Full Stack Security Engineer (Application & Product)

Runpod
$152,000 - $175,000Remote

About The Position

As RunPod continues to revolutionize the GPU cloud computing landscape, we are seeking a Full Stack Security Engineer to secure our customer-facing products, APIs, and internal services. This critical position will ensure the security of the software that powers our platform, enabling continued growth while protecting user data, billing systems, and web interfaces. The ideal candidate possesses strong software development abilities coupled with deep experience in application security, DevSecOps, and modern web architectures. You will embed directly with our engineering teams to ensure our product is secure by design. RunPod is seeking a proactive AppSec professional who believes in Integrated Security. You won't just toss PDF reports over the fence; you will write code to fix vulnerabilities, build automated security guardrails into our CI/CD pipelines, and foster a security-first culture among our developers.

Requirements

  • 5+ years of experience in application security, product security, or as a software engineer with a heavy security focus.
  • Strong programming and code-review skills in languages like Python, Go, JavaScript/TypeScript, or similar modern stacks.
  • Deep understanding of web application vulnerabilities (OWASP Top 10), API security (REST/GraphQL), and modern authentication flows (OAuth, OIDC, JWT).
  • Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP).
  • Experience building and maintaining automated security pipelines (DevSecOps).
  • Ability to translate complex security risks into actionable engineering tasks.

Nice To Haves

  • Relevant application security certifications (e.g., OSWE, GWAPT, CISSP).
  • Experience securing cloud-native applications running on Kubernetes/Docker environments.
  • Background in managing bug bounty programs or coordinated vulnerability disclosures.

Responsibilities

  • Lead threat modeling, architecture reviews, and code reviews for our web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in our Python, Go, or JavaScript/TypeScript codebases alongside the engineering team.
  • Implement, tune, and manage security testing tools (SAST, DAST, SCA) within our CI/CD pipelines to catch vulnerabilities early in the SDLC.
  • Configure and manage application-layer security controls, including Web Application Firewalls (WAF), bot protection, and API gateways.
  • Provide security guidance, secure coding training, and standard operating procedures to development teams.
  • Collaborate with operations to ensure product-level adherence to relevant frameworks (e.g., SOC 2, ISO 27001, GDPR) and participate in bug bounty triage.

Benefits

  • Competitive base pay
  • Meaningful equity in a fast-growing company
  • Generous medical, dental & vision plans
  • Flexible PTO
  • Remote work first
  • $1,200 Home Office & Equipment Stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service