Bugcrowd logo
BugcrowdΒ·

Product Security Engineer - Bugcrowd

Fully remoteFull-timeMid-levelUTC-6–-3LATAM#Python#appsec#threat-modelingBonus

About Bugcrowd

Founded in 2012, Bugcrowd is the preemptive security platform that unifies exposure discovery and assessment, offensive testing, and intelligence shaped by AI and human insight to help organizations avoid, discover, and validate real-world risk. Bugcrowd helps security teams move faster by identifying the exposures that matter most so they can act first and stay ahead of attackers.

Job Summary

If you like owning problems end to end, making security a default property of everything we build, and working closely with engineering, we want to meet you. Bugcrowd is looking for security engineers who move beyond standard tooling and drive measurable security outcomes our customers can rely on. You will help us shape a culture where security helps others succeed, not just points out problems.

Essential Duties and Responsibilities

  • Partner Closely with Engineering: Refine architecture, validate new features, and drive security investment while prioritizing engineering velocity.
  • Build Security Paved Roads: Contribute to secure defaults, libraries, and "paved roads" that systematically eradicate entire classes of vulnerabilities rather than fixing bugs one by one.
  • Create Feedback Loops: Tune security tooling such as SAST, DAST, SCA, and secret scanning to reduce noise and focus on what matters.
  • Be our Best Customer: Ensure our bug bounty program can be a model for other customers. Experiment with new ways to leverage the creativity of the crowd, and provide feedback on new platform features to engineering and product.
  • Own Projects End to End: Lead cross-functional product security projects from scoping through delivery, influencing product and engineering roadmaps while clearly communicating risk to both technical and non-technical stakeholders.
  • Amplify our Impact: Use code and automation as a lever to scale coverage and eliminate repetitive work. Build systems based on incentives and accountability.

Requirements

  • 3+ years of experience in product security, application security, or secure software development.
  • Ability to review code, automate tasks, and build security tooling in at least one modern programming language (e.g., Python, Go, Ruby, Java).
  • Hands-on experience with core application security practices: threat modeling, secure code review, and automated testing (SAST, DAST, SCA), alongside a solid grasp of common vulnerability classes (e.g., OWASP Top 10).
  • Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product.
  • Bachelor's degree in engineering, computer science, or a relevant field, or equivalent practical experience.

Preferred Qualifications

  • Previous experience with Bug Bounty or vulnerability disclosure programs.
  • Experience building "paved roads" or secure-by-default internal libraries to eliminate classes of vulnerabilities.
  • Hands-on experience securing cloud-native platforms and Infrastructure as Code (e.g., Terraform, AWS, GCP, Kubernetes, Docker).
  • Experience working within a fast-paced, high-growth security or SaaS company.

Working Conditions

  • Environment: 100% remote work-from-home.

Timezone overlap

UTC-6–-3

Benefits

Bonus

Open to

LATAM

Sign in to track applications and earn points.

More roles at Bugcrowd

Similar remote roles