About The Position

Close is seeking a Senior Product Security Engineer to join their 100% remote team. This is a new role focused on making product security work systematic. The engineer will report to the Backend Platform team manager and work across the entire product and infrastructure surface. Responsibilities include finding vulnerabilities, prioritizing findings, and driving them through remediation, often by fixing them directly or providing clear guidance to owning teams. The role involves analyzing code, building proof-of-concepts, testing applications, tuning security tools, and automating vulnerability management. The engineer will be responsible for product and application security, partnering with Infrastructure on cloud security and with the Security & Trust Lead on GRC, compliance, and corporate security. This position offers significant autonomy to improve tooling, ownership, and reduce risk through code. The company utilizes a modern tech stack including Python, TypeScript, React, Docker, Kubernetes, and AWS.

Requirements

  • Application security engineer who writes code.
  • Ability to move from reading an unfamiliar code path, to reproducing an exploit, to proposing or shipping a production-quality fix.
  • Strong Python or TypeScript experience.
  • Fluency across both backend and frontend systems is preferred.
  • Skilled at finding vulnerabilities conventional scanners may miss.
  • Experience using modern AI-assisted review pipelines, guided by expert judgment, to uncover subtle flaws in web apps and APIs.
  • Ability to threat-model designs, white-box review code, and test running systems.
  • Offensive-minded and operationally responsible.
  • Ability to test like an attacker without being careless with customer data or production systems.
  • Ability to turn a finding into a safe reproduction, assess exploitability and business impact, and retest the eventual fix.
  • Automation builder with experience in SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling.
  • Ability to tune tools, connect them to engineering workflows, and remove noise.
  • AI-native and accountable, using coding agents and LLMs to accelerate investigation, code review, and repetitive engineering work, while verifying their output.
  • Ability to separate severity from priority, considering reachability, existing controls, customer impact, and attack chains.
  • Comfortable working across the business, collaborating with product engineers, Site Reliability Engineers, Security & Trust Lead, auditors, and external researchers.
  • Ability to follow findings to closure even when another team is responsible for the fix.
  • Self-directed in a remote environment, able to take an ambiguous surface and turn it into a practical plan with measurable progress.
  • Ability to investigate an unfamiliar system, determine what matters, and bring the right people along.

Nice To Haves

  • Experience with modern AI-assisted review pipelines.
  • Experience with coding agents and LLMs.
  • Experience with Python or TypeScript.
  • Experience with backend and frontend systems.

Responsibilities

  • Find vulnerabilities, determine which findings matter most, and drive them through remediation.
  • Analyze code, build proof-of-concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management.
  • Partner closely with the Infrastructure team on cloud security, access, and secrets.
  • Partner with the Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.
  • Build a recurring product security review program, including threat modeling new features, auditing high-risk areas, reviewing code, and building safe proof-of-concepts.
  • Improve application security testing by combining static analysis, dependency and secrets scanning, dynamic testing, and production testing.
  • Own vulnerability intake and remediation, triaging findings from various sources, reproducing issues, assessing exploitability and impact, tracking remediation, and verifying fixes.
  • Serve as technical lead for the bug bounty program.
  • Turn security alerts into useful engineering work by verifying scanner coverage, automating ingestion, deduplication, enrichment, prioritization, and routing.
  • Make dependency remediation safer and less manual by improving scanning, building workflows to assess upgrades, stage pull requests, run checks, and route work.
  • Make secrets routinely rotatable by partnering with service owners and Infrastructure to inventory secrets, add rotation paths, document runbooks, and automate rotation.
  • Strengthen AWS security with Infrastructure by evaluating and improving automated detection of risky configurations and turning findings into secure defaults and actionable remediation.
  • Support audits and raising the security floor by partnering with Security & Trust on external assessments, providing technical context, and ensuring findings are fixed.
  • Create documentation, paved roads, and lightweight training to help engineers make safer choices.
  • Take a key technical role in security incident response, coordinating investigation, containment, and remediation, and contributing to root-cause analysis and follow-up improvements.

Benefits

  • Competitive pay
  • Organization-wide goal-based bonus
  • ~5 weeks of PTO to start, increasing by 2 days per year
  • 1-week all-company Winter Holiday Break
  • Paid US holidays
  • 80% Work Option (4-day week at 80% pay)
  • Paid leave for primary and secondary caregivers
  • 1-month paid sabbatical every 5 years
  • Two medical plans with Close covering 99% of your premium
  • Dental insurance
  • Vision insurance
  • HSA
  • FSA
  • Company-paid Long-Term Disability
  • 401k with up to 6% company match, vested immediately
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service