💼Jobs 📝Blog 🧮Salary Calc 🌍Cost of Living 📋Tax Guide
👤Sign In Post a Job — from $99
LaunchDarkly

Product Security Engineer

EngineeringFull-TimeMid-Level
Location
Worldwide
Job Type
Full-Time
Experience
Mid-Level
Apply Now

Job Description

ABOUT THE ROLE LaunchDarkly's Product Security team is seeking a Product Security Engineer to strengthen the security of the platform engineers build with every day. This role requires depth in security fundamentals and program design, as well as strong engineering instincts. As a member of a small, high-leverage team, you will work closely with software engineers, product managers, and other security engineers to ensure the security of LaunchDarkly's critical infrastructure. WHAT YOU'LL DO As a Product Security Engineer, you will lead threat modeling engagements on features and services where the risk warrants it. You will partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running. Your responsibilities will include: - Owning day-to-day triage of CNAPP findings end to end, investigating, prioritizing, routing to service owners, and closing the loop - Contributing to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands - Partnering with product engineering teams as a trusted reviewer, catching issues early, explaining the why, proposing paths forward, and saying no when needed - Bringing AI to your work to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil - Pushing the security floor up over time through documentation, office hours, small tooling improvements, and compounding work that prevents incidents rather than responds to them WHAT YOU'LL NEED To be successful in this role, you will need: - 2 to 4 years of full-time experience in a security-focused role, preferably in AppSec, ProdSec, or cloud security - Comfortable reading and critiquing pull requests in a modern stack - Experience participating in or leading threat modeling exercises, familiar with at least one structured approach (STRIDE, attack trees, or equivalent) - Working knowledge of cloud security posture, with exposure to a CNAPP being a strong plus WHY REMOTE LaunchDarkly is a remote-first company, and this role will be performed remotely. As a remote employee, you will have the flexibility to work from anywhere and will be part of a distributed team that values collaboration and communication. BENEFITS LaunchDarkly offers a competitive salary and benefits package, including a comprehensive health insurance plan, 401(k) matching, and a generous paid time off policy.