[![Image](https://upload.wikimedia.org/wikipedia/commons/8/82/Telegram_logo.svg) Fresh remote jobs, sorted by category — join Jobicy on Telegram  › Fresh remote jobs on Telegram  ›](https://t.me/JobicyJobs) [All remote jobs](https://jobicy.com/jobs.md)Open role[![YipitData logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/e1bee9df-221.jpg)](https://jobicy.com/company/yipitdata.md)Remote opportunity at[YipitData](https://jobicy.com/company/yipitdata.md)

# Product Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/yipitdata.md)Share31 Aug 2026Published48Listing views4Application actions30 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryYipitData is hiring a hands-on Product Security Engineer to embed security practices across customer-facing products and services. The role partners closely with Engineering and Product teams on threat modeling, architecture reviews, vulnerability validation, remediation planning, and incident response. It owns and improves development-lifecycle tooling such as SAST, DAST, dependency, secret, and infrastructure-as-code scanning, with an emphasis on reducing false positives through automation and tuning. The position also addresses cloud, identity, multi-tenant, and emerging AI/LLM product-security risks in a fast-moving, high-ownership environment.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior-level security role requiring broad practical expertise across application architecture, cloud services, CI/CD, identity, vulnerability assessment, and AI-enabled products. Success depends on independently making risk-based tradeoffs while influencing multiple technical and non-technical stakeholders.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$180,000US market range$155k–$210k0$231k

AI insightThe stated annual base salary is $180,000 USD, so the job-offer median is $180,000. For a US-based Product Security Engineer with responsibility for application security architecture, security tooling, cloud environments, and AI-related risks, a reasonable US market base-salary range is approximately $155,000 to $210,000 annually; actual pay varies by experience, location, and scope.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Product Security](https://jobicy.com/jobs?search_keywords=Product%20Security.md)[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Security Architecture Review](https://jobicy.com/jobs?search_keywords=Security%20Architecture%20Review.md)[Vulnerability Management](https://jobicy.com/jobs?search_keywords=Vulnerability%20Management.md)[SAST](https://jobicy.com/jobs?search_keywords=SAST.md)[DAST](https://jobicy.com/jobs?search_keywords=DAST.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[CI/CD Security](https://jobicy.com/jobs?search_keywords=CICD%20Security.md)[AI Security](https://jobicy.com/jobs?search_keywords=AI%20Security.md)

Sample interview questionsHow would you conduct a threat model for a new multi-tenant API product?I would first map the architecture, assets, data flows, users, trust boundaries, and third-party dependencies. I would then identify likely abuse cases around authentication, authorization, tenant isolation, input handling, secrets, and rate limits; rank them by likelihood and impact; and work with engineers to define testable mitigations before release.

How do you distinguish an exploitable vulnerability from a low-value scanner finding?

I validate the finding in the actual application context by reviewing reachability, data flow, required privileges, environmental controls, and potential business impact. I document reproducible evidence where possible, assign risk based on realistic exploitability, and recommend remediation priorities rather than relying solely on scanner severity.

What steps would you take to improve adoption of SAST and dependency scanning among engineering teams?

I would tune rules to focus on high-confidence, relevant findings, integrate scans into existing pull-request and CI workflows, and establish clear ownership and remediation SLAs. I would also publish secure coding guidance, track false-positive rates and remediation trends, and use feedback from engineers to continuously improve the program.

How would you approach security for an LLM-enabled feature that can call external tools or agents?

I would assess prompt injection, data exfiltration, insecure tool authorization, excessive agency, cross-tenant data exposure, and supply-chain risks in model and tool integrations. Controls would include least-privileged scoped credentials, explicit authorization checks outside the model, input and output safeguards, audit logging, isolation of sensitive data, and adversarial testing aligned to relevant OWASP guidance.

Describe how you would handle a critical product-security incident.

I would quickly establish scope, severity, affected assets, and immediate containment actions while maintaining a clear incident record. I would coordinate with engineering and relevant business stakeholders on mitigation and communication, validate that the fix is effective, then lead root-cause analysis and durable follow-up actions such as control improvements, detection enhancements, and secure-design updates.

About Us:

YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B. Every day, our proprietary technology analyzes billions of alternative data points to uncover actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments.

Our data and research teams transform raw data into strategic intelligence, delivering accurate, timely, and deeply contextualized analysis that our customers—ranging from the world’s top investment funds to Fortune 500 companies—depend on to drive high-stakes decisions. From sourcing and licensing novel datasets to rigorous analysis and expert narrative framing, our teams ensure clients get not just data, but clarity and confidence.

We operate globally with offices in the US, APAC, and India. Our award-winning, people-centric culture—recognized by Inc. as a [Best Workplace](https://www.inc.com/profile/yipitdata) for three consecutive years—emphasizes transparency, ownership, and continuous mastery.

What It’s Like to Work at YipitData:

YipitData isn’t a place for coasting—it’s a launchpad for ambitious, impact-driven professionals.

From day one, you’ll take the lead on meaningful work, accelerate your growth, and gain exposure that shapes careers.

Why Top Talent Chooses YipitData:

* Ownership That Matters: You’ll lead high-impact projects with real business outcomes
* Rapid Growth: We compress years of learning into months
* Merit Over Titles: Trust and responsibility are earned through execution, not tenure
* Velocity with Purpose: We move fast, support each other, and aim high—always with purpose and intention

If your ambition is matched by your work ethic—and you’re hungry for a place where growth, impact, and ownership are the norm—YipitData might be the opportunity you’ve been waiting for.

About The Role:

YipitData is looking for a Product Security Engineer to help build security into the products and services we deliver to customers.

In this role, you will partner closely with Engineering and Product teams throughout the development lifecycle. You will assess new products and technologies, lead threat modeling and security design reviews, identify vulnerabilities, and help teams implement practical fixes before issues reach production.

This is a hands-on role for someone who understands how modern applications are designed and built. You should be comfortable reviewing system architecture, analyzing vulnerabilities, working directly with engineers, and improving the security tools embedded in our development pipelines.

This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one of our office hubs, or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding.

The work hours are flexible on this team, but most employees work East Coast hours.

As Our Product Security Engineer, You Will:

* Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production
* Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked
* Find and validate vulnerabilities, separate real risk from noise, and help teams prioritize what actually matters
* Work alongside engineers to design remediate plans that protect customers without bringing development to a halt
* Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning
* Tune security tools and workflows so engineers receive useful findings instead of a flood of false positives
* Build automation that allows Product Security to keep pace as our products, engineering teams, and use of AI continue to grow
* Turn security lessons into clear standards, secure design patterns, coding guidance, and documentation engineers will actually use
* Help lead the response when product security issues arise, from initial investigation and containment through root cause analysis and long-term remediation
* Become a trusted partner to Engineering and Product by bringing strong security judgment and workable solutions to difficult decisions
* Explore emerging risks across cloud and AI-enabled products and help YipitData prepare for attack techniques that do not yet have a standard playbook

You Are Likely To Succeed If:

* You have worked in product security, application security, software engineering, penetration testing, or another role that taught you how applications are built and broken
* You can look at a complex system, follow the data, identify trust boundaries, and quickly understand where the real risks may be hiding
* You know how to threat model, review architecture, and assess applications without relying entirely on a checklist
* You can validate a vulnerability, determine whether it is actually exploitable, and explain why it matters to both engineers and business leaders
* You are comfortable working across APIs, cloud services, containers, serverless technologies, and CI/CD pipelines
* You have worked with tools such as SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning, and know that getting useful results takes more than simply turning them on
* You can read and write code and are excited to automate repetitive security work using Python, JavaScript, or a similar language
* You bring strong judgment and can balance security, customer impact, engineering effort, and business priorities
* You communicate clearly, ask thoughtful questions, and can build credibility with both technical and non-technical teams
* You have secured AI-enabled products, agents, large language model applications, or MCP integrations and are excited by risks that do not yet have a perfect playbook
* You have deep experience with identity, authentication, authorization, or multi-tenant application security
* You have applied frameworks such as the OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST in real-world environments
* You enjoy working across multiple products and engineering teams in an environment where priorities move quickly and no two days look exactly the same

What We Offer:

Our compensation package includes comprehensive benefits, perks, and a competitive salary:

* We care about your personal life, and we mean it. We offer flexible work hours, flexible vacation, a generous 401K match, parental leave, team events, wellness budget, learning reimbursement, and more!
* Your growth at YipitData is determined by the impact that you are making, not by tenure, unnecessary facetime, or office politics. Everyone at YipitData is empowered to learn, self-improve, and master their skills in an environment focused on ownership, respect, and trust. See more on our high-impact, high-opportunity work environment above!
* The annual base salary range for this position is anticipated to be $$180,000 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant’s experience, knowledge, skills, abilities, and internal team benchmarks.

This role may be performed fully remotely within the United States. Please note that our US headquarters are located in NYC. If the remote work is performed outside of these offices, income may be subject to New York State tax withholding.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity employer.

[Job Applicant Privacy Notice](https://www.yipitdata.com/careers/job-applicant-privacy-notice)

Show more

[Apply now >](https://jobicy.com/jobs/152175-product-security-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs  Aug 31

### [Senior Cyber Threat Intelligence Analyst](https://jobicy.com/jobs/152158-senior-cyber-threat-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs  Aug 31

### [Staff Cyber Threat Intelligence Analyst](https://jobicy.com/jobs/152155-staff-cyber-threat-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 30

### [Software Engineer, Infrastructure Security](https://jobicy.com/jobs/152102-software-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora  Aug 29

### [Senior Infrastructure Security Software Engineer](https://jobicy.com/jobs/151970-senior-infrastructure-security-software-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora  Aug 29

### [Detection & CorpSec Engineer](https://jobicy.com/jobs/151966-detection-corpsec-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

*
![Veeam Software logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/f7716b71-221.jpg)
Veeam Software  Aug 28

### [Cyber-Security Operations Analyst III, Product AppSec](https://jobicy.com/jobs/151951-cyber-security-operations-analyst-iii-product-appsec.md)

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Engineer I, Information Technology](https://jobicy.com/jobs/151867-security-engineer-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Analyst I, Information Technology](https://jobicy.com/jobs/151862-security-analyst-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass  Aug 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Lead Security Operations Engineer](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…