Staff Product Security Engineer

Tools for Humanity

$276K — $320K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of hands-on experience in Product, Application, or Cloud Security
  • Proficient in Rust, Go, and Python for code review and development
  • Extensive experience with AWS architectures and secure infrastructure-as-code
  • Expertise in leading threat modeling sessions and providing guidance to engineering
  • Strong background in managing security tooling and embedding in CI/CD
  • Deep understanding of web and API security principles, including OWASP Top 10
  • Nice to have: experience with Kubernetes, container security, mobile applications, or smart contracts

Responsibilities

  • Lead secure architecture reviews and threat modeling for new applications and services
  • Engineer and implement automated security guardrails and libraries for developers
  • Perform security-focused code and infrastructure reviews in multiple programming languages
  • Own the vulnerability management process and drive remediation efforts
  • Mature and scale Secure SDLC and bug bounty programs for rapid growth

Benefits

  • Comprehensive healthcare, dental, and vision plans
  • 401(k) plan with matching contributions
  • Flexible time off to promote work-life balance
  • Professional development stipend for ongoing learning
  • Commuter benefits to support your travel needs
Full Job Description
About the Team

The Security team at Tools for Humanity operates at a level far beyond a regular company. Our objective is not just to secure an organization, but to build the trusted, foundational infrastructure for the world's largest identity and financial network. We are a team of over 15 seasoned engineers who are central to the success of the World protocol. We tackle a unique and complex threat landscape that spans state-of-the-art hardware security for the Orb , advanced cryptography including new zero-knowledge proofs, and the security of a global, distributed cloud and mobile ecosystem. Our work is critical to enabling the protocol to scale to billions of users while upholding an unwavering commitment to fail-safe security and privacy.

About the Opportunity

As a Product Security Engineer, you will be a hands-on technical leader responsible for safeguarding the products and services that power the World project. You will be "In the Driver's Seat," proactively embedding security into every stage of the development lifecycle. This is not a role for box-tickers; you will be expected to think from first principles to solve novel security challenges at a global scale. Your work will directly protect our users and ensure the integrity of a protocol designed for the majority of humanity.

You will:
  • Lead secure architecture reviews and threat modeling sessions for new application and cloud services.
  • Engineer and implement automated security guardrails and reusable libraries to make the secure path the easy path for developers.
  • Perform deep-dive, security-focused code and infrastructure reviews in languages like Rust, Go, and Python.
  • Own the vulnerability management process, from triaging bug bounty submissions to driving remediation efforts with engineering teams.
  • Mature and scale our Secure SDLC and bug bounty programs to keep pace with a rapidly growing engineering organization.
About You

You are a pragmatic and deeply technical security engineer who thrives on solving complex problems. You have a builder's mindset and are passionate about shipping secure products with "Extreme Urgency." You are comfortable with ambiguity and are driven by the opportunity to secure systems with world-changing potential.
  • You have 12+ years of hands-on experience in Product Security, Application Security, or Cloud Security.
  • You are proficient in code review and development in languages like Rust, Go, and Python.
  • You have extensive experience securing modern AWS architectures and developing secure infrastructure-as-code (e.g., Terraform and CDK).
  • You are an expert in leading threat modeling sessions and providing actionable guidance to engineering teams.
  • You have a strong background in implementing and managing security tooling (SAST, DAST, SCA) and embedding security into CI/CD pipelines.
  • You have a deep understanding of web and API security principles (OWASP Top 10) and have experience securing distributed, mobile-first systems.
  • Nice to have: Experience scaling a security champions program, expertise in Kubernetes (EKS) and container security or a particular interest in securing mobile applications or smart contracts.


What we offer

The reasonably estimated salary for this role at Tools for Humanity ranges from $276,000 - $320,000 plus a competitive long-term incentive package. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Tools for Humanity offers a wide range of best-in-class, comprehensive, and inclusive employee benefits for this role, including healthcare, dental, vision, 401(k) plan and match, life insurance, flexible time off, commuter benefits, professional development stipend, and much more.

If you don't think you meet all of the criteria but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.

Similar Jobs

More Jobs at Tools for Humanity

More Information Technology Jobs

Find similar Staff Product Security Engineer jobs: