Senior Security Engineer, Product Security
Summary
Senior Product Security Engineer who builds secure production services, adversarially tests AI/ML systems (prompt injection, jailbreaks), and partners with product/engineering teams to embed security by design. Core techs: TypeScript, Node.js, .NET, Python, AWS, and security tooling.
GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.
GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.
Essential Job Duties and Responsibilities
- Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
- Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
- Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
- Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
- Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
- Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
- Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
- Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
- Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
- Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
- Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.
Required Skills, Knowledge, and Abilities
- You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your résumé.
- You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
- You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
- You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
- Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
- Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
- Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
- Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
- You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.
- Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
- Running structured vendor evaluations or proofs of concept
- Contributing to security policy or standards, including for AI systems
- Delivering security training or building hands-on learning environments
- Depth in cryptography and key management
- Detection engineering, incident response, or threat hunting exposure
- An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
- Legal First Name
- Legal Last Name
- Home Phone optional
- Mailing Address Line 1
- Mailing Address Line 2 optional
- City
- State
- Zip Code
- Were you referred by a current employee of GoodLeap LLC? choose one
- If yes, please list employee name: optional
- Have you previously worked for GoodLeap LLC? choose one
- If yes, please list position: optional
- Are you subject to any type of agreement with a current or former employer or entity that would restrict your ability to work at GoodLeap LLC (e.g., non-compete, confidentiality, non-disclosure)? choose one
- University choose one · optional
- Degree optional
- No. of Years Attended optional
- Graduated? choose one · optional
- Company 1
- Title
- Years Worked
- Company 2
- Title
- Years Worked
- Are you legally eligible to work in the U.S.? choose one
- Will you now, or in the future, require visa sponsorship for employment at GoodLeap? choose one
- In connection with GoodLeap consideration of me for employment, continued employment, promotion, or reassignment, I understand that GoodLeap may obtain a consumer report and/or an investigative consumer report. GoodLeap may also conduct its own investigative inquiries into my background that may include obtaining such things as criminal, driving, personal reference(s), and job reference(s) pertaining to me. These inquiries will be conducted to provide GoodLeap with information regarding my character, general reputation, personal characteristics, mode of living, work records, salary history, characteristics, skills and abilities, education and training, employment experience, past job performance, reasons for termination of previous employment and other pertinent information. (Please initial.)
- I understand that for this purpose GoodLeap or persons acting on its behalf will be requesting information from various federal, state, and local governmental agencies, previous employers and their employees, personal acquaintances of mine, and other appropriate resources of information that maintain records or possess knowledge about my education, employment, criminal, driving and other relevant activities, experiences and records, including, but not limited to, my character, general reputation, personal characteristics, and mode of living. I authorize, without reservation, any person or entity contacted by GoodLeap or anyone acting on its behalf, to furnish the above‐stated information, and I release any such person or entity from any and all liability for furnishing such information. I also release GoodLeap from any and all liability for conducting such an investigation. I authorize GoodLeap to disclose my Social Security Number in order to obtain necessary information. I understand that if I refuse to execute this authorization, GoodLeap may refuse to grant employment based on this refusal. A copy of this executed authorization shall be valid as the original. (Please initial.)
- I understand that this employment application and any other documents, including policies, handbooks, guidelines, practices, benefits or manuals, are not intended to create any contractual obligation which in any way conflicts with GoodLeap’s policy that the employment relationship between GoodLeap and each employee is at‐will and can be terminated, with or without cause, and with or without notice at any time, at the option of either GoodLeap or the employee. I further understand that any oral or written statements to the contrary are expressly disavowed and should not and cannot be relied upon. (Please initial.)
- I understand that as a condition of employment with GoodLeap successful applicants must provide, within three days after beginning employment, documentation to prove identity and proper authorization to work in the United States. Specific instructions will be given prior to the first day of employment regarding the documents required. GoodLeap participates in E-Verify at all hiring sites throughout the United States. Individuals hired at hiring sites enrolled in E-Verify will have their Form I-9 information submitted to E-Verify. (Please initial.)
- I hereby acknowledge that I have read the above statements and understand them. I certify that I, the undersigned applicant, have personally completed this application. I declare under penalty of perjury that the facts contained in the application (or any resume or other documents submitted) are true and complete to the best of my knowledge. I understand that any misrepresentations or omissions will disqualify me from further consideration for employment, and will be justification for my dismissal from employment, if discovered at a later date. (Please initial.)
- Please enter your full legal name below as signature: