Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Staff Product Security Engineer

greenlight
Companygreenlight
CategoryEngineering
LocationAtlanta
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted25 Jun 2026
Last verified12 Aug 2026
SourceThe employer's own careers page (company_site)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Greenlight is a family fintech company serving over 6 million parents and kids with a banking app. This Staff Product Security Engineer role owns end-to-end security of consumer products, digital platforms, and emerging hardware devices, with a focus on threat modeling, penetration testing, PSIRT operations, and secure AI adoption within a regulated financial services environment. What You'll Do • Lead security architecture and design review sessions using STRIDE, PASTA, and attack tree methodologies; translate identified threats into actionable, risk-rated engineering remediations • Conduct hands-on penetration testing and security assessments across the full product stack, including red-teaming AI-powered products and development tools for prompt injection, data exfiltration, and guardrail bypasses • Drive PSIRT operations: triage vulnerability reports, lead technical investigations, coordinate remediation with engineering, score severity using CVSS, manage coordinated disclosure, and handle zero-day findings • Define and enforce enterprise policies for AI-assisted development environments, including guardrails for Claude and Cursor; architect MCP security controls and policies for AI-generated code and secrets scanning • Partner cross-functionally with architects, product managers, and engineering teams on security and compliance implications of new features; mentor junior security engineers and champion security culture through developer training on secure coding What You Need • 10+ years of product security experience spanning application security, cloud security, and secure SDLC across web, mobile, cloud, embedded systems, and AI • Expert-level threat modeling using STRIDE, PASTA, or equivalent methodologies; hands-on penetration testing skills across applications, APIs, cloud infrastructure, and hardware/firmware • PSIRT operational experience including vulnerability intake, triage, CVE/CVSS fluency, and FIRST PSIRT framework knowledge • Deep AI security expertise with expert-level understanding of OWASP Top 10 for LLM, API, Web, Mobile, and practical MITRE experience; hands-on experience with SAST, DAST, SCA tools and AI development tool security (Claude, Cursor) • Strong programming ability and code review capability; deep technical knowledge of CI/CD pipelines, programming languages and frameworks (Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies (AWS, GCP, Kubernetes, Ambassador, Helm), and databases (MySQL, DynamoDB, Redis) • Hardware and embedded security experience including secure boot, firmware integrity, hardware root of trust, and IoT threat modeling • Experience in the financial industry with knowledge of PCI DSS and COPPA, or demonstrated ability to learn regulated domains quickly Nice to Have • Published security research, CVE discoveries, bug bounty results, or red-team engagements demonstrating offensive security expertise • Experience with Kali Linux and proficiency in Linux-based security tools and environments • Ability to influence without authority and mentor without managing; exceptional communication skills translating complex risks for engineers, product managers, legal, compliance, and executives Medical, dental, vision, and HSA match; paid life insurance, AD&D, and disability benefits; traditional 401k with company match; unlimited PTO; paid company holidays; professional development stipends; mental health resources; 1:1 financial planners; fertility healthcare; 100% paid parental and caregiving leave with cleaning service and meals; flexible work-from-home options; fully stocked kitchen and catered lunches