Senior Security Engineer, Product Security

GoodLeap - United States

Hiring: Senior Security Engineer, Product Security Company: GoodLeap Location: United States Job Posted Time: 2026-09-16 19:30:01 Target Skills & Keywords : .NET, AWS, DNS, GraphQL, IAM, Infrastructure as Code, LLM, Node.js, OAuth, OpenAPI, Penetration Testing, Product Management, Python, REST, SAST, SCA, SaaS, TypeScript About the job Qualifications: •Direct message the job poster from GoodLeap •Senior Technical Recruiter, Product @ GoodLeap Leader •Essential Job Duties and Responsibilities •Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on. •Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management. •Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year. •Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling. •Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change. •Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs. •Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount. Compensation: •$146,000 - $169,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!