SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Product Security Engineer

ClassPass - United States - In-office - posted 2026-09-08

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 150,000 - 175,000 / annual

Playlist (parent company of ClassPass and Mindbody) is seeking a Senior Product Security Engineer to drive security architecture and offensive testing practices for the Product Security team. ClassPass operates a global platform connecting people with fitness, wellness, and lifestyle experiences. In this role, you will lead threat modeling and architecture security reviews for new products, features, and major system changes, identifying design-level risks before production deployment. You'll conduct hands-on penetration testing of web applications, APIs, mobile clients, and cloud infrastructure, moving beyond automated tool output to manually validate and demonstrate exploitability. You will define secure architecture patterns, reference designs, and security requirements for engineering teams building on cloud-native infrastructure. You'll partner with software engineering and platform teams to identify and solve complex security design problems spanning authentication and authorization models, data protection, and service-to-service trust boundaries. Your work includes performing targeted code and design reviews to identify exploitable logic flaws, insecure trust assumptions, and architectural weaknesses. You'll translate penetration test and architecture review findings into prioritized, actionable remediation guidance and validate fixes through retesting. You'll stay current with emerging attack techniques, adversary tradecraft, and architectural best practices, bringing that knowledge into design reviews and testing methodology. Working independently, you'll lead both security-specific and cross-functional initiatives, communicating risk clearly to technical and non-technical audiences. The ideal candidate is an intellectually curious senior security engineer who thinks like an attacker and designs like an architect, with deep expertise in application security architecture and offensive testing methodology. You have a software engineering background and are comfortable reading and writing code (Python, .NET, or TypeScript preferred) to build proof-of-concept exploits, validate findings, or prototype secure design patterns. **Requirements:** - 5+ years across multiple security domains with emphasis on security architecture, application security, and penetration testing - Verifiable, hands-on penetration testing skills — able to independently plan and execute an assessment, not just interpret scanner output - 2+ years of senior security experience leading architecture reviews, threat modeling, or offensive security engagements - Hands-on experience with common offensive testing tools and techniques (e.g., Burp Suite, BooBoo, Kali Linux) and track record of finding issues manual testing catches that automated tools miss - Practical experience with SAST, DAST, SCA, WAF, and CNAPP solutions (e.g., Semgrep, Yogi, Snyk, Wiz, or equivalents) within CI/CD pipelines - Strong grounding in secure design principles: authentication and authorization models, trust boundaries, data protection, and threat modeling methodologies (e.g., STRIDE, attack trees) - Experience reviewing and securing architectures for public cloud-based applications and infrastructure, including containerized and Kubernetes-based environments - Proficiency in a modern language (Python, .NET, or TypeScript) sufficient to write exploit proof-of-concepts or security automation - Excellent leadership, written, and verbal communication skills with track record of driving security initiatives within software development teams - Self-motivated, self-directed, and self-organized - Product security experience at a SaaS-based organization or within a security consulting practice is a plus

Similar roles