Get more replies from employers
Send a job-specific resume in minutes.
Xage, headquartered in Palo Alto, seeks a Product Security Engineer focused on red team testing and threat modeling. You’ll perform manual penetration testing across Web UIs, REST/gRPC APIs, desktop clients, and backend services, with automation support as needed.
This role emphasizes collaboration across teams to improve secure design. Ideal candidates bring multi-year offensive security experience, strong coding ability to read product code, and expertise in OAuth, SAML, mTLS, RBAC/ABAC, and
Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high – and only growing more urgent by the day. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. We are pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat.
We have built tremendous momentum across governments and commercial enterprises around the world, and it’s just the beginning. Recognized by Forbes as one of America’s Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of our mission. We are headquartered in Palo Alto, CA and have global teams across North America andEMEA.
We’re passionate about solving problems that have positive, real-world consequences for the lives of everyday people. We hope you’ll join us in the fight against cyberattacks and safeguarding critical infrastructure.
This role will be focused on penetration testing, threat modeling, and security review / analysis of Xage’s current and future products. Candidates should be comfortable with learning and ramping up on new features in a large code base and performing /manual/ penetration testing to uncover business logic flaws, authorization bypasses, injection issues, and improper use of protocols / cryptographic algorithms.
While the candidate should be familiar with automation tools to help with scanning / detection of vulnerabilities, our team has already integrated extensive usage of automated tools and this will be supplemental work for this role to help improve or integrate with these existing systems or to help automate parts of the manual penetration testing effort. Integration of common automation tooling is not a primary responsibility during the early stages of this role.
Candidates will be expected to help review the design of features currently in development, as well as review of previously implemented security critical features to identify issues within the existing product. Long term some additional areas the role may progress to as needed may include war gaming / emulation of adversaries or specific breach scenarios, implementation of custom automation tooling / fuzzers specific to Xage’s products, other program support for bug bounties / developer education / compliance efforts / etc.
This role will require working across multiple teams and organizations so good communication and team work skills are essential, Xage’s engineering culture prides itself on teamwork and collaboration to help multiply everyone’s skills and development across the entire team.
Xage Security has experienced explosive growth and received numerous awards and recognition, including:
July 24, 2026