Senior Product Security Engineer (USA Only, 100% Remote)

Close

United States

Remote

USD 140,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Remote-friendly work model
Parental leave
Sabbatical

Job summary

Close is seeking a Product Security Engineer to own security across our platform. You’ll write code in Python/TypeScript, identify and fix vulnerabilities, and influence threat modeling across backend, frontend, APIs, and cloud services.

You’ll partner with Infrastructure and Trust teams to advance SOC 2/compliance goals and reduce risk, in a fully remote work environment, across our Python/Flask/FastAPI, React, Docker/Kubernetes on AWS stack.

Qualifications

  • Proficient in Python or TypeScript with full-stack capability.
  • Experience finding vulnerabilities beyond traditional scanners.
  • Knowledge of cloud security, IAM, and governance practices.

Responsibilities

  • Own remediation of vulnerabilities from discovery to fix.
  • Develop PoCs and actionable remediation plans for complex issues.
  • Collaborate with Infra, Security & Trust, and Product teams to reduce risk across services.

Skills

Python
TypeScript
Security analysis
Threat modeling
Cloud security

Tools

Docker
Kubernetes
AWS

Job description

About Us
Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication-first, AI-powered sales software designed to help you succeed and scale.
We're bootstrapped and profitable which means we answer to our customers and play by our rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can't figure out sales.
Benefits

  • Compensation: Competitive pay plus an organization-wide goal-based bonus

  • Paid Time Off: ~5 weeks of PTO to start. Plus a 1-week all-company Winter Holiday Break and paid US holidays. You'll earn 2 extra days for every year you're with Close.

  • 80% Work Option: Work with your manager to choose between a standard 5-day week or a 4-day week at 80% pay

  • Parental Leave: Paid leave for primary and secondary caregivers

  • Sabbatical: A 1-month paid sabbatical every 5 years with the team

  • Healthcare (US residents): Two medical plans with Close covering 99% of your premium, plus Dental, Vision, HSA, FSA, and company-paid Long-Term Disability

  • 401k (US residents): We match your contributions up to 6%, vested immediately

About the Role

Close is a CRM built around the communication tools sales teams use every day: email, calling, SMS, workflows, reporting, and AI. Underneath that product is a broad technical surface —Python services and a large application backend, a TypeScript and React frontend, public APIs, Docker and Kubernetes, AWS infrastructure, and integrations with providers that handle sensitive customer data.

Security work happens across it all today, but the ownership is spread across Engineering, Infrastructure, and Security & Trust. We’re hiring our first dedicated Product Security Engineer to make that work systematic. You’ll report to the Backend Platform team manager within EPD (Engineering, Product, and Design), while working across the entire product and infrastructure surface. You’ll find vulnerabilities, determine which findings matter most, and drive them through remediation. Often you’ll fix the problem yourself. Other times you’ll give the owning team a clear reproduction, a practical path forward, and enough context to prioritize correctly.

You’ll analyze code, build proof-of-concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management. This is not a role where you forward scanner alerts and call the queue managed. Product and application security will be your responsibility. You’ll partner closely with our Infrastructure team on cloud security, access, and secrets, and with our Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.

This role is a new one at Close. You’ll have significant room to decide where better tooling, clearer ownership, and a small amount of code can reduce the most risk.

Our stack

Our backend is primarily Python, with Flask and FastAPI services and TaskTiger and Temporal handling much of our asynchronous work. We expose REST and GraphQL APIs and store data in MongoDB, PostgreSQL, Elasticsearch, and Redis.

Our frontend is a large single-page TypeScript application built primarily with React. We bundle with Vite, target modern browsers, and test with Vitest, React Testing Library, Playwright, and Chromatic. The product updates in near real time and uses technologies including WebSockets and WebRTC. Our mobile application is built with React Native.

We build and test Docker images in CI/CD and continuously deploy them to Kubernetes on AWS. Our infrastructure uses managed services including EKS, MSK, and ElastiCache, alongside services running on EC2. Terraform and Ansible automate much of the underlying infrastructure, and our containerized local development environment lets engineers run the full system on their own machines.

For this role, our stack extends beyond simply backend or frontend: browser behavior, frontend state, API authorization, asynchronous processing, data access, third-party integrations, containers, and cloud configuration can all be part of the same attack path.

We love open sourcing our code and ideas on our GitHub and on The Making of Close, our behind-the-scenes Product & Engineering blog. Check out our open source projects like SocketShark, TaskTiger, LimitLion and ciso8601.

AI is both how we build and what we ship, and that's reshaped what engineering looks like. This is a transformation we’re embracing and find deeply exciting.

You are
  • An application security engineer who writes code. You can move from reading an unfamiliar code path, to reproducing an exploit, to proposing or shipping a production-quality fix. Strong Python or TypeScript experience would be especially useful; fluency across both backend and frontend systems is even better.

  • Skilled at finding vulnerabilities conventional scanners may miss. You use modern AI-assisted review pipelines, guided by expert judgment, to uncover subtle flaws in web apps and APIs—from authentication, authorization, and tenant isolation to injection, SSRF, unsafe data flows, and business logic. You can threat-model designs, white-box

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer (USA Only, 100% Remote)
Senior Product Security Engineer (USA Only, 100% Remote)

Close • Northern (KY)

Remote
USD 140,000 - 180,000
PTO ~5 weeks
80% work option
Parental leave
+3
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)

Bazeta • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)

Close • Northern (KY)

Remote
USD 180,000 - 240,000
PTO 5 weeks
4/5 day work week
Parental leave
+3
Senior Product Security Engineer - Remote AI Focus
Senior Product Security Engineer - Remote AI Focus

Close • United States

Remote
USD 140,000 - 200,000
Health insurance
Remote-friendly work model
Parental leave
+1
Senior Product Security Engineer - Remote
Senior Product Security Engineer - Remote

Close • Northern (KY)

Remote
USD 140,000 - 180,000
PTO ~5 weeks
80% work option
Parental leave
+3
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)

Coinscapture • Northern (KY)

Hybrid
USD 150,000 - 190,000
Paid Time Off
Remote work option
Healthcare
+1
Backend Engineer (Security)
Backend Engineer (Security)

Remote Worker LTD. • United States

Remote
USD 140,000 - 210,000
Compensation & equity
Async work
Home office setup
+3
Senior Product Security Engineer
Senior Product Security Engineer

Function • United States

On-site
USD 150,000 - 190,000
Choose your own holidays
Health Insurance
401k Match
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)
Senior Backend Engineer - Backend Platform (USA Only, 100% Remote)

Promptcube3 • Northern (KY)

Hybrid
USD 140,000 - 210,000
PTO 5 weeks
Winter holiday break
US holidays
+3
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3