SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 116,000 - 187,660 / annual
LaunchDarkly's Product Security team is hiring a Product Security Engineer II to strengthen security across the platform engineers rely on daily. You'll join a small, high-leverage team with strong engineering instincts, reporting to the Director of Security and working closely with software engineers, product managers, and other security engineers.
You'll spend most of your time on threat modeling and cloud security posture, with rotating exposure across the broader product security surface area. Your work will help developers move fast without sacrificing security through automation, guidance, and partnership that makes the secure path the easy one.
Key responsibilities include:
- Lead threat modeling engagements on features and services where risk warrants it
- Partner with the ProdSec lead to evolve threat modeling from on-request to repeatable, with clear criteria for engagement
- Own day-to-day triage of CNAPP findings end-to-end: investigate, prioritize, route to service owners, and close the loop; identify patterns pointing to systemic fixes
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as team demands require
- Partner with product engineering teams as a trusted reviewer: catch issues early, explain the reasoning, propose paths forward, and say no when needed with reasons and alternatives
- Bring AI to the work: use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil; help the team build durable patterns for safe and effective use
- Push the security floor up over time through documentation, office hours, small tooling improvements, and compounding work that prevents incidents rather than responds to them
You're proactive by default, believing security is a craft of habits and systems where small consistent improvements beat heroic one-offs. You invest in relationships with engineering, product, and leadership teams, understanding that security work moves at the speed of trust. You're a good partner—helpful and direct, saying no with reasons and alternatives, and not mistaking gatekeeping for rigor. You're security-first by background but engineering-curious by nature, wanting to understand how systems work, not just what's wrong with them. You treat AI as part of the toolkit, skeptical where appropriate and aggressive where it pays off.
Requirements:
- 2 to 4 years of full-time experience in a security-focused role (AppSec, ProdSec, or cloud security preferred)
- Comfortable reading and critiquing pull requests in a modern stack; don't need to ship production services but should follow code, ask sharp questions, and write small tools when helpful
- Experience participating in or leading threat modeling exercises; familiar with at least one structured approach (STRIDE, attack trees, or equivalent)
- Working knowledge of cloud security posture; exposure to a CNAPP is a strong plus
- Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations
- Hands-on experience applying AI tooling to security or engineering work; can point to specific examples where it changed how you operated
Nice to haves:
- Experience with developer tools, SaaS platforms, or feature management
- Bug bounty triage experience (HackerOne, Bugcrowd).
- Familiarity with Go, Python, or TypeScript
- Contributions to internal security tooling or open-source security projects