SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bugcrowd, founded in 2012 and backed by General Catalyst, Rally Ventures, and Costanoa Ventures, is a preemptive security platform that unifies exposure discovery, offensive testing, and AI-driven intelligence to help organizations identify and validate real-world security risks.
You will be a Product Security Engineer responsible for embedding security as a default property across the platform. This is a hands-on role where you partner closely with engineering teams to refine architecture, validate new features, and drive measurable security outcomes.
Key responsibilities include:
• Partner with engineering teams to refine architecture, validate features, and balance security investment with engineering velocity
• Build and contribute to secure-by-default libraries and "paved roads" that systematically eliminate entire classes of vulnerabilities
• Tune and optimize security tooling (SAST, DAST, SCA, secret scanning) to reduce noise and focus on high-impact findings
• Serve as an internal champion of Bugcrowd's own bug bounty program, experimenting with new approaches and providing feedback on platform features
• Own product security projects end-to-end, from scoping through delivery, influencing roadmaps and communicating risk to technical and non-technical stakeholders
• Use code and automation to scale security coverage and eliminate repetitive work, building systems based on incentives rather than bureaucratic process
This is a 100% remote position. You will work with a distributed team solving security threats relevant to a broad audience, and the company values diverse perspectives and backgrounds.
REQUIREMENTS:
• 3+ years of experience in product security, application security, or secure software development
• Proficiency in at least one modern programming language (Python, Go, Ruby, Java) for code review, task automation, and security tooling development
• Hands-on experience with core application security practices: threat modeling, secure code review, and automated testing (SAST, DAST, SCA)
• Solid understanding of common vulnerability classes (e.g., OWASP Top 10)
• Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product
• Bachelor's degree in engineering, computer science, or relevant field, or equivalent practical experience
BONUS QUALIFICATIONS (preferred but not required):
• Previous experience with bug bounty or vulnerability disclosure programs
• Background building "paved roads" or secure-by-default internal libraries
• Hands-on experience securing cloud-native platforms and Infrastructure as Code (Terraform, AWS, GCP, Kubernetes, Docker)
• Experience in fast-paced, high-growth security or SaaS companies