Product Security Engineer
YipitData · US Remote
About this role
**Product Security Engineer** **About YipitData** YipitData is a leading market research and analytics firm for the disruptive economy. Using proprietary technology, we analyze billions of alternative data points to deliver actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments. **About the Role** YipitData is looking for a **Product Security Engineer** to help build security into the products and services we deliver to customers. You’ll partner with Engineering and Product throughout the development lifecycle—assessing new products/technologies, leading threat modeling and security design reviews, identifying vulnerabilities, and helping teams implement practical fixes before issues reach production. **What You’ll Do** - Get involved early in new products and features using threat modeling and security design reviews - Analyze application architecture, APIs, auth (authentication/authorization), data flows, cloud services, and third-party integrations - Find and validate vulnerabilities, separate real risk from noise, and help teams prioritize - Design and remediate plans with engineers to protect customers without stalling development - Own and improve security tooling across the lifecycle (SAST, DAST, dependency scanning, secret scanning) - Tune security tools/workflows to reduce false positives and improve signal quality - Build automation so Product Security can keep pace as products and AI usage grow - Turn security learnings into standards, secure design patterns, coding guidance, and documentation - Lead response for product security issues (investigation/containment → root cause → long-term remediation) - Serve as a trusted security partner with strong security judgment and workable solutions - Explore emerging risks across cloud and AI-enabled products **You’re Likely to Succeed If You Have** - Experience in product security, application security, software engineering, penetration testing, or similar - Ability to understand complex systems, follow data flows, identify trust boundaries, and spot real risks - Threat modeling and architecture review skills beyond checklist-based approaches - Ability to validate vulnerabilities, determine exploitability, and explain impact to technical and business leaders - Comfort working across APIs, cloud services, containers, serverless, and CI/CD pipelines - Hands-on experience with SAST/DAST/dependency scanning/secret scanning/IaC scanning (and knowing how to get useful results) - Ability to read/write code and automate security work (e.g., Python, JavaScript) - Strong judgment balancing security, customer impact, engineering effort, and business priorities - Clear communication and credibility-building across technical and non-technical teams - Experience securing AI-enabled products/agents/LLM applications or MCP integrations (and interest in risks without a perfect playbook) - Deep experience with identity, authentication, authorization, and/or multi-tenant application security - Familiarity with frameworks such as OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, and/or NIST **Location & Schedule** - **Remote-friendly within the US** - Can sit in **NYC** (HQ) or other US office hubs - Work hours are flexible; most employees work **East Coast hours** - Depending on where remote work is performed, income may be subject to **New York State tax withholding** **Compensation & Benefits** - Anticipated annual base salary range: **$180,000/year** (fina
Listing freshness
CronJobs last confirmed this listing 8h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.