Staff Application & Product Security Engineer @Cleo (US)
Software Development
Salary usd 160,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today

[Hiring] Staff Application & Product Security Engineer @Cleo (US)

Today - Cleo (US) is hiring a remote Staff Application & Product Security Engineer. πŸ’Έ Salary: usd 160,000 - 180,000 per year πŸ“Location: USA

Role Description

You will be the most senior hands-on application security engineer at Cleo, owning both how security is built into our products from design through release and the security posture of the products we ship, both on-premise and SaaS, as our customers experience them. This is a Staff-level individual contributor role with real program ownership: you set the standards, build the guardrails, and work directly with engineers in the code. You report to the CISO and partner daily with Engineering, and our Cloud Security team. You are not a one-person department: security engineers and consulting partners execute under your direction. Your job is to set direction, make the hard technical calls, and build leverage through automation and partners rather than carry every task yourself.

Qualifications

  • 6+ years in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams.
  • Strong object-oriented developer with strong proficiency in an object-oriented programming language, preferably Java.
  • Deep knowledge of application attack surfaces: authentication, authorization, API security, business-logic flaws, and modern service architectures.
  • Hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines.
  • Hands-on exploit reproduction and patch validation experience.
  • Coordinated disclosure experience with external security researchers and customers.
  • Product security experience on shipped software with an installed base.
  • Experience running threat modeling, design reviews, and manual security testing.
  • Clear communicator who can turn technical risk into engineering guidance for both developers and executives.

Requirements

  • Own and mature Cleo’s SSDLC: security requirements, threat modeling, and design reviews for high-risk product changes, APIs, and integrations.
  • Run and tune SAST, SCA, secrets detection, container, and IaC scanning.
  • Build reusable secure patterns, reference implementations, and policy-as-code controls.
  • Own developer security enablement: Security Champions meeting, deliver engineering security training campaigns, and provide practical remediation guidance.
  • Run risk-based triage, remediation, and verification for application and product vulnerabilities.
  • Own the penetration testing program: scope and coordinate third-party engagements.
  • Run our Vulnerability Disclosure Program, including researcher communications.
  • Coordinate the CVE lifecycle for Cleo products.
  • Own the application and product-security controls in Cleo's NIST CSF 2.0 program.
  • Own the security posture of the products Cleo ships across SaaS and customer-hosted deployment models.
  • Own the Product Security Roadmap and partner with Product Management, the CTO, and Architecture.
  • Be the technical owner for customer-facing product security.
  • Own threat modeling and security review for LLM-enabled product features.
  • Build controls and secure patterns for AI-related risks.
  • Apply and operationalize the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.

Benefits

  • Compensation: $160,000 to $180,000 + Bonus Opportunity
  • Great Healthcare + Dental + Vision
  • Flexible PTO
  • Culture of support, encouraging Life-Work balance
  • 401k match
  • FSA and HSA options
  • Employee Assistance Program
  • Paid Parental Leave
  • Remote work environment
  • Accelerated title and salary growth potential
  • A fun and energetic work environment
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Staff Application & Product Security Engineer @Cleo (US)
Software Development
Salary usd 160,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,336+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later