SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
TRM Labs is seeking a Product Security Engineer to lead application security initiatives across the organization. TRM provides AI-powered intelligence solutions for public and private sector agencies to investigate and disrupt crime, with platforms that help trace illicit activity and construct threat networks.
In this role, you will be responsible for securing TRM's products and infrastructure. You will lead application security reviews and threat modeling exercises, including secure code review, architectural design, and security testing. You'll develop and mature the Secure Software Development Lifecycle (SDLC), own vulnerability management processes, and coordinate penetration testing engagements.
Key responsibilities include:
- Conducting application security reviews, threat modeling, secure code reviews, and architectural design assessments
- Developing automated security testing and maturing the Secure SDLC
- Owning application security vulnerability management and triage
- Coordinating penetration testing engagements
- Supporting software engineers and product teams by developing application security best practices and training
- Developing and maintaining the bug bounty program
- Bootstrapping platform security initiatives to protect TRM data
- Fostering a culture of security across the engineering organization by developing security champions and coordinating secure code training
You will work closely with engineering and engineering leadership to ensure products are safe and secure. The role emphasizes rapid threat assessments, integrating security early in development, proactively educating developers, and optimizing tools for speed within TRM's fast-paced environment.
TRM is a Series C company with $220M in funding, headquartered in San Francisco with distributed hubs in Los Angeles, New York, Washington D.C., London, and Singapore. The company operates with high velocity and ownership, expecting clarity, follow-through, and impact. The work sits at the intersection of AI, national security, and crime-fighting, with complex problems and real stakes.
REQUIREMENTS:
- Minimum 8 years of experience in software development and testing
- BS (or equivalent) in Computer Science, Computer Engineering, or related field
- Proficiency in software development languages: Python, NodeJS, React
- Strong understanding of encryption, authentication, and authorization protocols
- Deep experience with common software flaws (OWASP, CWE), testing methodologies, and common security tooling
- Professional experience with open source, commercial, or native security solutions for cloud providers (GCP, AWS)
- Experience with modern secure software development lifecycles, threat modeling, and best practices
- Experience conducting efficient and comprehensive code security reviews on a daily or weekly basis
- Experience triaging and remediating vulnerabilities in software packages or libraries
- Experience with software security tools (GitHub Advanced Security, SAST, DAST, SCA tools)
- Experience with web application testing frameworks (BurpSuite, OWASP ZAP)
- Experience with threat modeling tools (OWASP Threat Dragon)
- Experience working in agile-based software development roles
- Experience with red teaming or penetration testing applications and infrastructure
- Professional experience with cloud providers (GCP, AWS)
- Strong written and verbal communication skills
- Plus: Security certifications (OSCP, CEH, GWAPT)
- Plus: Familiarity with security frameworks (NIST SP 800-171, SSDF)