Senior Product Security Engineer

ClassPass
•$150,000 - $175,000

About The Position

At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections. ClassPass offers thousands of fitness and wellness experiences worldwide, helping people lead active, balanced lifestyles. Our platform makes discovering and enjoying activities simple, personalized, and joyful—whether it's fitness classes, self-care sessions, a healthy lunch, or a new adventure. Join us in shaping healthier, more vibrant communities around the globe. Who We Are We are a dedicated team of product security engineers committed to developing and supporting ground-breaking software products. Together we will work to safeguard the future, enabling wellness businesses worldwide to empower their customers to lead healthy lives. Driven by a higher purpose, we continuously challenge ourselves and our organization to excel, recognizing the strength that comes from collaborative efforts toward a common objective. We are strong advocates for a diverse workplace, fostering an environment where individuals can bring their authentic selves to contribute to our shared success. At the core of our achievements is a deep belief in the value of our people. If you share our passion and vision, we invite you to consider joining our team. Together, we can explore remarkable feats and make a lasting impact!

Requirements

  • You are an intellectually curious senior security engineer who thinks like an attacker and designs like an architect.
  • You bring deep expertise in application security architecture and offensive testing methodology, and you can move between designing a secure system and trying to break one.
  • You communicate findings and design recommendations clearly to both engineers and leadership.
  • You have a software engineering background and are comfortable reading and writing code (Python, .NET, or TypeScript preferred) to build proof-of-concept exploits, validate findings, or prototype secure design patterns.
  • 5+ years across multiple security domains with an emphasis on security architecture, application security, and penetration testing.
  • Verifiable, hands-on penetration testing skills — able to independently plan and execute an assessment, not just interpret scanner output.
  • 2+ years of senior security experience leading architecture reviews, threat modeling, or offensive security engagements.
  • Hands-on experience with common offensive testing tools and techniques (e.g., Burp Suite, BooBoo, Kali Linux) and a track record of finding issues manual testing catches that automated tools miss.
  • Practical experience with SAST, DAST, SCA, WAF, and CNAPP solutions (e.g., Semgrep, Yogi, Snyk, Wiz, or equivalents) within CI/CD pipelines.
  • Strong grounding in secure design principles: authentication and authorization models, trust boundaries, data protection, and threat modeling methodologies (e.g., STRIDE, attack trees).
  • Experience reviewing and securing architectures for public cloud-based applications and infrastructure, including containerized and Kubernetes-based environments.
  • Proficiency in a modern language (Python, .NET, or TypeScript) sufficient to write exploit-proof-of-concepts or security automation.
  • Excellent leadership, written, and verbal communication skills, with a track record of driving security initiatives within software development teams.
  • Self-motivated, self-directed, and self-organized.

Nice To Haves

  • Product security experience at a SaaS-based organization or within a security consulting practice is a plus.

Responsibilities

  • Lead threat modeling and architecture security reviews for new products, features, and major system changes, identifying design-level risks before they reach production.
  • Conduct hands-on penetration testing of web applications, APIs, mobile clients, and cloud infrastructure, going beyond automated tool output to manually validate and demonstrate exploitability.
  • Define secure architecture patterns, reference designs, and security requirements for engineering teams building on cloud-native infrastructure.
  • Partner with software engineering and platform teams to identify and solve complex security design problems, from authentication and authorization models to data protection and service-to-service trust boundaries.
  • Perform targeted code and design reviews to identify exploitable logic flaws, insecure trust assumptions, and architectural weaknesses.
  • Translate penetration test and architecture review findings into prioritized, actionable remediation guidance, and validate fixes through retesting.
  • Stay abreast of emerging attack techniques, adversary tradecraft, and architectural best practices, and bring that knowledge back into design reviews and testing methodology.
  • Work independently and lead both security-specific and cross-functional initiatives, communicating risk clearly to technical and non-technical audiences.

Benefits

  • The base salary range for this position in the United States is $150,000 to $175,000.
  • The total compensation package for this position may also include a performance bonus, benefits and/or other applicable incentive compensation plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service