Senior Product Security

Jobtailor

California (MO)

On-site

USD 150,000 - 210,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced security engineer focused on application security, static analysis, and threat modeling. You will work with product teams to surface and validate risks, author rules, and reduce manual effort while delivering measurable security outcomes.

The role requires strong coding knowledge across multiple ecosystems and hands-on experience with static analysis tooling like Semgrep or CodeQL. Collaboration and clear communication are essential for success.

Qualifications

  • 5+ years in security engineering, application security, or a closely related role.
  • At least 2 years in hands-on vulnerability-discovery capacity.
  • Deep familiarity with at least one major language ecosystem (Java, Python, JavaScript/TypeScript, Go, Ruby, or similar).
  • Ability to read and reason about code in other languages.
  • Working knowledge of static analysis tooling and custom rule authoring, tuning, and maintenance.
  • Experience with Semgrep, CodeQL, or equivalent.
  • Practical experience with threat modeling, authentication/authorization design, cloud security architecture, or supply chain security.
  • Ability to scope own work from a vague ask.
  • Excellent written and verbal communication.
  • A related technical degree required

Responsibilities

  • Surface real risk using agentic security systems, static analysis, manual review, and threat modeling.
  • Validate findings can be triggered manually or by extending tooling.
  • Reduce manual validation costs through engineering.
  • Author static analysis rules that block recurring vulnerability classes at PR time.
  • Contribute to intake pipelines for high-value findings into merge-blocking rules.
  • Advise on findings that meet rule-worthy thresholds.
  • Provide security consulting on difficult architectural questions.
  • Apply and extend scoping methodology across products.
  • Partner with product engineering teams to identify, validate, and prevent vulnerabilities.
  • Deliver measurable impact through detections shipped and vulnerabilities closed.

Skills

Security engineering
Vulnerability discovery
Static analysis tooling
Threat modeling
Programming languages

Education

Related Technical Degree

Tools

Semgrep
CodeQL

Job description

  • Use agentic security systems, custom static analysis, manual review, and threat modeling to surface real risk
  • Validate whether security findings can actually be triggered, manually or by extending automated tooling
  • Reduce manual validation costs through engineering
  • Author static analysis rules that block recurring vulnerability classes at pull-request time
  • Contribute to the intake pipeline that graduates high-value findings into merge-blocking rules
  • Advise on which findings meet the rule-worthy threshold
  • Provide security consulting on difficult architectural questions
  • Apply and extend the scoping methodology across products
  • Partner directly with product engineering teams to identify, validate, and prevent vulnerabilities
  • Deliver measurable impact through detections shipped, vulnerabilities closed, and systemic patterns eliminated
Requirements
  • 5+ years in security engineering, application security, or a directly adjacent role
  • At least 2 years in a hands-on vulnerability-discovery capacity
  • Deep familiarity with at least one major language ecosystem (Java, Python, JavaScript/TypeScript, Go, Ruby, or similar)
  • Ability to read and reason about code in other languages
  • Working knowledge of static analysis tooling and custom rule authoring, tuning, and maintenance
  • Experience with Semgrep, CodeQL, or equivalent
  • Practical experience with threat modeling, authentication and authorization design, cloud security architecture, or supply chain security
  • Ability to scope own work from a vague ask
  • Excellent written and verbal communication
  • A related technical degree required
Core Competencies

Demonstrates expertise in security engineering and application security, with a strong focus on vulnerability discovery, static analysis tooling, and threat modeling. Capable of collaborating with product engineering teams to implement effective security measures and deliver measurable impact.

Highest-signal resume keywords
  • Security Engineering
  • Vulnerability Discovery
  • Static Analysis Tooling
  • Threat Modeling
  • Java, Python, JavaScript/TypeScript, Go, Ruby
Hard Skills
  • Static Analysis Rule Authoring
  • Vulnerability Validation
  • Code Review
  • Security Consulting
  • Cloud Security Architecture
Soft Skills
  • Excellent Written Communication
  • Excellent Verbal Communication
Certifications & Qualifications
  • Related Technical Degree
Industry Keywords
  • Application Security
  • Threat Modeling
  • Authentication Design
  • Authorization Design
  • Supply Chain Security
Tools & Technologies
  • Semgrep
  • CodeQL
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Vulnerability Management Technical Lead
Vulnerability Management Technical Lead

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 230,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Jobtailor • Lehi (UT)

On-site
USD 120,000 - 180,000
Product Security Engineer
Product Security Engineer

Inmar Inc. • Winston-Salem (NC)

On-site
USD 100,000 - 130,000
Application Security Engineer – Software Composition Analysis (SCA)
Application Security Engineer – Software Composition Analysis (SCA)

Zelis • Plano (TX)

On-site
USD 120,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Product Security Engineer
Product Security Engineer

GoMining • United States

Hybrid
USD 120,000 - 190,000
Courses & conferences support (up to )
Remote or hybrid format with flexible,
Paid time off and holidays
Penetration Testing Engineer II
Penetration Testing Engineer II

Jobtailor • Bentonville (AR)

On-site
USD 80,000 - 110,000