Senior Product Security Engineer

AnyscaleSan Francisco, CA
$180,000 - $210,000Remote

About The Position

Anyscale is seeking a Senior Product Security Engineer to address its growing product security needs as it scales to serve larger and more demanding customers. This role is crucial for owning the secure software development lifecycle (SSSDL) and acting as a partner to the engineering team in building security into the product. Reporting to the Head of Security, the successful candidate will work closely with engineering. This is a senior position with high ownership, responsible for operating a scalable SSDL, collaborating with engineering on security features and secure design, reviewing system security, and managing the process of finding, tracking, resolving, and reporting vulnerabilities in Anyscale's products. The goal for the first year is to establish an SSDL that supports engineering growth, integrate security reviews into the product shipping process, and ensure accurate, on-demand vulnerability reporting with clear resolution paths.

Requirements

  • 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup.
  • Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review.
  • A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings.
  • Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories.
  • A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches.
  • Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering.
  • The communication and seniority to set direction, review others' work, and raise the bar for those around you.

Nice To Haves

  • Experience producing vulnerability or security posture reporting for enterprise or regulated customers.
  • Familiarity with container artifact security, including image scanning, signing, and SBOM generation.
  • Experience building or maturing an SSDL program at scale.
  • Background in AI or ML platforms or distributed systems.

Responsibilities

  • Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt.
  • Partner with engineering on security features and secure-by-design architecture, from early design through implementation.
  • Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work.
  • Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand.
  • Drive vulnerabilities to resolution with engineering against defined SLAs.
  • Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks.
  • Mentor other engineers and raise the security bar across the organization.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service