Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Product Security Engineer image - Rise Careers
Job details

Senior Product Security Engineer

Who We Are

Red Canary was founded to create a world where every organization can make its greatest impact without fear of cyber threats. We’re a cyber security company who protects, supports and empowers organizations to make better security decisions so they can focus on their mission without fear of cyber threats.


The combination of our market-defining technology and expertise prevents breaches every day and sets a new standard for partnership in the industry. We’re united in our commitment to customers and grounded in our values, which earned us a place on the Forbes Best Start-up Employers 2022 list.  If our mission resonates with you, let’s talk.


What We Believe In

- Do what’s right for the customer

- Be kind and authentic

- Deliver great quality

- Be relentless


Challenges You Will Solve

Delivering excellent, secure software is paramount to Red Canary's mission! Some of the best security teams in the world depend on our software to protect their organizations, and in turn we expect the highest standards of security for our platform.


Our Senior Product Security Engineers collaborate across product teams to mature our product security program and help ensure secure outcomes for software development at scale. Under your guidance, the Red Canary product security model will be viewed as the standard by which all other security providers are measured. The program you will join enables rapid development of our product features for our customers, by providing repeatable secure patterns and seamless guardrails.


A continuous improvement mentality is crucial for success! In this role you’ll get the opportunity to craft and implement security standard methodologies at every stage of the development lifecycle, from design through production. Not only will you have the chance to uncover exploitable bugs in software, but more meaningfully, you’ll be an integral piece of getting them fixed as early in the process as possible.


What You'll Do
  • Embed with the product teams and attend regular stand-ups and planning meetings and build positive relationships with key partners
  • Serve as the security authority on your product, ensuring the corporate security controls are working as designed, that security requirements are provided to the team before coding begins, and that vulnerabilities are being fixed within their SLAs
  • Ensure s-SDLC controls are embedded in your product and serve as control owner for a subset of these controls, mentoring other team members
  • Engage in application and domain-specific threat modeling, and attack surface analysis and reduction
  • Work alongside engineers, performing peer review and mentoring as needed
  • Assist in continuous improvement efforts and serve as a resource for more junior members


What You'll Bring
  • At least 5 years experience in securing enterprise-grade web applications and services with demonstrated expertise in threat modeling and attack surface analysis.
  • Solid understanding of common languages such as Ruby, Javascript, Go, etc.
  • Strong experience in web application security issues and standards (ex. OWASP Top 10, SANS Top 25, etc.)
  • Understanding and experience with securing public cloud deployments, including AWS and/or Azure, and serverless architecture 
  • Familiarity with CI/CD tools and processes, such as GitHub, Travis CI, CircleCI, Docker, and Kubernetes
  • Strong foundation in core information security principles and concepts (encryption, authentication, etc.)
  • Experience with automated application security tools and technologies (SAST, DAST, SCA etc.)
  • Excellent communication skills and the ability to explain sophisticated security topics in simple terms


Based salary for the role is $155,000 - $160,000. 


This role is eligible for a grant of stock options, subject to the approval of the company's board of directors. This role is also eligible for participation in the company's bonus program.


The application deadline is January 3, 2025.



Why Red Canary?

Red Canary is where people embody our mission to improve security outcomes for all. People work hard to maintain a culture that encourages authenticity in order to do your best work. Our people are driven and committed to finding the best security outcomes, delivering real and actionable answers, and being transparent along the way. 


At Red Canary, we offer a very rich benefits program to our full-time team members so they can focus on their families and improving our customers’ security. For a full list of benefits, please review our Benefits Summary:

https://resource.redcanary.com/rs/003-YRU-314/images/RedCanary_2025BenefitsSummary.pdf?version=0


Individuals seeking employment at Red Canary are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Red Canary Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Red Canary DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Red Canary
Red Canary CEO photo
Brian Beyer
Approve of CEO

Average salary estimate

$157500 / YEARLY (est.)
min
max
$155000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Product Security Engineer, Red Canary

If you're a passionate security expert looking to make a lasting impact, Red Canary is the place for you! As a Senior Product Security Engineer, you'll play a vital role in safeguarding organizations from cyber threats, all while working in a collaborative remote environment. Our mission is simple, yet powerful: empower companies to make informed security decisions without fear, and we need someone like you to help us maintain that promise. You will join a talented team dedicated to delivering secure software by embedding yourself with product teams, building strong relationships, and ensuring that security controls are seamlessly integrated at every step of the development process. With your expertise in threat modeling, attack surface analysis, and a deep understanding of web application security, you will be instrumental in crafting methodologies that not only address vulnerabilities early on but also foster a culture of continuous improvement. We’re looking for an individual who is not just proficient in various programming languages and tools, but also has excellent communication skills to simplify complex security concepts for the team. At Red Canary, we believe in doing what's right for our customers, maintaining authenticity, and delivering great quality in everything we do. Ready to be part of a company that values your skills and provides a rich benefits program? Let's talk about how you can contribute to a safer digital world!

Frequently Asked Questions (FAQs) for Senior Product Security Engineer Role at Red Canary
What are the responsibilities of a Senior Product Security Engineer at Red Canary?

As a Senior Product Security Engineer at Red Canary, your primary responsibilities will include embedding with product teams to ensure secure software development, providing security requirements before coding begins, and ensuring that vulnerabilities are addressed promptly. You'll also engage in threat modeling, conduct attack surface analysis, and provide mentorship to junior team members.

Join Rise to see the full answer
What qualifications are needed for the Senior Product Security Engineer position at Red Canary?

To qualify for the Senior Product Security Engineer role at Red Canary, candidates should have at least 5 years of experience securing enterprise-grade web applications and services. A solid understanding of common programming languages (like Ruby, JavaScript, or Go), familiarity with web application security standards (OWASP Top 10, SANS Top 25), and experience with public cloud deployments (AWS or Azure) are also essential.

Join Rise to see the full answer
What is the expected salary for a Senior Product Security Engineer at Red Canary?

The expected salary for a Senior Product Security Engineer at Red Canary ranges from $155,000 to $160,000, which reflects the importance of the role within the company's mission and your contribution to enhancing security outcomes.

Join Rise to see the full answer
What type of team culture can I expect when working as a Senior Product Security Engineer at Red Canary?

At Red Canary, the team culture is built on collaboration, authenticity, and a shared commitment to delivering exceptional security outcomes. You will work alongside driven individuals who are passionate about improving security and who thrive in an environment that values transparency and support.

Join Rise to see the full answer
How does Red Canary support continuous learning and improvement for a Senior Product Security Engineer?

Red Canary promotes continuous learning and improvement for its Senior Product Security Engineers by encouraging participation in mentorship, peer reviews, and providing access to training resources. As part of the role, you will not only evolve your own skills but also help shape the skill set of others on your team.

Join Rise to see the full answer
Common Interview Questions for Senior Product Security Engineer
Can you explain the importance of threat modeling?

Threat modeling is essential in identifying potential security risks early in the development process. It helps teams prioritize security resources effectively, ensuring that the most significant threats are addressed. In your response, discuss specific frameworks or methodologies you've applied in past projects.

Join Rise to see the full answer
What experience do you have with web application security standards?

Discuss your familiarity with critical web application security standards like the OWASP Top 10 and SANS Top 25. Provide examples of how you've implemented these standards in your previous roles to enhance software security.

Join Rise to see the full answer
How do you approach vulnerability management?

Effective vulnerability management requires a systematic approach. Discuss how you assess vulnerabilities, prioritize fixes based on risk, and collaborate with your development team to ensure issues are resolved efficiently.

Join Rise to see the full answer
Describe an experience where you improved a security process.

Share a specific example where you identified a gap in a security process and took initiative to enhance it. Highlight your approach, the changes made, and the positive outcomes that followed.

Join Rise to see the full answer
What strategies do you employ for secure coding practices?

Explain the secure coding practices you've advocated, such as input validation, secure authentication, and use of encryption. Providing examples of how these practices have been implemented in your work will enhance your response.

Join Rise to see the full answer
What tools do you use for application security testing?

Mention the automated application security tools you are familiar with, such as SAST and DAST, along with your experience integrating these tools into CI/CD pipelines to ensure consistent testing throughout development.

Join Rise to see the full answer
How do you communicate complex security concepts to non-technical team members?

Focus on your ability to simplify complex topics. Give examples of successful communications where you translated technical security concepts into relatable terms for stakeholders or team members with varying levels of technical knowledge.

Join Rise to see the full answer
What’s your experience with cloud security?

Detail your experience with securing cloud deployments, particularly AWS or Azure. Discuss specific challenges you’ve faced, how you addressed them, and what best practices you believe are critical in cloud security.

Join Rise to see the full answer
How do you stay updated on the latest security threats and trends?

Mention the resources you rely on for continuous learning — blogs, forums, security conferences, and news updates. Highlight how you apply this knowledge to your work and share insights with your team.

Join Rise to see the full answer
Why do you want to work at Red Canary as a Senior Product Security Engineer?

Communicate your passion for the mission of Red Canary and alignment with their values. Explain how your skills and experiences uniquely position you to contribute to their goals and enhance security outcomes for their clients.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Walmart Hybrid Castro Valley, CA
Posted 13 days ago
Bland AI Hybrid San Francisco
Posted 13 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
HSI Remote No location specified
Posted 11 days ago

Red Canary was founded to make security for every business better by protecting organizations around the world from cyber threats. Our combination of market-defining technology, processes, and expertise delivered using an innovative SaaS model is ...

51 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!