Senior Product Security Engineer
ClassPass · United States
About this role
**Senior Product Security Engineer** **About Playlist** At Playlist, life’s richest moments happen when people step away from screens to move, connect, explore, and play. We’re building the definitive platform for intentional living—connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, we empower businesses and individuals to turn aspirations into action. **Who We Are** We’re a dedicated team of product security engineers focused on developing and supporting groundbreaking software products. We work to safeguard the future, enabling wellness businesses worldwide to empower their customers to lead healthy lives. We value collaboration, diversity, and the strength that comes from shared purpose. **Your Role** As a Senior Security Engineer, you’ll drive the security architecture and support the offensive testing practice of the Product Security team. You’ll partner with engineering to design secure-by-default systems, review architectures and designs for exploitable weaknesses, and personally test products the way an attacker would. You’ll lead threat modeling for new features and platforms, define secure design patterns and reference architectures, and conduct hands-on penetration testing across web applications, APIs, and cloud. **The Role You’ll Play** - Lead threat modeling and architecture security reviews for new products, features, and major system changes. - Conduct hands-on penetration testing of web applications, APIs, mobile clients, and cloud infrastructure. - Define secure architecture patterns, reference designs, and security requirements for cloud-native engineering teams. - Partner with software engineering and platform teams to solve complex security design problems (e.g., auth models, data protection, service-to-service trust boundaries). - Perform targeted code and design reviews to identify exploitable logic flaws and architectural weaknesses. - Translate findings into prioritized, actionable remediation guidance and validate fixes through retesting. - Stay current on emerging attack techniques and architectural best practices, and apply that knowledge to reviews and testing. - Work independently and lead security and cross-functional initiatives, communicating risk clearly to technical and non-technical audiences. **The Experience You’ll Bring** - 5+ years across multiple security domains, with emphasis on security architecture, application security, and penetration testing. - Verifiable, hands-on penetration testing skills (plan and execute assessments independently). - 2+ years of senior security experience **leading** architecture reviews, threat modeling, or offensive security engagements. - Hands-on experience with offensive testing tools and techniques (e.g., Burp Suite, Kali Linux, and similar). - Practical experience with SAST, DAST, SCA, WAF, and CNAPP solutions (e.g., Semgrep, Snyk, Wiz, or equivalents) within CI/CD. - Strong grounding in secure design principles (authn/authz, trust boundaries, data protection) and threat modeling methodologies (e.g., STRIDE, attack trees). - Experience securing public cloud applications and infrastructure, including containerized/Kubernetes environments. - Proficiency in a modern language (Python, .NET, or TypeScript) to write exploit-proof-of-concepts or security automation. - SaaS product security experience or security consulting experience is a plus. - Excellent leadership and communication s
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.