Product Security Engineer

YipitData
$180,000Remote

About The Position

YipitData is seeking a Product Security Engineer to integrate security into the products and services offered to customers. This role involves close collaboration with Engineering and Product teams throughout the development lifecycle. The engineer will assess new products and technologies, conduct threat modeling and security design reviews, identify vulnerabilities, and assist teams in implementing practical fixes before production. This is a hands-on position requiring an understanding of modern application design and development, comfort with reviewing system architecture, analyzing vulnerabilities, working directly with engineers, and enhancing security tools within development pipelines. The role is remote-friendly within the US, with flexible work hours, though most employees align with East Coast hours. The annual base salary range is anticipated to be $180,000/year.

Requirements

  • Worked in product security, application security, software engineering, penetration testing, or another role that taught you how applications are built and broken
  • Can look at a complex system, follow the data, identify trust boundaries, and quickly understand where the real risks may be hiding
  • Know how to threat model, review architecture, and assess applications without relying entirely on a checklist
  • Can validate a vulnerability, determine whether it is actually exploitable, and explain why it matters to both engineers and business leaders
  • Comfortable working across APIs, cloud services, containers, serverless technologies, and CI/CD pipelines
  • Worked with tools such as SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning, and know that getting useful results takes more than simply turning them on
  • Can read and write code and are excited to automate repetitive security work using Python, JavaScript, or a similar language
  • Bring strong judgment and can balance security, customer impact, engineering effort, and business priorities
  • Communicate clearly, ask thoughtful questions, and can build credibility with both technical and non-technical teams

Nice To Haves

  • Secured AI-enabled products, agents, large language model applications, or MCP integrations and are excited by risks that do not yet have a perfect playbook
  • Deep experience with identity, authentication, authorization, or multi-tenant application security
  • Applied frameworks such as the OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST in real-world environments
  • Enjoy working across multiple products and engineering teams in an environment where priorities move quickly and no two days look exactly the same

Responsibilities

  • Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production
  • Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked
  • Find and validate vulnerabilities, separate real risk from noise, and help teams prioritize what actually matters
  • Work alongside engineers to design remediate plans that protect customers without bringing development to a halt
  • Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning
  • Tune security tools and workflows so engineers receive useful findings instead of a flood of false positives
  • Build automation that allows Product Security to keep pace as our products, engineering teams, and use of AI continue to grow
  • Turn security lessons into clear standards, secure design patterns, coding guidance, and documentation engineers will actually use
  • Help lead the response when product security issues arise, from initial investigation and containment through root cause analysis and long-term remediation
  • Become a trusted partner to Engineering and Product by bringing strong security judgment and workable solutions to difficult decisions
  • Explore emerging risks across cloud and AI-enabled products and help YipitData prepare for attack techniques that do not yet have a standard playbook

Benefits

  • flexible work hours
  • flexible vacation
  • generous 401K match
  • parental leave
  • team events
  • wellness budget
  • learning reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service