Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Experienced Product Security Engineer image - Rise Careers
Job details

Experienced Product Security Engineer

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.


The mission of Plaid's Product Security Team is “Improve our customer’s trust by assuring secure development and delivery of products and services,  minimizing risk to the ecosystem, and preventing security incidents.” The Product Security team is responsible for managing the security processes, policies and controls to secure Plaid’s developer and consumer facing products. We are focused on areas like Application Security, Vulnerability Management, Secure Development Lifecycle, Penetration Testing and Cloud Security.


As an Experienced Product Security Engineer at Plaid, you'll be a trusted advisor, collaborating closely with engineering and product teams to ensure security is a cornerstone of every product. You'll partner with leadership to shape product strategy, advocate for strong security controls, and influence future product iterations. By leveraging your deep industry knowledge, you'll lead the charge in implementing secure architecture and design principles, ensuring early detection and prevention of vulnerabilities. Your expertise in security assessments and penetration testing will help identify and mitigate potential threats, while your mentorship and training efforts will foster a security-conscious culture. By owning specific areas of Plaid's product portfolio, you'll provide expert guidance and minimize risks, ultimately strengthening Plaid's security posture.


This role is perfect for you if:


-You thrive in a collaborative environment, working alongside product, engineering, and security teams.

-Your passion lies in designing secure solutions and building robust security programs.

-You possess a deep understanding of security best practices and industry trends.

-You have a knack for translating complex technical concepts into actionable strategies.

-You enjoy developing and mentoring others, fostering a strong security culture.


Join us, and be part of the future where security is the cornerstone of everything we build!


Responsibilities
  • Collaborate with engineering and product teams to integrate security into the product lifecycle, from inception to deployment, ensuring that security is a core consideration in all design and development decisions.
  • Conduct Threat Modeling and Risk Assessments from the early stages of the product development lifecycle to identify, assess, and prioritize security risks, enabling proactive mitigation strategies.
  • Perform rigorous security testing and reviews for new features being built in the assigned area to uncover and address security weaknesses.
  • Lead incident response efforts, investigate root causes, and implement corrective actions to minimize impact and prevent future occurrences.
  • Foster a Security-Conscious Culture by educating and empowering engineering and product teams through training, awareness campaigns, and mentorship, cultivating a strong security mindset.


Requirements
  • Must haves:
  • Proven experience in product and application security concepts, including API, web, and mobile app security.
  • Ability to communicate complex security concepts to technical and non-technical audiences, including senior leadership.
  • Expertise in conducting comprehensive threat modeling and risk assessments to identify and mitigate vulnerabilities.
  • Proficiency in secure SDLC practices, application security testing tools (SAST, DAST, Burp Suite), container security (Docker, Kubernetes), and cloud security.
  • Proven ability to thrive in fast-paced environments and excel in ambiguous situations. 

  • Nice to haves:
  • Knowledge and experience in securing AI/ML based products.
  • Experience with the risk management associated with financial technology companies.
  • Experience with red teaming or penetration testing.


$186,840 - $279,720 a year
Target base salary for this role is between $186,840 and $279,720 per year. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!


Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.


Please review our Candidate Privacy Notice here.

Plaid Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Plaid DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Plaid
Plaid CEO photo
Zach Perret
Approve of CEO

Average salary estimate

$233280 / YEARLY (est.)
min
max
$186840K
$279720K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Experienced Product Security Engineer, Plaid

As an Experienced Product Security Engineer at Plaid, you'll play a crucial role in safeguarding the future of finance. At Plaid, our mission is to empower individuals by enhancing how they interact with their financial lives. We're collaborating with a myriad of companies—from banks to fintech applications—to ensure seamless and secure access to financial data. Your primary responsibility will be to work closely with engineering and product teams, ensuring that security is at the heart of our development processes. You'll leverage your expertise to conduct threat modeling, implement secure design principles, and engage in vulnerability assessments. Your role is not just about identifying risks, but also about fostering a security-conscious culture within the organization. As you mentor team members and lead incident response efforts, you will use your passion for security to help shape product strategy. The ideal candidate thrives in a fast-paced environment, enjoys translating complex security concepts into actionable strategies, and is passionate about developing robust security frameworks. Joining Plaid means you’re not just another engineer; you’re a trusted advisor, a collaborator in creating products that millions trust. If you’re ready to take on the challenge, become a pivotal part of our mission to build a secure, equitable financial ecosystem. Together, we can ensure that security is foundational to everything we create for developers and consumers alike. Let's redefine what trust means in technology together!

Frequently Asked Questions (FAQs) for Experienced Product Security Engineer Role at Plaid
What are the responsibilities of the Experienced Product Security Engineer at Plaid?

The Experienced Product Security Engineer at Plaid is tasked with integrating security into every phase of product development, conducting thorough threat modeling and risk assessments, leading incident responses, and fostering a security-conscious culture across teams. By collaborating closely with engineering and product teams, you will ensure that security is a priority and a foundational aspect of our product offerings.

Join Rise to see the full answer
What skills are essential for the Experienced Product Security Engineer position at Plaid?

Essential skills for the Experienced Product Security Engineer role at Plaid include a deep understanding of product and application security concepts, proficiency in secure development lifecycle practices, and expertise in application security testing tools. Successful candidates should also possess the ability to articulate complex security concepts to diverse audiences and excel in fast-paced, ambiguous settings.

Join Rise to see the full answer
How does the Experienced Product Security Engineer contribute to Plaid's security culture?

The Experienced Product Security Engineer at Plaid plays a vital role in cultivating a security-conscious culture by offering mentorship, training, and awareness campaigns. By engaging with product and engineering teams and empowering them with security knowledge, the engineer ensures that all employees prioritize security in their daily tasks and decisions.

Join Rise to see the full answer
What experience is preferred for the Experienced Product Security Engineer role at Plaid?

Preferred experience for the Experienced Product Security Engineer at Plaid includes robust knowledge in application security, including API and mobile app security, familiarity with cloud security, and experience with risk management in fintech. Additional experience with AI/ML product security and penetration testing is also a plus, as it aligns with the evolving security landscape.

Join Rise to see the full answer
What is Plaid's approach to diversity and inclusion for the Experienced Product Security Engineer role?

Plaid is committed to building a diverse and equitable team, as demonstrated by our open invitation for candidates with varied experiences to apply for the Experienced Product Security Engineer role. We value the unique perspectives that diverse individuals bring, and we strive to create an inclusive environment where everyone feels empowered to contribute to our mission.

Join Rise to see the full answer
Common Interview Questions for Experienced Product Security Engineer
How do you integrate security into the product development lifecycle?

To integrate security into the product development lifecycle, it's essential to collaborate closely with engineering and product teams from the outset. You can initiate security discussions during project planning and involve security assessments throughout every phase, ensuring security considerations are part of the design, implementation, and monitoring processes.

Join Rise to see the full answer
Can you describe your experience with threat modeling?

In discussing my experience with threat modeling, I would emphasize a systematic approach, starting with identifying assets and potential threats, assessing vulnerabilities, and determining risk levels. Using methodologies like STRIDE or PASTA, I systematically prioritize threats based on impact and likelihood, which allows teams to tackle the most pressing security concerns first.

Join Rise to see the full answer
What tools do you use for application security testing?

For application security testing, I typically use tools like SAST for static code analysis, DAST for dynamic testing of running applications, and Burp Suite for web vulnerability scanning. These tools help to identify security weaknesses early and allow for iterative improvements through the development cycle.

Join Rise to see the full answer
How would you educate non-technical team members about security risks?

When educating non-technical team members about security risks, I focus on simplifying complex concepts and using relatable analogies. I conduct interactive workshops or training sessions, emphasizing real-world security incidents to highlight risks and promote best practices, making the content engaging and relevant.

Join Rise to see the full answer
What is your experience with incident response?

My experience with incident response involves leading cross-functional teams during security incidents, conducting root cause analyses, and formulating a clear communication plan. I prioritize documenting the incident thoroughly and implementing corrective actions while working to refine our incident response processes ensure better preparedness for future issues.

Join Rise to see the full answer
Can you discuss a successful security program you've implemented?

In my previous role, I successfully implemented a security awareness program that included regular training sessions, phishing simulations, and ongoing communication about security updates. This initiative led to a significant reduction in security incidents due to better employee engagement and understanding of security practices.

Join Rise to see the full answer
What are the key components of a secure development lifecycle?

Key components of a secure development lifecycle (SDLC) include threat modeling, secure coding practices, regular security testing, and continuous monitoring. By embedding security into each phase—planning, development, testing, deployment, and maintenance—teams can proactively identify and address vulnerabilities, enhancing the security of the final product.

Join Rise to see the full answer
How do you stay updated on the latest security trends and threats?

To stay updated on the latest security trends and threats, I engage with the cybersecurity community through blogs, webinars, and conferences. I also participate in forums, subscribe to industry reports, and follow thought leaders on social media to ensure I’m aware of emerging threats and best practices.

Join Rise to see the full answer
How do you manage communication with senior leadership regarding security risks?

When communicating security risks to senior leadership, I focus on presenting clear, concise summaries that highlight the potential business impact. Providing visual data and actionable recommendations can help facilitate informed decisions. It's essential to align security objectives with the company’s strategic goals to demonstrate the importance of addressing these risks.

Join Rise to see the full answer
What role does mentorship play in your approach to product security?

Mentorship is a crucial component of my approach to product security. By actively mentoring colleagues, I help foster a culture of security awareness and skill development. This includes conducting regular knowledge sharing sessions, providing resources for professional growth, and encouraging open dialogue about security challenges and solutions.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 5 days ago
xAI Hybrid San Francisco & Palo Alto, CA
Posted 2 days ago
Posted 10 days ago
Photo of the Rise User
Posted 3 days ago
Eve Remote San Mateo, California
Posted 12 days ago
Photo of the Rise User
Zeeco Hybrid Plainville, CT
Posted 13 days ago
Photo of the Rise User
Posted 8 minutes ago
Photo of the Rise User
Posted 12 days ago

Plaid’s mission is to unlock financial freedom for everyone.

84 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 11, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!