Senior Product Security Engineer
Posted 48mins ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Product Security Engineer securing Close’s AI-powered CRM across applications, APIs, cloud infrastructure, and integrations. Building vulnerability management, security automation, and incident-response capabilities.
Responsibilities:
- Build a recurring product security review program across backend, frontend, APIs, and customer-facing integrations
- Threat-model new features, audit high-risk areas, review code, and build safe proof-of-concepts in isolated development environments
- Improve application security testing using static analysis, dependency and secrets scanning, dynamic testing, and focused automation
- Own vulnerability intake and remediation from HackerOne, scanners, penetration tests, audits, customers, and internal research
- Reproduce issues, assess exploitability and impact, track remediation, and verify fixes
- Serve as technical lead for the bug bounty program
- Automate security-alert ingestion, deduplication, enrichment, prioritization, and routing
- Improve dependency scanning and create safer upgrade and pull-request workflows
- Inventory application secrets, add rotation paths, document runbooks, and automate rotation where appropriate
- Expand Vault-backed dynamic credentials and reduce emergency secret rotations
- Partner with Infrastructure to strengthen AWS security across identity, networking, compute, storage, containers, and registries
- Create secure defaults, just-in-time access patterns, infrastructure guardrails, and actionable remediation
- Support external assessments, audits, SOC 2 goals, documentation, paved roads, and engineering training
- Take a key technical role in security incident response, including investigation, containment, remediation, root-cause analysis, and follow-up improvements
- Report to the Backend Platform team manager within Engineering, Product, and Design while working across the product and infrastructure surface
Requirements:
- USA-only role; must be legally able to work in the US
- Application security engineer who writes code and can move from code analysis to exploit reproduction and production-quality fixes
- Strong Python or TypeScript experience; fluency across backend and frontend systems is advantageous
- Ability to find vulnerabilities conventional scanners may miss
- Experience with authentication, authorization, tenant isolation, injection, SSRF, unsafe data flows, and business logic security
- Ability to threat-model designs, conduct white-box code reviews, and test running systems
- Ability to test like an attacker while protecting customer data and production systems
- Experience with SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling
- Ability to tune security tools, connect them to engineering workflows, and reduce noise
- Experience using coding agents and LLMs while verifying their output
- Ability to assess exploitability, business impact, reachability, existing controls, and attack chains
- Ability to collaborate with product engineers, Site Reliability Engineers, Security & Trust, auditors, and external researchers
- Ability to work self-directed in a remote environment and turn ambiguous security surfaces into practical plans
- Knowledge of Python, TypeScript, React, Flask, FastAPI, GraphQL, Docker, Kubernetes, AWS, Vault, GitHub Actions, MongoDB, PostgreSQL, Redis, Kafka, Elasticsearch, or related security tooling
Benefits:
- Competitive pay plus an organization-wide goal-based bonus
- ~5 weeks of PTO to start
- 1-week all-company Winter Holiday Break
- Paid US holidays
- 2 extra PTO days for every year with Close
- Choice of a standard 5-day week or a 4-day week at 80% pay
- Paid leave for primary and secondary caregivers
- 1-month paid sabbatical every 5 years with the team
- Two medical plans for US residents with Close covering 99% of the premium
- Dental coverage
- Vision coverage
- HSA
- FSA
- Company-paid Long-Term Disability
- 401(k) matching up to 6% for US residents, vested immediately
- Annual in-person company team gatherings/offsites



















