, secure "paved road" configurations and guardrails, making secure deployment the friction-free path of least resistance for product teams.


Program Scaling & Mentorship


  • Maintain and scale updated product architecture documentation while continuously elevating team capabilities, autonomy, and cross-functional alignment through active, hands-on mentorship.



Benefits and Compensation

Listed vary based on the location of your employment and the nature of your employment with SailPoint. As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-max, USD): $145,300 - $244,850.00



Benefits Overview


  • Health and wellness coverage: Medical, dental, and vision insurance

  • Disability coverage: Short-term and long-term disability

  • Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)

  • Additional life coverage options: Supplemental life insurance for employees, spouses, and children

  • Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account

  • Financial security: 401(k) Savings and Investment Plan with company matching

  • Time off benefits: Flexible vacation policy

  • Holidays: 8 paid holidays annually

  • Sick leave

  • Parental support: Paid parental leave

  • Employee Assistance Program (EAP) and Care Counselors

  • Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options

  • Health Savings Account (HSA) with employer contribution



SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law. Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact applicationassistance@sailpoint.com or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations. NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.



SailPoint is a leading provider of identity security for the modern enterprise. Enterprise security starts and ends with identities and their access, yet the ability to manage and secure identities today has moved well beyond human capacity. Using a foundation of artificial intelligence and machine learning, the SailPoint Identity Security Platform delivers the right level of access to the right identities and resources at the right time- matching the scale, velocity, and environmental needs of today’s cloud-oriented enterprise. Our intelligent, autonomous, and integrated solutions put identity security at the core of digital business operations, enabling even the most complex organizations across the globe to build a security foundation capable of defending against today’s most pressing threats.



The employment policy of SailPoint is to provide equal opportunity to all persons, and it is SailPoint’s policy to take affirmative action to employ and advance in employment protected veterans and individuals with disabilities. It is SailPoint’s policy to recruit, hire, train and promote qualified individuals in all job titles, and ensure that all other personnel actions are administered without regard to race, color, religion, national origin, sex, military and/or veteran status, disability, or other legally protected status, and we will ensure that all employment decisions are based only on valid job requirements. SailPoint does not discriminate on the basis of national origin or citizenship status as provided under the Immigration Reform and Control Act of 1986. Employees and applicants shall not be subjected to harassment, intimidation, threats, coercion, or discrimination because they have engaged in or may engage in any of the following activities: Filing a complaint; Assisting or participating in an investigation, compliance evaluation, hearing, or any other activity related to the administration of the affirmative action provisions of Section 503, VEVRAA, or any other Federal, State or local law requiring equal opportunity for individuals with disabilities or protected veterans; Opposing any act or practice made unlawful by Section 503, VEVRAA, or their implementing regulations in this part, or any other Federal, State or local law requiring equal opportunity for individuals with disabilities or protected veterans; or Exercising any other right protected by section 503, VEVRAA or their implementing regulations. SailPoint will also provide reasonable accommodation to known physical or mental limitations of an otherwise qualified employee or applicant for employment, unless the accommodation would impose undue hardship on the operation of our business. SailPoint’s affirmative action program contains an audit and reporting system which enables us to measure the effectiveness of our program, indicate any need for remedial action, determine the degree to which our objectives have been attained, determine whether protected veterans and individuals with disabilities had had the opportunity to participate in company-sponsored activities, measure our compliance with the program’s specific obligations, and document actions taken to comply with these obligations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Staff Software Engineer
Senior Staff Software Engineer

SailPoint Technologies, Inc. • United States

On-site
USD 156,000 - 263,000
Health insurance
401(k) Plan
Paid vacation
+4
Senior Staff Software Engineer
Senior Staff Software Engineer

SailPoint Technologies Holdings, Inc. • Northern (KY)

On-site
USD 156,000 - 263,000
Manager, Technical Program Management
Manager, Technical Program Management

SailPoint Technologies Holdings, Inc. • United States

On-site
USD 130,000 - 219,000
Manager, Technical Program Management
Manager, Technical Program Management

SailPoint • United States

Remote
USD 130,000 - 219,000
Health and welfare benefits
401(k) with company matching
Paid time off
Manager, Engineering
Manager, Engineering

SailPoint Technologies Holdings, Inc. • United States

On-site
USD 141,000 - 237,000
Manager, Adversary Intelligence
Manager, Adversary Intelligence

SailPoint • United States

Remote
USD 124,000 - 209,000
Health and wellness coverage
Disability coverage
Life insurance
+5
Healthcare Account Executive - Tennessee
Healthcare Account Executive - Tennessee

SailPoint Technologies Holdings, Inc. • Tennessee

On-site
USD 109,000 - 165,000
Health and wellness coverage
401(k) with company matching
Flexible vacation policy
+1
Principal Security Architect
Principal Security Architect

SailPoint Technologies Holdings, Inc. • Austin (TX), Northern (KY)

On-site
USD 162,000 - 273,000
Health insurance
Dental and Vision
Disability coverage
+3
Technical Advisor
Technical Advisor

SailPoint Technologies Holdings, Inc. • United States

On-site
USD 148,000 - 249,000
Health and wellness coverage
Disability coverage
Life insurance
+8
Technical Advisor
Technical Advisor

SailPoint • United States

Remote
USD 148,000 - 249,000
Health and wellness coverage
Disability coverage
Life protection
+1