Anyscale

Senior Product Security Engineer

Anyscale$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in product or application security, preferably in high-growth startups.
  • Proven experience leading a secure software development lifecycle at scale.
  • Hands-on experience collaborating with engineering on security features and architecture.
  • Expertise in software composition analysis, secret scanning, and SAST tools.
  • Understanding of software supply chain security and SBOM strategies.
  • Skilled in triaging vulnerabilities using CVSS and a business-focused approach.
  • Strong communication and leadership abilities for directing and mentoring teams.

Responsibilities

  • Own and manage a scalable secure software development lifecycle, including threat modeling and secure practices.
  • Collaborate with engineering on security features and secure design from inception to implementation.
  • Conduct security reviews of existing systems and new projects, converting findings into actionable priorities.
  • Lead vulnerability management efforts by cataloging components and generating accurate security posture reports.
  • Drive resolution of vulnerabilities in collaboration with engineering, adhering to defined service level agreements.
  • Oversee software composition analysis, secret scanning, and SAST practices across product repositories.
  • Mentor engineering teams to foster a culture of security awareness and improve security standards.

Benefits

  • Opportunities for professional growth with a focus on ownership and high-impact work.
  • Collaborative work environment with significant cross-departmental interaction.
  • Chance to shape and scale security practices in a growing company.
  • Flexible working conditions, accommodating a remote or hybrid work model.
Full Job Description
About the Role

Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering's partner on building security into the product. Reporting to the Head of Security, you will work in close partnership with engineering.

This is a senior, high-ownership role. You will own and operate a scalable SSDL, partner with engineering on security features and secure design, review the security of existing systems and new initiatives, and own how we find, track, drive to resolution and report on vulnerabilities in what we ship. This role is based in India.

In your first year, success looks like an SSDL that scales with engineering rather than gating it, security review embedded in how new initiatives ship, and accurate, on-demand vulnerability reporting backed by a working path to resolution.
What You'll Do
  • Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt.
  • Partner with engineering on security features and secure-by-design architecture, from early design through implementation.
  • Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work.
  • Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand.
  • Drive vulnerabilities to resolution with engineering against defined SLAs.
  • Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks.
  • Mentor other engineers and raise the security bar across the organization.
What You'll Bring
  • 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup.
  • Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review.
  • A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings.
  • Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories.
  • A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches.
  • Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering.
  • The communication and seniority to set direction, review others' work, and raise the bar for those around you.
Nice to Have
  • Experience producing vulnerability or security posture reporting for enterprise or regulated customers.
  • Familiarity with container artifact security, including image scanning, signing, and SBOM generation.
  • Experience building or maturing an SSDL program at scale.
  • Background in AI or ML platforms or distributed systems.

About Anyscale

SOHO 3Q is a prime community-focused, shared office space in China managed by SOHO China. It is headquartered at Chaowai SOHO in Beijing, China. As of June 2019, the coworking space had 30 spaces in China.
Learn more about Anyscale

Similar Jobs

More Jobs at Anyscale

More Information Technology Jobs

Find similar Senior Product Security Engineer jobs: