GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America. GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome. GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch†is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed