Product Security Engineer

DevRevIsrael, TX

About The Position

At DevRev, we are building the future of work with Computer, an AI teammate that unifies data sources, tools, and workflows into a single AI-ready platform. This platform provides real-time insights, proactive suggestions, and powerful agentic actions, extending existing software with AI-native apps and agents that collaborate with teams and customers to update workflows, coordinate across teams, and eliminate repetitive tasks. This approach, called Team Intelligence, fosters human-AI collaboration, breaks down silos, and enables solving larger problems. DevRev is a growing SaaS startup, backed by Khosla Ventures and Mayfield with over $150M raised, and is trusted by global companies. The company is building its security team from the ground up and is seeking a hands-on Product Security Engineer. This role is practical and impact-driven, involving embedding with product and engineering teams to proactively identify and address security vulnerabilities. The ideal candidate enjoys moving fast, owning problems end-to-end, and thinking like a real attacker.

Requirements

  • 5+ years of experience in application security, offensive security, or penetration testing.
  • Strong understanding of web and API security (OWASP Top 10, auth, sessions, access control).
  • Experience testing modern SaaS products.
  • Comfort working in cloud environments (AWS / GCP / Azure at a practical level).
  • Experience with common security testing tools (Burp Suite, Nuclei, etc.).
  • Ability to communicate findings clearly and pragmatically to engineers.
  • Self-starter mindset — comfortable operating with limited process and high ownership.

Nice To Haves

  • Startup experience or early-stage product exposure.
  • Bug bounty or responsible disclosure experience.
  • Secure code review experience (any major language).
  • Familiarity with CI/CD and modern SDLC security.
  • Offensive security certifications (OSCP, GWAPT, etc.).

Responsibilities

  • Actively test our SaaS product for security vulnerabilities across web apps, APIs, and cloud infrastructure.
  • Perform manual security testing and targeted penetration tests (beyond automated scanners).
  • Implement and help implement automated security test suites.
  • Identify abuse cases, business logic flaws, and real-world attack paths.
  • Work directly with engineers to reproduce issues and drive fixes.
  • Help introduce lightweight security practices into the development process (threat modeling, secure design reviews).
  • Validate fixes and ensure issues are fully resolved.
  • Stay current on new vulnerabilities, attack techniques, and SaaS-relevant threats.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service