Greenlight Financial Technology

Staff Product Security Engineer

Greenlight Financial Technology$165K — $200K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of product security experience including application security and secure SDLC.
  • Expert in threat modeling using methodologies like STRIDE and PASTA.
  • Hands-on expertise in penetration testing across various platforms.
  • Experience managing PSIRT operations including vulnerability triage and incident response.
  • Deep understanding of AI security risks and OWASP Top 10 for various technologies.
  • Strong programming skills to build security tools and automate workflows.
  • Solid technical knowledge of CI/CD pipelines and relevant technologies.

Responsibilities

  • Lead security architecture and threat modeling sessions with product teams.
  • Translate threats into risk-rated engineering remediations based on severity.
  • Conduct penetration testing to assess security across product lines.
  • Red-Team AI products to evaluate guardrails and security measures.
  • Manage PSIRT operations including intake and coordination of vulnerability reports.
  • Define enterprise policies for AI-assisted development environments.
  • Champion security culture through developer training and advocacy.

Benefits

  • Medical, dental, vision, and HSA match.
  • Unlimited PTO and paid company holidays.
  • Professional development stipends.
  • Flexible work-from-home options including remote and in-office.
  • 100% paid parental and caregiving leave with additional support during leave.
  • Access to mental health resources and 1:1 financial planners.
Full Job Description
We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. This individual will be responsible for the end-to-end security of our consumer products, digital platform and an emerging hardware device line. The Staff Product Security Engineer will drive security review, threat modeling programs, lead penetration testing, manage PSIRT operations, champion secure AI adoption and establish security guardrails for AI powered products and AI assisted development workflows within a highly regulated financial services environment.

This role reports to the Senior Manager of Product Security.

Your day-to-day:

  • Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA and attack tree methodologies.
  • Translate threats into actionable, risk-rated engineering remediations prioritized by severity.
  • Conduct hands-on penetration testing and security assessments across our full product stack producing actionable reports for engineering and leadership.
  • Red-Team our AI powered products and development tools to test for prompt injection, data exfiltration, MCP server exploitation, and tool misuse. Probe AI guardrails to ensure they hold. Experience with product security tools such as Burp Suite, Metasploit, Kali Linux, Postman, etc.
  • Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on-call incidents. This includes managing zero day findings, driving remediation, collaborating with engineering to patch or mitigate with compensating controls.
  • Shape the posture of our AI assisted development environment defining and enforcing enterprise policies for claude and cursor.
  • Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers and collaborating with the AI team on securing ML pipelines.
  • Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products and ensuring every engineer understands that product security is an enabler and not a gate.


What you'll bring to the team:

  • 10+ years of product security experience spanning application security, cloud security, and secure SDLC. you will have full SDLC experience from design through development, deployment and incident response.
  • Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems.
  • Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware. You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red-team engagements.
  • PSIRT operational experience from vulnerability intake and triage. You are fluent in CVE, CVSS, FIRST PSIRT frameworks.
  • Deep hands down AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and have practical experience with MITRE.
  • Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor.
  • You understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development. You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic.
  • Strong programming ability and capability to review code, build security tools, automate workflows and be credible with the engineering teams you partner with.
  • Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications.
  • Strong knowledge of programing language & frameworks (i.e. Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies and infrastructure (i.e. AWS, GCP, Kubernetes, Ambassador, Helm), and databases (i.e. MySQL, DynamoDB, Redis)
  • Ability to influence without authority, mentor without managing , and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance and executives alike.


Preferred experience:

  • Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience.
  • Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly.


Work perks at Greenlight:

  • Medical, dental, vision, and HSA match
  • Paid life insurance, AD&D, and disability benefits
  • Traditional 401k with company match
  • Unlimited PTO
  • Paid company holidays and pop-up bonus holidays
  • Professional development stipends
  • Mental health resources
  • 1:1 financial planners
  • Fertility healthcare
  • 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
  • Flexible WFH, both remote and in-office opportunities
  • Fully stocked kitchen, catered lunches, and occasional in-office happy hours
  • Employee resource groups


Our stance on salaries:

Greenlight provides a competitive compensation package with a market-based approach to pay and will vary depending on your location, experience and skill set. The total compensation package for this position will also include a discretionary performance bonus, equity rewards, medical benefits, 401K match, and more. Greenlight conducts continuous compensation evaluations across departments and geographies to ensure we are keeping our pay current and competitive.

The estimated base pay range for this position in (NY, CA, WA): $165,000-200,000

The estimated base pay range for this position in (CO): $165,000-185,000

About Greenlight Financial Technology

Greenlight Financial Technology is a financial technology company that provides a debit card for kids and teens. The company was founded in 2014 by Tim Sheehan and Johnson Cook. Greenlight's debit card is designed to help parents teach their children financial responsibility and manage their children's spending. The card allows parents to set spending limits, approve or deny transactions, and monitor their children's spending. Greenlight also offers a mobile app that allows parents to manage their children's accounts and track their spending. The company is headquartered in Atlanta, Georgia.
Learn more about Greenlight Financial Technology
Size
300 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Greenlight Financial Technology

More Information Technology Jobs

Find similar Staff Product Security Engineer jobs: