P
Staff Product Security Engineer (Security)
Phantom
Contract type
Ongoing
Work mode
100% remote
Experience
Senior · 5+ years
Job description
Key details
- Partner with engineering teams to identify and address security risks across mobile applications, web products, APIs, and backend services
- Lead security reviews for new products and major architectural changes, focusing on authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations
- Embed practical security controls into the software development lifecycle from design through production operation
- Perform AI-assisted security code reviews and targeted testing of high-risk features, building repeatable vulnerability discovery approaches
- Develop and improve security tooling that provides fast, actionable feedback without unnecessary friction
- Harden CI/CD, build, and release systems against supply chain threats including dependency risk, secrets exposure, build provenance, and artifact integrity
- Triage findings from internal testing, researchers, bug bounty, and third-party assessments, driving issues through verified remediation
- Support investigation of product security incidents and turn lessons into durable improvements
- Establish product security patterns and expectations across engineering; lead ambiguous cross-functional initiatives at Staff level
- Company mission
- Information not specified
Primary stack
Core technologies
TypeScriptPython (Programming Language)Go
Benefits
- Information not specified
Requirements & details
- 5+ years of experience in product security, application security, security engineering, or software engineering, including senior or staff level
- Strong understanding of web, mobile, API, and distributed-system security including authentication, authorization, session management, cryptography, and common vulnerability classes
- Hands-on experience building or applying AI-assisted security tooling to test applications and APIs
- Ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python, and Go
- Experience securing software supply chains and CI/CD systems including dependencies, build provenance, and artifact integrity
- Fully remote role open to candidates based in the US, UK, and Canada
- TypeScript, JavaScript, Rust, Python, Go, AI Agents, LLMs
- TypeScript
- Python (Programming Language)
- Go
