
Staff Product Security Engineer
- Atlanta, GA
- $165,000-185,000 per year
- Permanent
- Full-time
- Support in developing and executing a comprehensive product security strategy that aligns with the company's goals and risk appetite.
- Foster a culture of security awareness and ownership across the Engineering and Product organizations.
- Integrate security best practices and automated tooling into the entire Software Development Lifecycle (SDLC), from design and threat modeling to testing and deployment.
- Establish and enforce secure development standards (i.e. API security, coding, IaC, etc.) and best practices across the organization.
- Oversee the application security program, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and manual penetration testing.
- Partner closely with engineering, product, and platform teams to prioritize and remediate security vulnerabilities in a timely and efficient manner.
- Establish and manage a mature incident response process for product-related security events and vulnerabilities.
- Partner with engineering, product, and platform teams to enhance Greenlight Application's security features.
- Stay current with the latest security threats, vulnerabilities, and industry best practices to continuously evolve our security controls and processes.
- Deep technical knowledge of web and mobile application security, common vulnerabilities (OWASP Top 10), and secure coding practices.
- Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications
- End to end experience on implementing and managing tools for Product Security (i.e. API Security, Mobile Protection, SAST, runtime scanning, etc.)
- Hands-on experience with security tools for SAST, DAST, IAST, and penetration testing.
- Strong understanding of cloud security principles in AWS environments.
- Excellent communication skills with the ability to articulate complex security concepts to both technical and non-technical audiences.
- Plus: Experience with security tools such as Burp Suite, Metasploit, Kali Linux
- Plus: Background in financial services, fintech, or highly regulated industries
- Plus: Hands-on certifications (e.g. OSCP, Certified Ethical Hacker, SANS) and/or demonstrated code projects. Please share your github or public code samples with us!
- MySQL, DynamoDB, Redis
- Kubernetes, Ambassador, Helm, Rancher
- Medical, dental, vision, and HSA match
- Paid life insurance, AD&D, and disability benefits
- Traditional 401k with company match
- Unlimited PTO
- Paid company holidays and pop-up bonus holidays
- Professional development stipends
- Mental health resources
- 1:1 financial planners
- Fertility healthcare
- 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
- Flexible WFH, both remote and in-office opportunities
- Fully stocked kitchen, catered lunches, and occasional in-office happy hours
- Employee resource groups