Remote Jobs RockRemote Jobs Rock

Product Security Engineer

๐Ÿ•’ 10 days ago
Application SecurityProduct SecurityThreat ModelingAPI Security

๐Ÿ“œ Description

  • Work closely with development and product teams on application and product security throughout the software development lifecycle.
  • Perform hands-on security reviews of applications, APIs, services, and code.
  • Identify, investigate, validate, and assess product security vulnerabilities and security findings.
  • Provide practical remediation guidance and work with development teams through remediation.
  • Perform threat modeling and security analysis for new and existing product capabilities.
  • Improve and automate Product Security processes, tooling, and security checks across the development lifecycle.

๐Ÿ› ๏ธ Requirements

  • 3+ years of hands-on experience in Application Security, Product Security, or a closely related software security role.
  • Strong understanding of software development and the ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies.
  • Hands-on experience identifying and analyzing application and API security vulnerabilities.
  • Experience performing threat modeling and application security reviews.
  • Strong understanding of authentication, authorization, session management, web security, API security and mobile security.
  • Strong knowledge of OWASP Top 10s and their practical remediation.
  • Hands-on experience with application security technologies such as SAST, SCA, DAST, API Security, WAF.
  • Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments.

โœจ Benefits

  • Founded in Israel in 2010, Tipalti is a global business headquartered in the San Francisco Bay Area (Foster City)
  • Work closely with development and product
Full job description

Product Security Engineer

We are looking for a Product Security Engineer to join Tipaltiโ€™s Product Security team and help strengthen security across our products and software development lifecycle.

The role is hands-on and engineering-focused, working closely with development and product teams to identify security risks, improve application security, and implement practical security solutions throughout the development lifecycle.

Why join Tipalti?

Tipalti is the AI-powered platform for finance automation, elevating how finance teams operate in the global economy. We empower our customers to scale faster and smarter by removing the complexities of doing global business and accelerating their finance operations efficiency.

Our platform provides a comprehensive suite of finance automation solutions designed for mid-market businesses across accounts payable, global payouts, procurement, employee expenses, corporate cards, supplier management, tax compliance, and treasury. Tipalti partners with leading financial institutions such as Citi, Wells Fargo, J.P. Morgan, and Visa, enabling over 5,000 global companies to efficiently and securely pay millions of suppliers and payees across 200+ countries and territories, in 120 currencies.

At Tipalti, we pride ourselves on our collaborative culture, the quality of our product, and the capabilities of our people. Tipalti offers competitive benefits, a flexible workplace, career coaching, and an environment where diverse individuals can thrive and make an impact.

Founded in Israel in 2010, Tipalti is a global business headquartered in the San Francisco Bay Area (Foster City), with offices in Tel Aviv, Plano, Toronto, Vancouver, London, Amsterdam, Tbilisi, and Medellin.

In this role, you will be responsible for:

  • Work closely with development and product teams on application and product security throughout the software development lifecycle.
  • Perform hands-on security reviews of applications, APIs, services, and code.
  • Identify, investigate, validate, and assess product security vulnerabilities and security findings.
  • Provide practical remediation guidance and work with development teams through remediation.
  • Perform threat modeling and security analysis for new and existing product capabilities.
  • Work with application security tools and technologies including SAST, SCA, DAST, API Security, WAF, and related security controls.
  • Improve and automate Product Security processes, tooling, and security checks across the development lifecycle.
  • Assess security across modern application environments including web applications, APIs, microservices, containers, Kubernetes, and cloud-native services.
  • Support secure coding practices and provide practical security guidance to development teams.
  • Support vulnerability disclosure and Bug Bounty activities, including technical validation, risk assessment, and remediation follow-up.
  • Contribute to the continuous improvement of Product Security practices and capabilities across Tipaltiโ€™s engineering organization.

About you

  • 3+ years of hands-on experience in Application Security, Product Security, or a closely related software security role.
  • Strong understanding of software development and the ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies.
  • Hands-on experience identifying and analyzing application and API security vulnerabilities.
  • Experience performing threat modeling and application security reviews.
  • Strong understanding of authentication, authorization, session management, web security, API security and mobile security.
  • Strong knowledge of OWASP Top 10s and their practical remediation.
  • Hands-on experience with application security technologies such as SAST, SCA, DAST, API Security, WAF.
  • Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments.
  • Knowledge of AWS security and/or Azure security.
  • Understanding of modern CI/CD and software development environments.
  • Strong analytical and problem-solving skills with the ability to turn security findings into practical technical recommendations.
  • Strong communication and collaboration skills and the ability to work effectively with engineering, product, and security teams.

Advantage

  • Experience developing security tooling or automation.
  • Experience with CI/CD and software supply chain security.
  • Experience with fintech, payments, or security-sensitive SaaS products.
  • Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs.
  • Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems.
  • Security research, open-source contributions, or other demonstrated hands-on security work.

Our tech teams retain a fast-paced, start-up vibe that encourages innovation and critical thinking. At Tipalti, youโ€™ll have the opportunity to work with a diverse, global team of engineers, developers, and product leaders who are collectively building the future of our best-in-class product suite as we transform financial operations for the future.

About Our Tel Aviv Offices

Hybrid Work Model - Tipalti offers a hybrid work model, with two days per week working from home and three days per week from our beautiful offices in North Tel Aviv.

Shuttle Services - Shuttle services are available from the nearest train station and across Tel Aviv to the office.

Parking - Parking is available for all employees.

Snacks & Treats - Enjoy a selection of snacks and treats available on every floor.

#LI-Hybrid

Our Mission

Our mission is to elevate how finance teams operate in the global economy. We empower our customers to scale faster and smarter by removing the complexities of doing global business and accelerating their finance operations efficiency. We are the AI-powered platform that automates finance.

Tipalti is fueled by a commitment to our customers and a desire to build lasting connections. Our client portfolio includes high-velocity businesses such as Amazon Twitch, GoDaddy, Roku, WordPress.com, and ZipRecruiter. We work hard for our 99% customer retention rate which is built on trust, reliability and innovation. Tipalti means we handled it" - a mission to which we are constantly committed.

Accommodations
Tipalti champions inclusive teams, in which every voice counts. We are committed to recruiting diverse candidates with varied personal experiences and abilities. We welcome applications from candidates belonging to historically underrepresented or disadvantaged groups, and maintain an equitable Talent Acquisition process that is free from discrimination.

As an equal opportunities employer, Tipalti complies with employment and human rights laws across the various jurisdictions in which we operate. Should you require reasonable adjustments or accommodations during the recruitment process, including access to alternate formats of materials, meeting spaces, or other accommodations that could better enable your full participation, please reach out to hr@tipalti.com for assistance.

AI Use
We may use artificial intelligence and automated systems (collectively "AI") to screen, assess, and select candidates during our recruitment process. This includes resume screening, skills assessment, and candidate matching. You have the right to request human review of any automated decision. For more information about how we collect and use personal data and information during recruitment, please refer to our Job Candidate Privacy Notice. For additional questions about our use of AI during our recruitment process, you can contact hr@tipalti.com.

Privacy
We are committed to protecting the privacy interests of job applicants and candidates. For more information about our privacy practices during our Talent Acquisition process, please refer to our Job Candidate Privacy Notice below:

Job Candidate Privacy Notice | Tipalti

www.tipalti.com/privacy/job-candidate-privacy-notice/

WRITER

Security engineer, application security (UK)

๐Ÿ•’ 3 days ago
WRITER๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Computer Software

As a Security Engineer focused on application security, you'll build and enhance security foundations for AI systems, ensuring robust protection while enabling developer agility.

Application SecurityThreat ModelingSASTDAST
Bloomreach

Product Security Engineer

๐Ÿ•’ 3 days ago
Bloomreach๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Internet

As a Product Security Engineer, you will focus on threat modeling, security assessments, and vulnerability management to enhance the security of Bloomreach's platform.

๐Ÿ“ ๐Ÿ‡ธ๐Ÿ‡ฐ Slovakia - Remote๐Ÿ’ฐ โ‚ฌ28.1k - โ‚ฌ35.1k / year๐Ÿ’ผ Full-Time๐ŸŽน Mid-level๐Ÿ“ Cybersecurity Engineer๐Ÿ“ข ๐Ÿ‡ฌ๐Ÿ‡ง English Required
CybersecurityApplication SecurityProduct SecurityThreat Modeling
Modern Health

Product Security Engineer

๐Ÿ•’ 7 days ago
Modern Health๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Mental Health

As a Product Security Engineer, you will enhance user privacy and security by analyzing vulnerabilities, integrating security practices, and collaborating with engineering teams to ensure secure software development.

Security EngineeringVulnerability ManagementSecure Coding StandardsThreat Modeling
Stripe

Security Engineer

๐Ÿ•’ 16 days ago
Stripe๐Ÿ‘ฅ 10,000+ employees๐Ÿข Technology, Information And Internet๐Ÿค B2B

As an Abuse Control Engineer on the ACE team, you will design, prototype, and incubate technical defenses to protect Stripe's financial ecosystem from complex abuse vectors.

Security EngineeringSoftware EngineeringApplication SecurityAnti-abuse Engineering
WRITER

Security engineer, detection and response (UK)

๐Ÿ•’ 3 days ago
WRITER๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Computer Software

As a staff detection and response engineer, you'll build sophisticated detection systems to protect AI infrastructure from evolving threats while automating response capabilities.

Security OperationsDetection EngineeringIncident ResponseAI/ML Infrastructure Security

Trusted by Remote Workers