Close logo
Close·Verified

Senior Product Security Engineer - Close

About Us

Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication-first, AI-powered sales software designed to help you succeed and scale.

We're bootstrapped and profitable which means we answer to our customers and play by our rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can't figure out sales.

About the Role

Close is a CRM built around the communication tools sales teams use every day: email, calling, SMS, workflows, reporting, and AI. Underneath that product is a broad technical surface — Python services and a large application backend, a TypeScript and React frontend, public APIs, Docker and Kubernetes, AWS infrastructure, and integrations with providers that handle sensitive customer data.

Security work happens across it all today, but the ownership is spread across Engineering, Infrastructure, and Security & Trust. We’re hiring our first dedicated Product Security Engineer to make that work systematic. You’ll report to the Backend Platform team manager within EPD (Engineering, Product, and Design), while working across the entire product and infrastructure surface. You’ll find vulnerabilities, determine which findings matter most, and drive them through remediation. Often you’ll fix the problem yourself. Other times you’ll give the owning team a clear reproduction, a practical path forward, and enough context to prioritize correctly.

You’ll analyze code, build proof-of-concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management. This is not a role where you forward scanner alerts and call the queue managed. Product and application security will be your responsibility. You’ll partner closely with our Infrastructure team on cloud security, access, and secrets, and with our Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.

This role is a new one at Close. You’ll have significant room to decide where better tooling, clearer ownership, and a small amount of code can reduce the most risk.

Our Stack

  • Backend: Python (Flask, FastAPI), TaskTiger, Temporal, REST & GraphQL APIs, MongoDB, PostgreSQL, Elasticsearch, Redis
  • Frontend: TypeScript, React, Vite, Vitest, React Testing Library, Playwright, Chromatic, WebSockets, WebRTC, React Native (mobile)
  • Infrastructure: Docker, Kubernetes, AWS (EKS, MSK, ElastiCache, EC2), Terraform, Ansible

You Are

  • An application security engineer who writes code: You can move from reading an unfamiliar code path, to reproducing an exploit, to proposing or shipping a production-quality fix. Strong Python or TypeScript experience is especially useful.
  • Skilled at finding vulnerabilities: You use modern AI-assisted review pipelines, guided by expert judgment, to uncover subtle flaws in web apps and APIs—from auth, tenant isolation, injection, SSRF, to business logic.
  • Offensive-minded and operationally responsible: You know how to test like an attacker without being careless with customer data or production systems.
  • An automation builder: Experience with SAST, DAST, SCA, container scanning, secrets scanning, or cloud posture tooling, and knowing how to remove noise and connect tools to engineering workflows.
  • AI-native and accountable: You use coding agents and LLMs to accelerate investigation, code review, and repetitive engineering work while verifying their output.
  • Able to separate severity from priority: Consider reachability, existing controls, customer impact, and attack chains.
  • Comfortable working across the business: Collaborate with product engineers, SREs, Security & Trust Lead, auditors, and external researchers.
  • Self-directed in a remote environment: Take an ambiguous surface and turn it into a practical plan with measurable progress.

You Will

  • Build a recurring product security review program and threat model new features.
  • Improve application security testing by combining static, dynamic, and dependency analysis.
  • Own vulnerability intake and remediation, serving as technical lead for our bug bounty program.
  • Turn security alerts into useful engineering work and automate ingestion and deduplication.
  • Make dependency remediation safer and less manual across Python and TypeScript codebases.
  • Make secrets routinely rotatable and expand our use of Vault-backed dynamic credentials.
  • Strengthen AWS security with Infrastructure and evaluate automated detection of risky configs.
  • Support audits and raise the security floor with documentation, paved roads, and lightweight training.
  • Take a key technical role in security incident response, coordinating investigation and root-cause analysis.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Close

Similar remote roles