YipitData

Product Security Engineer

YipitData$180K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in product security, application security, or software engineering.
  • Strong understanding of system architecture and vulnerability assessment.
  • Experience with security tools like SAST, DAST, and dependency scanning.
  • Ability to code in languages such as Python or JavaScript for automating security tasks.
  • Familiarity with frameworks such as OWASP Top 10 and NIST.
  • Experience securing AI-enabled products and understanding new attack techniques.
  • Strong communication skills to collaborate with technical and non-technical teams.

Responsibilities

  • Engage early in product development to conduct threat modeling and security design reviews.
  • Analyze application architecture and data flows to identify potential attack vectors.
  • Validate and prioritize vulnerabilities based on real-world risks.
  • Collaborate with engineering teams to create remediation plans without hindering development.
  • Enhance security tooling throughout the development lifecycle.
  • Automate security processes to align with rapid product and team growth.
  • Transform security insights into actionable guidelines and documentations for engineers.

Benefits

  • Flexible work hours and vacation policies.
  • Generous 401K match and parental leave.
  • Support for wellness and learning through budgets for professional development.
  • A high-impact work culture focused on ownership and personal growth.
  • Opportunities for exposure across multiple products and teams.
Full Job Description
About The Role:

YipitData is looking for a Product Security Engineer to help build security into the products and services we deliver to customers.

In this role, you will partner closely with Engineering and Product teams throughout the development lifecycle. You will assess new products and technologies, lead threat modeling and security design reviews, identify vulnerabilities, and help teams implement practical fixes before issues reach production.

This is a hands-on role for someone who understands how modern applications are designed and built. You should be comfortable reviewing system architecture, analyzing vulnerabilities, working directly with engineers, and improving the security tools embedded in our development pipelines.

This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one of our office hubs, or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding.

The work hours are flexible on this team, but most employees work East Coast hours.

As Our Product Security Engineer, You Will:
  • Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production
  • Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked
  • Find and validate vulnerabilities, separate real risk from noise, and help teams prioritize what actually matters
  • Work alongside engineers to design remediate plans that protect customers without bringing development to a halt
  • Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning
  • Tune security tools and workflows so engineers receive useful findings instead of a flood of false positives
  • Build automation that allows Product Security to keep pace as our products, engineering teams, and use of AI continue to grow
  • Turn security lessons into clear standards, secure design patterns, coding guidance, and documentation engineers will actually use
  • Help lead the response when product security issues arise, from initial investigation and containment through root cause analysis and long-term remediation
  • Become a trusted partner to Engineering and Product by bringing strong security judgment and workable solutions to difficult decisions
  • Explore emerging risks across cloud and AI-enabled products and help YipitData prepare for attack techniques that do not yet have a standard playbook

You Are Likely To Succeed If:
  • You have worked in product security, application security, software engineering, penetration testing, or another role that taught you how applications are built and broken
  • You can look at a complex system, follow the data, identify trust boundaries, and quickly understand where the real risks may be hiding
  • You know how to threat model, review architecture, and assess applications without relying entirely on a checklist
  • You can validate a vulnerability, determine whether it is actually exploitable, and explain why it matters to both engineers and business leaders
  • You are comfortable working across APIs, cloud services, containers, serverless technologies, and CI/CD pipelines
  • You have worked with tools such as SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning, and know that getting useful results takes more than simply turning them on
  • You can read and write code and are excited to automate repetitive security work using Python, JavaScript, or a similar language
  • You bring strong judgment and can balance security, customer impact, engineering effort, and business priorities
  • You communicate clearly, ask thoughtful questions, and can build credibility with both technical and non-technical teams
  • You have secured AI-enabled products, agents, large language model applications, or MCP integrations and are excited by risks that do not yet have a perfect playbook
  • You have deep experience with identity, authentication, authorization, or multi-tenant application security
  • You have applied frameworks such as the OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST in real-world environments
  • You enjoy working across multiple products and engineering teams in an environment where priorities move quickly and no two days look exactly the same

What We Offer:

Our compensation package includes comprehensive benefits, perks, and a competitive salary:
  • We care about your personal life, and we mean it. We offer flexible work hours, flexible vacation, a generous 401K match, parental leave, team events, wellness budget, learning reimbursement, and more!
  • Your growth at YipitData is determined by the impact that you are making, not by tenure, unnecessary facetime, or office politics. Everyone at YipitData is empowered to learn, self-improve, and master their skills in an environment focused on ownership, respect, and trust. See more on our high-impact, high-opportunity work environment above!
  • The annual base salary range for this position is anticipated to be $$180,000 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant's experience, knowledge, skills, abilities, and internal team benchmarks.

This role may be performed fully remotely within the United States. Please note that our US headquarters are located in NYC. If the remote work is performed outside of these offices, income may be subject to New York State tax withholding.

About YipitData

YipitData is a data analytics company that provides investment professionals with actionable insights on companies and industries. The company's platform aggregates and analyzes data from a variety of sources, including social media, news articles, and financial reports, to identify trends and patterns that can inform investment decisions. YipitData's clients include hedge funds, private equity firms, and other institutional investors.
Learn more about YipitData
Size
100 employees
Industry
Founded
2010

Similar Jobs

More Jobs at YipitData

More Information Technology Jobs

Find similar Product Security Engineer jobs: