{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/title/product-security-engineer"},"x-facet":{"type":"title","slug":"product-security-engineer","display":"Product Security Engineer","count":3},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ef348b50-2ac"},"title":"Product Security Engineer","description":"<p>Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our rapidly evolving platform. You will partner closely with product engineering teams to build paved roads, frameworks, and automated controls that make the secure path the easy path for our engineering teams.</p>\n<p>Your responsibilities will include developing self-service security frameworks and &#39;paved roads&#39; that allow engineering teams to ship secure code by default. You will focus on automated guardrails for common vulnerabilities, while prioritising deep-dive design reviews into complex business logic and data isolation issues. You will also partner with product and engineering teams to review designs early, contribute to threat modelling for new features and complex initiatives, and provide clear, actionable security guidance.</p>\n<p>You will research emerging threats and evolving best practices, specifically regarding AI and LLM safety, and implement controls to secure these workflows. You will manage and evolve our approach to external penetration testing and bug bounties, driving remediation for findings and treating vulnerability management as an engineering problem.</p>\n<p>You will contribute to the long-term roadmaps, metrics, and strategic planning for the security team. As a senior member of the team, you will lead complex threat modelling sessions for major product launches and define secure coding standards, and actively mentor other engineers to raise the technical security bar across the organisation.</p>\n<p>We are looking for a highly experienced Product Security Engineer with a strong background in computer science or a related field, and proficiency in writing clean, maintainable code. You should have deep familiarity with JavaScript or TypeScript, Node.js, and modern web application frameworks, and be able to reason about the security implications of systems built on them. You should also have hands-on experience securing LLM integrations and identifying prompt injection or data leakage risks.</p>\n<p>You will excel at communicating complex security risks to non-security stakeholders and enjoy collaborating cross-functionally to find solutions that balance security with engineering velocity. You will be comfortable working in a fast-paced environment, navigating ambiguity, continuously learning about emerging threats and technologies, and contributing to long-term security strategy.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ef348b50-2ac","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Airtable","sameAs":"https://airtable.com/","logo":"https://logos.yubhub.co/airtable.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/airtable/jobs/8194662002","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["JavaScript","TypeScript","Node.js","Modern web application frameworks","LLM integrations","Prompt injection","Data leakage risks","Threat modelling","Secure coding standards"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:55:21.514Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA; New York, NY; Remote (Seattle, WA only)"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"JavaScript, TypeScript, Node.js, Modern web application frameworks, LLM integrations, Prompt injection, Data leakage risks, Threat modelling, Secure coding standards"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b284be7d-7d6"},"title":"Product Security Engineer","description":"<p>Meet Yubico: the creator of the most secure passkeys and leading provider of hardware authentication security keys. Our company’s mission is to make secure login easy and available for everyone.</p>\n<p>Yubico was founded in 2007 by Stina and Jakob Ehrensvard, and is public on Nasdaq Stockholm Main Market: YUBICO. Our customers include Fortune 500 companies, hundreds of government agencies and millions of individuals in over 160 countries that rely on Yubico technology to secure access to computers, online services and mobile apps.</p>\n<p>The Role: The Product Security team is responsible for ensuring Yubico develops and maintains secure products and services. As part of the Product Security team, your primary responsibility will be to collaborate with the firmware and software teams to design and integrate solutions that support secure design and development practices.</p>\n<p>Tasks &amp; Responsibilities:</p>\n<ul>\n<li>Define and evangelize requirements and guidance for secure by design and secure by default principles</li>\n<li>Implement automation to prevent and detect security flaws in all phases of development</li>\n<li>Conduct design reviews and manual security assessments</li>\n<li>Lead training and awareness sessions</li>\n<li>Define and implement metrics to provide visibility into the impact of your work</li>\n<li>Define, lead, and influence processes to secure products and services</li>\n<li>Identify and advocate for new and novel uses of Yubico’s technology</li>\n</ul>\n<p>Basic Qualifications:</p>\n<ul>\n<li>3+ years in a product security role</li>\n<li>3+ years of software development</li>\n<li>Proficiency in threat modeling</li>\n<li>Proficiency in C</li>\n<li>Knowledge of common vulnerability classes</li>\n<li>Experience in static code analysis</li>\n</ul>\n<p>Optional Skills and Experience:</p>\n<ul>\n<li>Knowledge of WebAuthn, OATH HOTP, OATH TOTP, U2F, PIV, or OpenPGP</li>\n<li>Proficiency in .NET or C++</li>\n<li>Experience developing for ARM</li>\n<li>Experience in targeted fuzzing</li>\n</ul>\n<p>Additional Information\nWe are an equal opportunity employer, we value diversity and uphold an inclusive environment where all people feel that they are equally respected and valued. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity or expression, age, marital status, religion, national origin, disability, protected Veteran status or any other characteristic protected by law.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b284be7d-7d6","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Yubico","sameAs":"https://www.yubico.com/","logo":"https://logos.yubhub.co/yubico.com.png"},"x-apply-url":"https://jobs.lever.co/yubico/646cd3ab-3be7-4987-a508-6bfdf83c71cc","x-work-arrangement":"remote","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$120,000-140,000 per year","x-skills-required":["product security","software development","threat modeling","C","static code analysis"],"x-skills-preferred":["WebAuthn",".NET","C++","ARM","targeted fuzzing"],"datePosted":"2026-04-17T13:13:08.372Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Western US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"product security, software development, threat modeling, C, static code analysis, WebAuthn, .NET, C++, ARM, targeted fuzzing","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":120000,"maxValue":140000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_f4ab3a42-b0a"},"title":"Product Security Engineer","description":"<p>We believe that the way people interact with their finances will drastically improve in the next few years. We&#39;re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products.</p>\n<p>Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use.</p>\n<p>The Product Security team is responsible for the processes, policies, controls, and engineering systems that secure Plaid&#39;s developer- and consumer-facing products. The team focuses on areas including application security, vulnerability management, secure development lifecycle, penetration testing, and cloud security.</p>\n<p>We&#39;re looking for a Product Security Engineer who is fundamentally a builder. Unlike traditional product security roles, this position is designed for a software engineer who wants to solve security challenges at scale by developing production-grade services, libraries, and frameworks.</p>\n<p>In this role, you&#39;ll build and maintain Plaid&#39;s vulnerability management orchestration service, automate workflows to reduce operational toil, and create solutions that eliminate entire classes of vulnerabilities. You&#39;ll also partner closely with product engineers to ensure services meet security standards, support incident response and security awareness efforts, and collaborate across the security platform organization to deliver the engineering foundations that make secure development the default at Plaid.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Build the secure engineering foundations that secure the future of digital finance.</li>\n<li>Develop maintainable and secure software to enhance Plaid&#39;s security posture and create paved roads for developers for easy and default integration of security controls.</li>\n<li>Design, develop, and maintain security-critical services and components.</li>\n<li>Develop internal tooling to automate vulnerability detection, dependency management, and remediation workflows within the CI/CD pipeline.</li>\n<li>Replace manual security gates with engineered solutions that allow product teams to ship faster and more securely.</li>\n<li>Communicate effectively with managers and team members regarding project deliverables and progress.</li>\n<li>Design and implement technical solutions that align with the evolving needs of the business.</li>\n<li>Proactively identify and address security vulnerabilities in products and services.</li>\n<li>Actively participate in incident response and security awareness initiatives.</li>\n</ul>\n<p><strong>Qualifications</strong></p>\n<ul>\n<li>2 + years of professional experience building and scaling production services.</li>\n<li>Ability to architect software systems to meet security, privacy, usability, scalability and cost requirements.</li>\n</ul>\n<p>While these experience and characteristics are not prerequisites, candidates who possess them would be well-suited for the role:</p>\n<ul>\n<li>Experience building systems or services related to vulnerability management, data encryption, key management, secret management, user authentication, service authentication, authorization systems, and security policy enforcement.</li>\n<li>Experience designing distributed systems and microservices with a focus on performance and reliability.</li>\n<li>Familiarity with modern cloud infrastructure (AWS, Kubernetes, Terraform) and how to integrate security controls into them.</li>\n<li>A passion for creating tools and libraries that other engineers love to use.</li>\n<li>Passionate about educating others on security and privacy.</li>\n</ul>\n<p><strong>Additional Information</strong></p>\n<p>Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn&#39;t fully match the job description.</p>\n<p>We are always looking for team members that will bring something unique to Plaid!</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_f4ab3a42-b0a","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Plaid","sameAs":"https://plaid.com/","logo":"https://logos.yubhub.co/plaid.com.png"},"x-apply-url":"https://jobs.lever.co/plaid/49f7e590-5487-4c58-84fb-54045ab793d1","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$188,748-$260,652 per year","x-skills-required":["vulnerability management","data encryption","key management","secret management","user authentication","service authentication","authorization systems","security policy enforcement","cloud infrastructure","AWS","Kubernetes","Terraform"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:52:37.315Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"vulnerability management, data encryption, key management, secret management, user authentication, service authentication, authorization systems, security policy enforcement, cloud infrastructure, AWS, Kubernetes, Terraform","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":188748,"maxValue":260652,"unitText":"YEAR"}}}]}