Green Light Jobs

Green Light Jobs

Staff Product Security Engineer

Atlanta (Remote Friendly) · Staff+

Sponsorship not specified$165k-$200kDetected 27 days ago
JavaSwiftKotlinReactReduxSwiftUINode.jsMySQLRedisDynamoDBAWSGCPCloud PlatformsKubernetesHelmCI/CDLinuxMachine LearningLLMsCybersecurityPenetration TestingComplianceOutbound SalesPostman

About the role

  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware.
  • You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red-team engagements.

Responsibilities

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA and attack tree methodologies.
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on-call incidents.
  • Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers and collaborating with the AI team on securing ML pipelines.
  • Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products and ensuring every engineer understands that product security is an enabler and not a gate.
  • The Staff Product Security Engineer will drive security review, threat modeling programs, lead penetration testing, manage PSIRT operations, champion secure AI adoption and establish security guardrails for AI powered products and AI assisted development workflows within a highly regulated financial services environment.

Requirements

  • Deep hands down AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and have practical experience with MITRE.
  • You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic.
  • Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications.
  • Ability to influence without authority, mentor without managing, and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance and executives alike.
  • Experience with product security tools such as Burp Suite, Metasploit, Kali Linux, Postman, etc.

Nice to have

  • Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience.
  • Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly.

Skills

  • Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems.
  • Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor.

Compensation

  • $165,000-200,000
  • $165,000-185,000

Benefits

  • The total compensation package for this position will also include a discretionary performance bonus, equity rewards, medical benefits, 401K match, and more.
  • With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family's future.

Company info

  • It takes a special team to aim for a never-been-done-before mission like ours.
  • Greenlight is committed to an inclusive work environment and interview experience.
  • If you require reasonable accommodations to participate in our hiring process, please reach out to your recruiter directly or email accomodations@greenlight.me.
  • We're looking for people who love working together because they know it makes us stronger, people who look to others and ask, "How can I help?" and then "How can we make this even better?" If you're ready to roll up your sleeves and help create a world where every child grows up to be happy and healthy in money and life, apply to join our team.
  • Greenlight is an equal opportunity employer and will not discriminate against any employee or applicant based on age, race, color, national origin, gender, gender identity or expression, sexual orientation, religion, physical or mental disability, medical condition (including pregnancy, childbirth, or a medical condition related to pregnancy or childbirth), genetic information, marital status, veteran status, or any other characteristic protected by federal, state or local law.
  • 10+ years of product security experience spanning application security, cloud security, and secure SDLC. you will have full SDLC experience from design through development, deployment and incident response.
  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware. You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red-team engagements.
  • PSIRT operational experience from vulnerability intake and triage. You are fluent in CVE, CVSS, FIRST PSIRT frameworks.
  • You understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development. You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic.
  • Strong programming ability and capability to review code, build security tools, automate workflows and be credible with the engineering teams you partner with.

This listing is sourced directly from Green Light Jobs's careers page and normalized into a canonical job model.