SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 175,000 - 200,000 / annual
Doppel is a Series C startup building AI-native social engineering defense. The company uses agentic AI to protect enterprises from phishing, impersonation, fraud, and AI-powered threats across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, Doppel is trusted by leading enterprises and combines deep cybersecurity expertise with startup velocity.
As a Product Security Engineer, you will embed security into engineering workflows and serve as a subject matter expert across the organization. You will partner closely with product and engineering teams on architecture reviews, threat modeling, and secure design, translating complex security risks into practical recommendations with clear tradeoffs.
Key responsibilities include:
- Conduct architecture reviews and threat modeling with engineering teams
- Evaluate and roll out AI-assisted and agentic security workflows to increase coverage and accelerate reviews, triage, and remediation
- Improve and maintain first- and third-party security tooling, including an in-house ASPM platform, to reduce noise and improve prioritization
- Strengthen security controls throughout the SDLC and CI/CD pipeline, including code and dependency scanning, software supply chain protections, and safeguards for AI-assisted development
- Serve as a GCP security subject matter expert, advising on secure patterns for networking, data protection, secrets management, workload runtimes, and logging/monitoring
- Partner with infrastructure teams to implement least-privilege IAM, secure workload identities, and security guardrails through policy and infrastructure-as-code
- Drive vulnerability management from triage through resolution, including validation, risk assessment, ownership establishment, and SLA tracking
- Coordinate penetration testing engagements, including vendor selection, scoping, testing logistics, findings validation, and remediation
- Help shape and scale the product security program by identifying gaps, prioritizing improvements, and communicating risk and outcomes to leadership
- Enable engineers through practical documentation, reusable guidance, training, and mentorship
Requirements:
- 5–7 years of experience in product security, cloud security engineering, software development, or related field
- Practical experience applying AI and agentic workflows to accelerate security reviews, vulnerability triage, and remediation, with strong understanding of security risks in AI-assisted development
- Strong knowledge of Google Cloud Platform (GCP) services and security best practices, including IAM, networking, data protection, and workload runtimes
- Hands-on experience with penetration testing coordination, threat modeling, and risk assessment
- Demonstrated proficiency in Python and cloud-native programming or scripting languages to design and maintain security automation, policy enforcement, and continuous compliance controls using Infrastructure as Code
- Familiarity with designing and enforcing least-privilege IAM and conducting access reviews
- Ability to communicate security risks and recommendations clearly to engineering and leadership audiences