WorkOS

Product Security Engineer

WorkOS β€’ $108K β€” $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in security engineering or security-focused software engineering roles.
  • Proficient in executing security assessments, penetration testing, and responsible disclosure.
  • Experience with common industry security tools.
  • Proven track record of identifying vulnerabilities in software, supported by CVEs or bug bounties.
  • Strong communication skills to effectively collaborate with engineering teams.
  • Skilled in reading and writing code, leveraging AI in security processes.
  • Bonus: Familiarity with authentication and identity domains.

Responsibilities

  • Lead secure design initiatives with engineering teams and conduct risk assessments throughout product development.
  • Create systems that prioritize security by default, making secure options the simplest for engineers.
  • Conduct penetration testing and code audits to discover vulnerabilities from an adversary's perspective.
  • Enhance security tooling by integrating and improving vulnerability management across engineering processes.
  • Oversee and refine the responsible disclosure program, focusing on automation and submission validation.
  • Develop and implement code changes to rectify vulnerabilities and bolster the security of WorkOS products.
  • Engage with customers to address their security-related questions and enhance trust.

Benefits

  • 401k matching
  • Competitive equity options
  • Healthcare, dental, and vision coverage for employees and their families
  • FSA, short-term and long-term disability, and voluntary life insurance
  • Carrot fertility benefits
  • 20 days paid vacation plus 10 holidays and unlimited sick leave
  • 12 weeks fully paid parental leave
  • Monthly fitness stipend for gym memberships or wellness activities
  • Monthly wellness stipend for stress relief and relaxation activities
  • Commuter benefits for hybrid employees located in SF or NYC
Full Job Description
Who we're looking for
  • Risk-focused and pragmatic. You excel at identifying and reasoning about security risk in real-world contexts. You prioritize ruthlessly, always asking: what's the most effective way to reduce risk right now and in the long term?
  • A builder who can break things. You're comfortable reading and writing code, and you have a passion for deeply understanding the products you secure. You think like an attacker to find subtle, high impact vulnerabilities and like a defender to design pragmatic, effective mitigations.
  • A strong partner to engineering. You build trust with engineers by understanding their priorities, making security frictionless, and finding ways to make the secure path, the easiest path.
  • Excited about AI. You're embracing AI and automation to scale security and reduce toil.
  • Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.

Responsibilities
  • Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.
  • Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.
  • Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.
  • Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.
  • Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.
  • Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.
  • Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.

Qualifications
  • 5+ years of experience in a security engineering or security-focused software engineering role.
  • Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
  • Familiarity with and experience using common industry tooling.
  • Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.
  • Strong written and verbal communication skills, particularly in partnering with engineering teams.
  • Comfortable reading and writing code, and able to effectively leverage AI during the process.
  • Bonus: Experience in the authentication and identity domain.
  • Bonus: Experience writing production level code, especially developing security features.


Benefits and Perks (US Only) πŸ’–

At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.

  • 401k matching
  • Competitive Equity
  • Healthcare, dental and vision coverage
  • FSA, ST/LT Disability, Voluntary Life
  • Carrot fertility benefits
  • 20 days paid vacation + 10 holidays + unlimited sick leave
  • 12 weeks fully paid parental leave
  • Fitness: Monthly stipend for gyms, yoga classes, race registrations or whatever keeps you active
  • Wellness: Monthly stipend for a massage, meditations class, therapy, or activities that enhance your well-being
  • Commuter benefits for hybrid employees in SF/NYC
  • Unlimited token usage!

Please inquire directly with our recruiting team for benefits available to those working outside the US.

About WorkOS

WorkOS is a software company that provides developer tools for building enterprise-grade applications. The company was founded in 2019 by Michael Grinich and Hayley Griffin. WorkOS' mission is to make it easy for developers to build applications that integrate with enterprise systems. The company's flagship product is the WorkOS API, which provides a set of tools for building enterprise-grade applications that integrate with popular identity providers, such as Google and Microsoft. WorkOS has raised $10 million in funding from top investors, including Founders Fund and Gradient Ventures.
Learn more about WorkOS
Size
50 employees
Industry

Similar Jobs

More Jobs at WorkOS

  • WorkOS
    Data Engineer
    $110K β€” $130K *
    Canada, KY 41519 (Pike County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Product Security Engineer jobs: