Product Security Engineer – Red Team/Pen Testing

xage, inc

Palo Alto (CA)

On-site

USD 140,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Visa transfers and immigration

Job summary

Xage, headquartered in Palo Alto, seeks a Product Security Engineer focused on red team testing and threat modeling. You’ll perform manual penetration testing across Web UIs, REST/gRPC APIs, desktop clients, and backend services, with automation support as needed.

This role emphasizes collaboration across teams to improve secure design. Ideal candidates bring multi-year offensive security experience, strong coding ability to read product code, and expertise in OAuth, SAML, mTLS, RBAC/ABAC, and

Qualifications

  • Multiple years of hands-on offensive security experience (pentesting, red teaming, vulnerability research).
  • Able to read and understand code across product features to uncover vulnerabilities.
  • Strong knowledge of OAuth, SAML, mTLS, SSO, RBAC/ABAC models.
  • Deep Web and API security expertise; familiar with OWASP Top 10 and threat modeling.
  • Excellent written and verbal communication; able to mentor teammates.

Responsibilities

  • Conduct offensive security testing of Xage products across Web UIs, APIs, desktop clients, and backend services.
  • Review feature designs and provide security input to guide architecture and development.
  • Document findings with reproducible steps; collaborate with developers to remediate and verify fixes.

Skills

Offensive security
Penetration testing
Red teaming
Coding proficiency
OAuth/SAML
mTLS/PKI
RBAC/ABAC
OWASP Top 10
Web security
API security

Job description

Product Security Engineer – Red Team/Pen Testing

Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high – and only growing more urgent by the day. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. We are pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat.

We have built tremendous momentum across governments and commercial enterprises around the world, and it’s just the beginning. Recognized by Forbes as one of America’s Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of our mission. We are headquartered in Palo Alto, CA and have global teams across North America andEMEA.

We’re passionate about solving problems that have positive, real-world consequences for the lives of everyday people. We hope you’ll join us in the fight against cyberattacks and safeguarding critical infrastructure.

About the Role

This role will be focused on penetration testing, threat modeling, and security review / analysis of Xage’s current and future products. Candidates should be comfortable with learning and ramping up on new features in a large code base and performing /manual/ penetration testing to uncover business logic flaws, authorization bypasses, injection issues, and improper use of protocols / cryptographic algorithms.

While the candidate should be familiar with automation tools to help with scanning / detection of vulnerabilities, our team has already integrated extensive usage of automated tools and this will be supplemental work for this role to help improve or integrate with these existing systems or to help automate parts of the manual penetration testing effort. Integration of common automation tooling is not a primary responsibility during the early stages of this role.

Candidates will be expected to help review the design of features currently in development, as well as review of previously implemented security critical features to identify issues within the existing product. Long term some additional areas the role may progress to as needed may include war gaming / emulation of adversaries or specific breach scenarios, implementation of custom automation tooling / fuzzers specific to Xage’s products, other program support for bug bounties / developer education / compliance efforts / etc.

This role will require working across multiple teams and organizations so good communication and team work skills are essential, Xage’s engineering culture prides itself on teamwork and collaboration to help multiply everyone’s skills and development across the entire team.

Key Responsibilities
  • Offensive penetration testing of Xage’s products
    • Penetrating testing areas include Web UIs, REST/gRPC APIs, desktop clients, backend services, and deployment infrastructure
    • Testing should primarily focus on manual efforts which will require reading and understanding the code and architecture of existing Xage products and features
    • As needed, contribute to the extension of existing automation tools or development of novel custom tooling to support detection efforts
  • Threat modelling and security review of Xage products and features
    • Help the product security team to provide input and signoff on all new features being added to the product
    • Contribute to continuous review of older features already existing in the product to help close any gaps from early stage products and software
    • Provide input and guidance on brainstorming / architectural discussions to help educate and guide the team to appropriate security conscious design decisions
  • Reporting issues, remediation, and verification of resolution
    • Provide clear findings on any vulnerabilities discovered with reproduction steps and possible fixes
    • Work alongside developers to remediate issues and push fixes through the development lifecycle
    • Educate and expand the capabilities of developers to help them understand how to avoid common security issues
    • Suggest improvements to libraries or tooling for development teams to help prevent security issues before they happen
Requirements
  • Multiple years of hands-on offensive security experience (penetration testing, red teaming, vulnerability research, etc.) against software products, not just corporate IT vulnerabilities.
  • Must be fluent and capable enough in coding to understand features within the code base and help uncover vulnerabilities within our products.
  • Strong understanding of common authentication and authorization protocols/areas such as OAuth, SAML, mTLS / PKI, SSO, MFA, FIDO2, RBAC/ABAC models.
  • Strong Web and API security expertise, knowledgeable about OWASP/Top 10 issue, authentication flows, session management, injection issues, etc.
  • Strong networking and protocol fundamentals, should be capable of reading traffic captures and understanding / reverse engineering custom protocols.
  • Strong communication skills, both verbal and written
  • Collaborative and willing to educate / mentor other team members
Preferred Qualifications
  • Prior experience working in startup environments
  • Prior experience as an initial penetration testing / offensive security hire
  • Prior experience working on an OT / IT authentication and authorization product
  • Salary Range: $140,000 – $170,000 p/yr + Equity
  • We will process visa transfers and immigration
  • Work with founders and executives closely and participate in all aspects of company building
  • Early stage opportunity in a massive sized market with proven traction and growing rapidly
Recognition & Momentum

Xage Security has experienced explosive growth and received numerous awards and recognition, including:

  • Named by Forbes one of America’s Best Startup Employers 2024-2026
  • $17 million contract awarded by U.S. Space Force’s Space Systems Command (SSC) to offer its zero trust access control
  • Named in Gartner research on Cyber-Physical Systems Protection Platforms, Zero Trust Network Access, Privileged Access Management, and CPS Secure Remote Access
  • Named in Forrester research on Operation Technology Security, IoT, and Microsegmentation
  • Named a Gold winner for Identity & Access Security Solution in the 2024 American Business Awards
  • Named a Top 10 Security Solution in the CRN Internet of Things 50 list 2024
  • ISO 27001:2022, IEC 62443, and FIPS 140-2 Certified
Early in Career Software Engineer (Security Products)

July 24, 2026

Software Engineer – Backend
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Safety Engineer (Red Team)
Product Safety Engineer (Red Team)

Xage Security • Palo Alto (CA)

On-site
USD 170,000 - 200,000
Software Engineer – Backend
Software Engineer – Backend

xage, inc • Palo Alto (CA)

On-site
Security-Focused Full Stack Engineer — IAM & Zero Trust, Equity
Security-Focused Full Stack Engineer — IAM & Zero Trust, Equity

xage, inc • Palo Alto (CA)

On-site
Early in Career Software Engineer (Security Products)
Early in Career Software Engineer (Security Products)

xage, inc • Palo Alto (CA)

On-site
USD 100,000 - 115,000
Equity
Visa transfers
Full Stack Engineer
Full Stack Engineer

xage, inc • Palo Alto (CA)

On-site
Zero-Trust Backend Engineer (Go) for Secure Edge Systems
Zero-Trust Backend Engineer (Go) for Secure Edge Systems

xage, inc • Palo Alto (CA)

On-site
Senior Engineer, Secure Remote Access & Zero Trust
Senior Engineer, Secure Remote Access & Zero Trust

xage, inc • Palo Alto (CA)

Remote
Sr. Solutions Architect – US
Sr. Solutions Architect – US

xage, inc • Palo Alto (CA)

On-site
USD 130,000 - 150,000
Competitive salary
Equity
Continuous training
+1
Senior Software Engineer – Zero Trust for Agentic AI
Senior Software Engineer – Zero Trust for Agentic AI

xage, inc • Palo Alto (CA)

On-site
USD 140,000 - 200,000
Health, dental, and vision coverage
Visa transfer and immigration support
Opportunity to work closely with executive leadership
Marketing Manager
Marketing Manager

xage, inc • Palo Alto (CA)

On-site
USD 80,000 - 85,000
Health, dental, vision insurance
Career development & training
Founders’ mentorship exposure
+1