Product Security Engineer

Technology Resource Management

United States

Remote

USD 140,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TRM Labs is seeking a Product Security Engineer to join our remote team in the United States. You will lead security reviews, threat modeling, and vulnerability management while embedding security into our fast-paced development cycles.

The role emphasizes collaboration with engineering leadership to ensure secure products and processes across TRM. Ideal candidates bring 8+ years in software development and testing, strong Python/NodeJS/React skills, and deep experience with cloud security and

Qualifications

  • 8+ years of software development and testing experience.
  • BS in CS/CE or related field.
  • Proficient in Python, NodeJS and React.
  • Experience with GCP and AWS in secure software.
  • Familiarity with OWASP/CWE testing methods.
  • Experience with security testing tools and processes.

Responsibilities

  • Lead application security reviews and threat modeling.
  • Develop automated testing and mature our Secure SDLC.
  • Own vulnerability management and remediation tracking.
  • Coordinate penetration testing engagements.
  • Support engineers with application security best practices.
  • Develop and maintain the bug bounty program.
  • Promote security culture across engineering teams.

Skills

8+ years exp
Python
NodeJS
React
Cloud (GCP/AWS)
OWASP/CWE
SAST/DAST/SCA
BurpSuite/ZAP

Education

BS in CS/CE or related

Tools

GitHub Advanced Security

Job description

Product Security Engineer

Location United States

Employment Type Full time

Location Type Remote

Department R&D Engineering Security

Overview

Application Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Team

The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.

The impact you will have here:
  • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing
  • Develop automated testing and mature our Secure SDLC
  • Own and perform application security vulnerability management
  • Coordinate penetration testing engagements
  • Support software engineers and product teams by developing application security best practices
  • Develop and maintain the bug bounty program
  • Bootstrap platform security initiatives that help protect TRM data
  • Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.
What we’re looking for:
  • Minimum 8 years of experience in Software Development and testing.
  • BS (or equivalent) in Computer Science, Computer Engineering, or related field.
  • Proficiency in software development languages: Python, NodeJS, React
  • Strong understanding of encryption, authentication, and authorization protocols
  • Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.
  • Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.
  • Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis
  • Experience triaging and remediating vulnerabilities in software packages or libraries
  • Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools
  • Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.
  • Experience with Threat modeling tools such as OWASP Threat Dragon, etc.
  • Experience working in a previous agile-based software development role required
  • Experience Red Teaming or penetration testing applications and infrastructure
  • Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.
  • Strong written and verbal communication skills.
  • Security certifications such as OSCP, CEH, GWAPT are a plus.
  • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus
About the Team:

The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.

We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.

Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.

Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.

Team’s Time Zones:
  • Eastern Standard Time (EST - GMT-4)
  • Pacific Standard Time (PST - GMT-7)
  • Central European Summer Time (CET - GMT+2)
Learn about TRM Speed in this position:
  • Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delay.
  • Integrate Security early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.
  • Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.
  • Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Technology Resource Management • United States

Remote
USD 130,000 - 190,000
Senior Product Security Engineer
Senior Product Security Engineer

Crypto Pro Network • United States

On-site
USD 215,000 - 230,000
Competitive salary
Equity plan participation
Senior Cloud Security Engineer (DevSecOps)
Senior Cloud Security Engineer (DevSecOps)

Crypto Pro Network • United States

On-site
USD 120,000 - 160,000
Flexible work environment
Impact-driven culture
Collaborative team
+1
Senior Software Engineer, Full Stack | Product Engineering
Senior Software Engineer, Full Stack | Product Engineering

Crypto Pro Network • San Francisco (CA)

On-site
USD 180,000 - 210,000
Senior Product Security Engineer - Remote
Senior Product Security Engineer - Remote

Technology Resource Management • United States

Remote
USD 140,000 - 210,000
Forward Deployed Engineer (TS/SCI)
Forward Deployed Engineer (TS/SCI)

Crypto Pro Network • United States

On-site
USD 200,000 - 265,000
Participation in equity plan
High impact role
Career growth opportunities
Engineering Manager, Product Engineering
Engineering Manager, Product Engineering

Crypto Pro Network • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Crypto Pro Network • United States

On-site
USD 190,000 - 221,000
Forward Deployed Software Engineer (TS/SCI)
Forward Deployed Software Engineer (TS/SCI)

Crypto Pro Network • United States

On-site
USD 200,000 - 265,000
Applied AI Engineer - National Security (TS/SCI)
Applied AI Engineer - National Security (TS/SCI)

Crypto Pro Network • United States

On-site
USD 200,000 - 265,000