Product Security Engineer III

GitHub

United States

On-site

USD 107,700 - 285,900

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GitHub is looking for a Product Security Engineer III to join their Product Security Engineering team. The role is hands-on, focused on building security tools and platforms that protect GitHub's products. Ideal candidates will have strong software engineering skills with a passion for application security. Responsibilities include designing static analysis pipelines, improving developer-facing tools, and collaborating with various teams to enhance security measures. A competitive salary range from $107,700 to $285,900 per year is offered, based on skills and experience.

Qualifications

  • 5+ years experience in security analysis, security research, or security engineering.
  • 1+ year experience in building security tooling.
  • 3+ years experience programming in Ruby, Go, or Python.

Responsibilities

  • Design, build, and maintain security tooling and automation.
  • Contribute to scalable solutions addressing recurring vulnerabilities.
  • Collaborate across teams to define security requirements.

Skills

Security analysis
Programming in Ruby
Programming in Go
Programming in Python
Building security tooling

Education

Associate's Degree in a related field
Bachelor's Degree in a related field
Master's Degree in a related field

Tools

Static analysis tools (SAST/DAST)
Code scanning frameworks

Job description

Overview

GitHub is transforming how the world builds secure software, and we are looking for a Product Security Engineer III to join our Product Security Engineering team. This is a hands‑on engineering role focused on building internal security platforms, tooling, and automation that protect GitHub's products at scale.

You will design, build, and maintain the systems that make GitHub's security program run: static analysis pipelines, agentic security tooling, supply chain defenses, and developer‑integrated security controls. The ideal candidate is a strong software engineer who is passionate about application security and wants to solve security problems through code. You will partner closely with product and engineering teams to ship security improvements that scale with the organization.

Locations

Remote, United States

Responsibilities
  • Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems.
  • Contribute to scalable solutions that reduce recurring vulnerability patterns, focusing on preventing classes of vulnerabilities rather than addressing individual instances.
  • Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings.
  • Develop security libraries, CI/CD integrations, and developer‑facing tools that make the secure path the default path for engineering teams.
  • Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain.
  • Collaborate with teams across the organization to address security risks and define new requirements and feature sets.
  • Analyze key metrics and KPIs to identify trends in security issues, evaluate the effectiveness of security tooling and automation, and recommend improvements to address gaps in measurement.
Qualifications

Required Qualifications:

  • 5+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Associate's Degree in a related field AND 4+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Bachelor's Degree in a related field AND 3+ years experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR Master's Degree in a related field AND 1+ year(s) experience in security analysis, security research, cyber security, security engineering, or relevant area
    • OR equivalent experience.
  • 1+ year(s) of experience in building security tooling and implementing solutions in complex environments.
  • 3+ years experience programming in at least 2 of these 3 coding languages: Ruby, Go, Python.

Preferred Qualifications:

  • Experience with static analysis tools (SAST/DAST), code scanning frameworks, or custom rule authoring.
  • Experience building agentic or AI‑driven security tooling (e.g., automated triage, classification, or remediation).
  • Familiarity with software supply chain security concepts and tooling.
  • Experience working in large‑scale monolith or distributed service codebases.
  • Familiarity with GitHub's products, platform, and developer ecosystem.
  • Strong expertise in security principles, including the Security Development Lifecycle (SDL), and experience in vulnerability management.
Compensation Range

Base salary range: USD $107,700.00 – USD $285,900.00 per year. These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, and abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in the role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.

EEO Statement

GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Outbound Product Manager, GitHub Advanced Security
Outbound Product Manager, GitHub Advanced Security

GitHub, Inc. • United States

On-site
USD 140,000 - 373,000
Outbound Product Manager, GitHub Advanced Security
Outbound Product Manager, GitHub Advanced Security

GitHub • United States

On-site
USD 140,000 - 373,000
Annual bonus
Stock options
Potential sales incentives
Software Engineer I, Secret Scanning
Software Engineer I, Secret Scanning

GitHub, Inc. • Northern (KY)

Hybrid
USD 69,000 - 183,000
Staff Developer Advocate, GitHub Security Lab
Staff Developer Advocate, GitHub Security Lab

GitHub, Inc. • United States

Remote
USD 121,000 - 324,000
Principal Software Engineer, Git Systems
Principal Software Engineer, Git Systems

GitHub, Inc. • United States

On-site
USD 160,000 - 425,000
Principal Software Engineer, Git Systems
Principal Software Engineer, Git Systems

GitHub • United States

On-site
USD 160,000 - 425,000
Senior Software Engineer, Data Engineering
Senior Software Engineer, Data Engineering

GitHub • United States

On-site
USD 124,000 - 330,000
Annual bonus
Stock options
Flexible work arrangements
Senior Product Security Engineer - Build Scalable Tooling
Senior Product Security Engineer - Build Scalable Tooling

GitHub • United States

On-site
USD 107,000 - 286,000
Staff Software Engineer, Git Systems
Staff Software Engineer, Git Systems

GitHub, Inc. • United States

On-site
USD 140,000 - 373,000
Competitive pay
Generous learning and growth opportunities
Excellent benefits
Staff Software Engineer
Staff Software Engineer

GitHub • United States

On-site
USD 140,400 - 372,300