StubHub

StubHub

Software Engineer II - Product Security

Los Angeles, California, United States · Mid

Sponsorship not specified$165k-$200kDetected 6 days ago
PythonJavaRubySwiftCode ReviewAWSKubernetesCI/CDCybersecurityComplianceCommunicationBurp SuiteCISSP

About the role

  • StubHub's Product Security Engineering Team plays a critical role in securing the platforms that power the world's largest ticket marketplace.
  • This team works hands-on with cutting-edge tools and cloud-native technologies to embed security into every layer of the software development lifecycle-from architecture to automation.

Responsibilities

  • Collaborate with development teams to embed security into CI/CD pipelines, including the implementation of automated code scanning tools.
  • Develop and maintain secure coding guidelines and conduct security awareness training for developers.
  • Respond to security incidents, perform root cause analyses, and recommend effective remediations.
  • Help develop and enforce application security policies, standards, and procedures aligned with industry regulations and best practices.
  • Build and maintain robust product vulnerability management processes and procedures.
  • Write and maintain production-grade APIs to automate security processes and streamline infrastructure and developer workflows.
  • Proven ability to implement SAST, DAST, and SBOM tooling within development workflows.
  • Accelerated Growth Environment: An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale.

Requirements

  • Intermediate-level experience with cloud security principles and technologies in AWS and Azure.
  • Software development experience in Java & C#.
  • Extensive experience with automated security testing tools (e.g., Burp Suite, OWASP ZAP, Snyk).
  • Strong communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences.
  • Hands-on experience in applied cryptography and key management.
  • Experience in performing structured threat modeling (e.g., STRIDE, PASTA).
  • Intermediate proficiency in at least one scripting language (e.g., Python, Ruby).
  • Familiarity with security frameworks such as PCI DSS, CIS, ISO 27001, and NIST CSF.
  • Industry-recognized security certifications (e.g., OSCP, CEH, CISSP, GWAPT).
  • Understanding of Kubernetes security fundamentals, including the use of admission controllers, network policies, role-based access control (RBAC), and ingress architecture design.

Nice to have

  • Preferred Skills and Qualifications:

Compensation

  • $165,000 - $200,000 USD
  • The anticipated gross base pay range is below for this role.

Benefits

  • Top Tier Compensation Package: Competitive base, equity, and upside that tracks with your impact.
  • Flexible Time Off: Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed.
  • Comprehensive Benefits Package: Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options.
  • Base annual salary is one component of StubHub's total compensation and competitive benefits package, which includes equity, 401(k), paid time off, paid parental leave, and comprehensive health benefits.

Company info

  • StubHub is the world's leading marketplace to buy and sell tickets to any live event, anywhere.
  • Through StubHub in North America and viagogo, our international platform, we service customers in 195 countries in 33 languages and 49 available currencies.
  • Come join our team for a front-row seat to the action.
  • If you're passionate about offensive security, CI/CD hardening, and driving real impact across modern product teams, this is your opportunity to lead and innovate at global scale.
  • Conduct security assessments, code reviews, and penetration tests on web applications, APIs, and mobile apps to identify vulnerabilities and flaws.
  • Stay current on emerging security threats, vulnerabilities, and mitigation strategies; proactively share insights across teams.
  • Conduct architectural reviews to ensure the security of new technologies and controls.
  • Triage and respond to findings from StubHub's enterprise Bug Bounty program.
  • What You've Done:
  • Demonstrated expert-level understanding of offensive web application security testing and defense-in-depth remediation strategies.
  • Expert-level skills in vulnerability assessments and code reviews.
  • Preferred Skills and
  • With more than 300 million tickets available annually on our platform to events around the world -- from sports to music, comedy to dance, festivals to theater -- StubHub offers the safest, most convenient way to buy or sell tickets to the most memorable live experiences.
  • We are an equal opportunity employer and value diversity on our team.
  • We do not discriminate on the basis of race, color, religion, sex, national origin, gender, sexual orientation, age, disability, veteran status, or any other legally protected status. <st

This listing is sourced directly from StubHub's careers page and normalized into a canonical job model.