[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Phantom logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/3d0a3a49-221.png)](https://jobicy.com/company/phantom.md)Remote opportunity at[Phantom](https://jobicy.com/company/phantom.md)

# Staff Product Security Engineer (Security)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/phantom.md)Share22 Sep 2026Published48Listing views3Application actions22 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryPhantom is hiring a Staff Product Security Engineer to lead hands-on application and product-security work across mobile, web, API, backend, cloud, and blockchain-adjacent systems. The role owns threat modeling, architecture reviews, secure SDLC controls, AI-assisted code review and testing, supply-chain security, vulnerability remediation, and incident-response improvements. This staff-level position requires technical leadership across engineering and product teams, with particular focus on authorization, transaction integrity, key material, and secure release processes. It is a fully remote full-time opportunity open to candidates in the United States, United Kingdom, and Canada.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a staff-level security role protecting financial and self-custodial products used at significant scale, requiring broad technical depth and sound judgment on exploitability and business impact. The engineer must independently drive ambiguous, cross-functional initiatives while influencing architecture and delivering verified remediation.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$225,000US market range$190k–$270k0$297k

AI insightThe disclosed target base-salary range is $200,000 to $250,000 per year, producing a midpoint of $225,000 annually. A competitive US market base-salary range for a Staff Product Security Engineer is estimated at $190,000 to $270,000 annually; total compensation may be higher when equity and performance bonus are included.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Product Security](https://jobicy.com/jobs?search_keywords=Product%20Security.md)[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Secure SDLC](https://jobicy.com/jobs?search_keywords=Secure%20SDLC.md)[Security Architecture](https://jobicy.com/jobs?search_keywords=Security%20Architecture.md)[Code Review](https://jobicy.com/jobs?search_keywords=Code%20Review.md)[API Security](https://jobicy.com/jobs?search_keywords=API%20Security.md)[Mobile Security](https://jobicy.com/jobs?search_keywords=Mobile%20Security.md)[Software Supply Chain Security](https://jobicy.com/jobs?search_keywords=Software%20Supply%20Chain%20Security.md)[CI/CD Security](https://jobicy.com/jobs?search_keywords=CICD%20Security.md)

Sample interview questionsHow would you conduct a threat model for a new wallet transaction-signing feature?I would map assets, trust boundaries, actors, entry points, and data flows first, with special attention to key material, signing requests, transaction simulation, authorization, and third-party integrations. I would identify abuse cases such as transaction substitution, malicious dApp requests, compromised clients, replay attacks, and privilege escalation, then prioritize mitigations by exploitability and user impact. Finally, I would convert the findings into testable engineering requirements and validate them before release.

Describe how you would improve product-security coverage without slowing product engineering teams unnecessarily.

I would focus on high-signal controls embedded in existing developer workflows: secure design reviews for high-risk changes, automated dependency and secret scanning, targeted SAST rules, CI policy checks, and reusable security libraries. I would measure false positives, remediation time, and escaped defects, then tune or remove controls that create friction without meaningful risk reduction. Clear ownership, actionable findings, and security champions also help make the program scalable.

What would you examine when assessing the security of a CI/CD and software supply-chain environment?

I would assess identity and least privilege for developers and automation, branch protections, secret storage and rotation, dependency provenance, build isolation, artifact integrity, signing, and deployment approvals. I would also review third-party actions or plugins, access to production credentials, audit logging, and incident-response paths for compromised pipelines. The objective is to establish a verifiable chain from reviewed source to trusted released artifact.

How do you determine whether a reported vulnerability deserves urgent remediation?

I assess the affected asset, required attacker access, exploit reliability, exposure, privilege gained, potential blast radius, and available compensating controls. I pair technical severity with business impact, especially whether user assets, sensitive data, transaction integrity, or service availability are at risk. I then communicate a concrete severity rationale, remediation path, owner, and verification criteria rather than relying only on a generic score.

Give an example of using AI-assisted security tooling responsibly.

I would use AI to accelerate repetitive tasks such as code-path exploration, test-case generation, log triage, and initial vulnerability hypothesis generation. However, I would require deterministic checks and human validation for security decisions, especially around exploitability, sensitive data, and production changes. I would evaluate the tool for data-handling risks, prompt-injection exposure, false positives, and measurable improvement in coverage or response time before broad adoption.

[Phantom](https://phantom.com) is on a mission to connect the world to the freedom of open markets. Tens of millions of people all over the world use Phantom to access global markets that never close, including perpetuals, prediction markets, tokenized assets, stablecoins and memes. Phantom users are able to discover the markets that matter and the cultural moments that shape them, building conviction through real-time data and the verified performance of top traders. With self-custody and access to open networks at its core, Phantom lets them control their financial moves in the same app they use to safely store or spend money worldwide.

Phantom has reached #1 in Google Play’s finance category and consistently ranks in the top 50 apps across all categories. Phantom partners with many of the most trusted and influential names in finance like Hyperliquid, Stripe, Kalshi and Visa, to make the most popular and innovative financial products accessible to everyone.

We are around 180 people, fully remote, backed by a $150M Series C investment from a16z, Sequoia Capital and Paradigm.

Security is core to Phantom’s product and the trust millions of users place in us. We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work—from code review and threat modeling to vulnerability discovery and security automation. We’re looking for strong security engineers with high agency who can identify the risks that matter, build practical solutions, and take ownership from initial discovery through verified remediation.

This is a hands-on, high-impact role spanning architecture, source code, testing, and production systems across Phantom’s mobile, web, and backend products. You’ll work directly with engineering and product teams, lead complex security initiatives, and build capabilities that scale across the company. At the Staff level, you’ll set technical direction and raise the bar for how Phantom designs, builds, and ships secure products.

This role is fully remote and open to candidates based in the US, UK and Canada.

### Responsibilities

*

Product Security Ownership: Partner with engineering teams to identify and address security risks across Phantom’s mobile applications, web products, APIs, and backend services.

*

Architecture and Threat Modeling: Lead security reviews for new products and major architectural changes, with particular attention to authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations.

*

Secure Product Development: Embed practical security controls into the software development lifecycle, from design and implementation through testing, release, and production operation.

*

Code Review and Security Testing: Perform AI assisted security code reviews and targeted testing of high-risk features. Build repeatable approaches that help find vulnerabilities before they reach production.

*

Security Tooling: Develop and improve tooling that gives engineers fast, actionable security feedback without creating unnecessary friction. Use automation and AI-assisted workflows where they materially improve coverage or speed.

*

Software Supply Chain Security: Harden CI/CD, build, and release systems against supply chain threats, including dependency risk, secrets exposure, build provenance, artifact integrity, and compromised developer or automation workflows.

*

Vulnerability Management: Triage findings from internal testing, researchers, bug bounty submissions, and third-party assessments. Work with owners to determine real-world impact and drive issues through verified remediation.

*

Incident Response: Support the investigation of product security incidents and suspicious activity. Turn lessons from incidents into durable improvements to product architecture, detection, and engineering standards.

*

Technical Leadership: Establish product security patterns and expectations across engineering. At the Staff level, lead ambiguous, cross-functional initiatives and influence architecture beyond any single product team.

### Qualifications

*

5+ years of experience in product security, application security, security engineering, or software engineering, including experience operating at a senior or staff level.

*

Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes.

*

Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation.

*

Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python and Go.

*

Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity.

*

Experience threat modeling complex products and translating security risks into concrete engineering requirements.

*

Strong judgment when evaluating exploitability, business impact, and appropriate remediation.

*

Track record of partnering effectively with engineering and product teams while maintaining a high security bar.

*

Clear written and verbal communication, including the ability to explain technical risk to both engineers and non-security stakeholders.

### Nice To Haves

*

Experience securing consumer financial products, wallets, payments, or other systems where client integrity and transaction safety are critical.

*

Familiarity with blockchain systems, smart-contract interactions, transaction simulation, signing workflows, or self-custodial wallet architecture.

*

Experience securing browser extensions or native mobile applications.

*

Experience building and integrating application-security tooling, static or dynamic analysis, security test infrastructure, or policy-as-code controls.

*

Familiarity with AWS, Kubernetes, CI/CD systems, and cloud-native service architectures.

*

Experience working with bug bounty programs or coordinating external security assessments.

### Why Work with Us

Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use. Our products serve a large and rapidly growing global community, which makes security engineering here both technically challenging and directly consequential.

This role offers the opportunity to:

*

Protect products used by tens of millions of people.

*

Work on security problems spanning mobile, browser, backend, cloud, and blockchain systems.

*

Shape product architecture early rather than reviewing security only at the end.

*

Build durable security capabilities while the company and product surface continue to grow.

*

Work with engineers who care deeply about product quality, user experience, and security.

### Benefits

*

Competitive salary and equity

*

Eligibility to participate in the company’s performance bonus program

*

Comprehensive medical, dental, and vision insurance with 100% coverage

*

Stipend for your ideal remote setup

*

Flexible hours and a supportive remote environment

*

Unlimited vacation—take time when you need it

*

401(k) retirement plan

*

Monthly wellness benefit

*

Weekly meal benefit

*

Global off-sites

The target base salary for this role will range between $200,000 to $250,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer.

We strongly encourage candidates of all backgrounds to apply. We believe that our work is stronger with a variety of perspectives, and we’re eager to further diversify our company. If you have a background that you feel would make an impact at Phantom, please consider applying. We’re committed to building an inclusive, supportive place for you to do the best work of your career.

By submitting your resume and application materials, you acknowledge and agree that Phantom Technologies, Inc. (“Phantom”) collects and processes your personal information (including application materials, interview records, and related data) to evaluate your candidacy. Phantom may use AI-powered tools and third-party service providers for transcription, note-taking, scheduling, and other administrative tasks. Phantom does not sell your information and your materials will be handled securely and in accordance with applicable data protection laws.

Show more

[Apply now >](https://jobicy.com/jobs/153861-staff-product-security-engineer-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Mozilla logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/mozilla.jpg)
Mozilla  Sep 22

### [Senior Security Engineer, Bug Bounty](https://jobicy.com/jobs/153893-senior-security-engineer-bug-bounty.md)

Why Mozilla? Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded…

*
![Goodleap logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/482c4fb7-221.png)
Goodleap  Sep 22

### [Senior Security Engineer, Product Security](https://jobicy.com/jobs/153887-senior-security-engineer-product-security.md)

About GoodLeap: GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more….

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 22

### [Threat Detection Analyst (Japanese & English speaking)](https://jobicy.com/jobs/153871-threat-detection-analyst-japanese-english-speaking.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Sep 22

### [Security and Infrastructure Engineer](https://jobicy.com/jobs/153866-security-and-infrastructure-engineer.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 21

### [Principal Software Engineer, Infrastructure Security](https://jobicy.com/jobs/153845-principal-software-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 21

### [Principal Security Engineer, Infrastructure Security](https://jobicy.com/jobs/153841-principal-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![DeleteMe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c26c546a-221.png)
DeleteMe  Sep 21

### [Privacy Advisor](https://jobicy.com/jobs/153793-privacy-advisor.md)

DeleteMe is the leader in proactive privacy protection. We help Individuals, Families, Businesses and Security teams reduce their human attack surface by continuously monitoring and removing exposed personal data (PII)…

*
![Oddball logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/02/8c034287ffd7b6474f90645b1c72e60a.jpeg)
Oddball  Sep 21

### [ATO Specialist](https://jobicy.com/jobs/153774-ato-specialist.md)

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a…

*
![DuckDuckGo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/11/ab8415dd5798a360323ce06beaf30c35.png)
DuckDuckGo  Sep 21

### [Senior Web Security Engineer, Browser Platform](https://jobicy.com/jobs/151281-senior-web-security-engineer-browser-platform.md)

Who We Are Hi, we’re DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable…

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 20

### [Senior Security Technical Account Manager](https://jobicy.com/jobs/153750-senior-security-technical-account-manager.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…