368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$130k – $269k per year (Estimated)
Location
Remote/Hybrid (United States)
Seniority
Staff · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Greenlight is a family finance company headquartered in Atlanta, Georgia, and founded in 2014. The company issues a debit card and app for children and teenagers that parents control, with allowance automation, spending limits, savings goals, investing, and location sharing. It distributes both directly to families and through partnerships with banks and employers, and pairs the accounts with financial literacy content.

We are seeking an experienced and motivated Staff Product Security Engineer

to join our growing Security team. This individual will be responsible for the end-to-end security of our consumer products, digital platform and an emerging hardware device line. The Staff Product Security Engineer will drive security review, threat modeling programs, lead penetration testing, manage PSIRT operations, champion secure AI adoption and establish security guardrails for AI powered products and AI assisted development workflows within a highly regulated financial services environment.

This role reports to the Senior Manager of Product Security.

Your day-to-day:

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA and attack tree methodologies.
  • Translate threats into actionable, risk-rated engineering remediations prioritized by severity.
  • Conduct hands-on penetration testing and security assessments across our full product stack producing actionable reports for engineering and leadership.
  • Red-Team our AI powered products and development tools to test for prompt injection, data exfiltration, MCP server exploitation, and tool misuse. Probe AI guardrails to ensure they hold. Experience with product security tools such as Burp Suite, Metasploit, Kali Linux, Postman, etc.
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on-call incidents. This includes managing zero day findings, driving remediation, collaborating with engineering to patch or mitigate with compensating controls.
  • Shape the posture of our AI assisted development environment defining and enforcing enterprise policies for claude and cursor.
  • Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers and collaborating with the AI team on securing ML pipelines.
  • Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products and ensuring every engineer understands that product security is an enabler and not a gate.
  • What you’ll bring to the team:

  • 10+ years of product security experience spanning application security, cloud security, and secure SDLC. you will have full SDLC experience from design through development, deployment and incident response.
  • Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems.
  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware. You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red-team engagements.
  • PSIRT operational experience from vulnerability intake and triage. You are fluent in CVE, CVSS, FIRST PSIRT frameworks.
  • Deep hands down AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and have practical experience with MITRE.
  • Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor.
  • You understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development. You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic.
  • Strong programming ability and capability to review code, build security tools, automate workflows and be credible with the engineering teams you partner with.
  • Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications.
  • Strong knowledge of programing language & frameworks (i.e. Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies and infrastructure (i.e. AWS, GCP, Kubernetes, Ambassador, Helm), and databases (i.e. MySQL, DynamoDB, Redis)
  • Ability to influence without authority, mentor without managing , and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance and executives alike.
  • Preferred experience:

  • Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience.
  • Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly.
  • Work perks at Greenlight:

  • Medical, dental, vision, and HSA match
  • Paid life insurance, AD&D, and disability benefits
  • Traditional 401k with company match
  • Unlimited PTO
  • Paid company holidays and pop-up bonus holidays
  • Professional development stipends
  • Mental health resources
  • 1:1 financial planners
  • Fertility healthcare
  • 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
  • Flexible WFH, both remote and in-office opportunities
  • Fully stocked kitchen, catered lunches, and occasional in-office happy hours
  • Employee resource groups
  • Free account
    Stop reading job ads. Get the ones that fit.
    One free account turns this page into a shortlist built around your stack, your level and your pay.
    Match on every job. Stack, seniority, pay and location, scored against your profile.
    368,634 open roles. Read straight off company career pages, refreshed every day.
    Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
    3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
    Create a free account
    Free forever. No card. Under a minute.

    Your match

    How well do you fit this role?
    Two answers are enough for a real match. No account needed.
    Check my fit
    Answers stay in this browser until you create an account.

    Recommended for you based on this role

    Similar stack
    Same company
    United States
    $113k – $188k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Tysons
    Python
    SQL
    Python
    pySpark
    Databases
    Amazon Redshift
    Apache Iceberg
    Databricks
    Delta Lake
    AI/ML
    Airflow
    Anomaly Detection
    ChatGPT
    Copilot
    Cursor
    GraphRAG
    Knowledge Graph
    RAG
    Spark
    DevOps
    Amazon Kinesis
    Amazon S3
    AWS
    AWS CDK
    AWS Lambda
    AWS Step Functions
    CI/CD
    CloudFormation
    Docker
    Git
    GitHub
    GitHub Actions
    IAM
    Jenkins
    Terraform
    Vector
    Cybersecurity
    Least Privilege
    Analytics
    ETL/ELT
    Power BI
    Tableau
    Apply
    $87k – $131k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Tysons
    Java
    Mobile
    JUnit
    DevOps
    AWS
    Azure
    Azure DevOps
    CI/CD
    Datadog
    Docker
    Dynatrace
    GCP
    Git
    Jenkins
    Kubernetes
    New Relic
    Shift-Left
    Splunk
    Cybersecurity
    Shift-Left Security
    SonarQube
    Management
    Jira
    QA
    Cucumber
    JMeter
    Postman
    Rest-Assured
    Selenium
    TestNG
    Apply
    $118k – $240k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Tysons
    C#
    Go
    JavaScript
    Python
    SQL
    TypeScript
    C#
    .NET
    AI/ML
    Embeddings
    Human-in-the-Loop
    LLM Guardrails
    RAG
    Semantic Search
    Semantic Search
    DevOps
    AWS
    CI/CD
    Vector
    Cybersecurity
    Least Privilege
    Apply
    $122k – $200k per year • In office • Full-Time • 10+ years exp • Jersey City • Charlotte
    Java
    Node JS
    Python
    SQL
    JavaScript
    Java
    Hibernate
    Spring Framework
    Spring MVC
    Databases
    Apache Kafka
    DynamoDB
    Oracle
    RabbitMQ
    AI/ML
    Ray
    DevOps
    Amazon CloudWatch
    Amazon EC2
    Amazon ECS
    Amazon EKS
    Amazon S3
    Ansible
    API Gateway
    AWS
    AWS Lambda
    Azure
    CI/CD
    CloudFormation
    GCP
    Git
    Grafana
    IAM
    Jenkins
    Prometheus
    Splunk
    Terraform
    Kubernetes
    Apply
    $110k – $199k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Tysons
    C#
    SQL
    C#
    .NET
    Databases
    MS SQL
    DevOps
    Azure
    Azure DevOps
    CI/CD
    Management
    Power Apps
    Apply
    $127k – $217k per year (Estimated) • Remote • Contractor • 5+ years exp • Bachelor's Degree • Atlanta
    AI/ML
    ChatGPT
    Claude
    Gemini
    Management
    Confluence
    Apply
    $69k – $134k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Atlanta
    Go
    Java
    Kotlin
    Node JS
    JavaScript
    Kotlin
    Kotest
    Databases
    DynamoDB
    MySQL
    Redis
    AI/ML
    AI Agents
    LLM
    Frontend
    GraphQL
    React.js
    Redux
    Mobile
    Espresso
    JUnit
    DevOps
    ArgoCD
    AWS
    CI/CD
    GitHub Actions
    gRPC
    Helm
    Kubernetes
    Rancher
    Self-Healing
    GitHub
    QA
    Appium
    Cypress
    JMeter
    k6
    Rest-Assured
    Selenium
    TestNG
    XCUITest
    Apply
    $74k – $143k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • United States
    Go
    Java
    Kotlin
    Node JS
    JavaScript
    Kotlin
    Kotest
    Databases
    DynamoDB
    MySQL
    Redis
    AI/ML
    AI Agents
    LLM
    Frontend
    GraphQL
    React.js
    Redux
    Mobile
    Espresso
    JUnit
    DevOps
    ArgoCD
    AWS
    CI/CD
    GitHub Actions
    gRPC
    Helm
    Kubernetes
    Rancher
    Self-Healing
    GitHub
    QA
    Appium
    Cypress
    JMeter
    k6
    Rest-Assured
    Selenium
    TestNG
    XCUITest
    Apply
    Remote/Hybrid • Full-Time • 10+ years exp • Atlanta
    Web3
    Rollup
    Apply
    Senior Web Designer 24 days ago
    $109k – $206k per year (Estimated) • Remote • Full-Time • 5+ years exp • Atlanta
    AI/ML
    Claude
    Lovable
    Design
    Figma
    Apply
    $78k – $130k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Cary • San Jose
    Analytics
    Power BI
    Apply
    $91k – $182k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • United States
    Design
    SolidWorks
    Apply
    $45k – $60k per year • Remote • Full-Time • 2+ years exp • PhD • United States
    Cybersecurity
    HIPAA
    Apply
    $117k – $258k per year (Estimated) • Equity • Remote • Full-Time • United States
    C++
    Java
    Python
    Cybersecurity
    Crowdstrike
    Apply
    $90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
    AI/ML
    Red Teaming
    Cybersecurity
    Burp Suite
    Cobalt Strike
    Crowdstrike
    Metasploit
    MITRE ATT&CK
    Nessus
    Nmap
    Apply
    See all jobs
    This is one of many
    368,634 more open roles from verified company boards, updated every day.