Staff Product Security Engineer
greenlight
| Company | greenlight |
| Category | Engineering |
| Location | Atlanta |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 25 Jun 2026 |
| Last verified | 12 Aug 2026 |
| Source | The employer's own careers page (company_site) |
Description
Greenlight is a family fintech company serving over 6 million parents and kids with a banking app. This Staff Product Security Engineer role owns end-to-end security of consumer products, digital platforms, and emerging hardware devices, with a focus on threat modeling, penetration testing, PSIRT operations, and secure AI adoption within a regulated financial services environment.
What You'll Do
• Lead security architecture and design review sessions using STRIDE, PASTA, and attack tree methodologies; translate identified threats into actionable, risk-rated engineering remediations
• Conduct hands-on penetration testing and security assessments across the full product stack, including red-teaming AI-powered products and development tools for prompt injection, data exfiltration, and guardrail bypasses
• Drive PSIRT operations: triage vulnerability reports, lead technical investigations, coordinate remediation with engineering, score severity using CVSS, manage coordinated disclosure, and handle zero-day findings
• Define and enforce enterprise policies for AI-assisted development environments, including guardrails for Claude and Cursor; architect MCP security controls and policies for AI-generated code and secrets scanning
• Partner cross-functionally with architects, product managers, and engineering teams on security and compliance implications of new features; mentor junior security engineers and champion security culture through developer training on secure coding
What You Need
• 10+ years of product security experience spanning application security, cloud security, and secure SDLC across web, mobile, cloud, embedded systems, and AI
• Expert-level threat modeling using STRIDE, PASTA, or equivalent methodologies; hands-on penetration testing skills across applications, APIs, cloud infrastructure, and hardware/firmware
• PSIRT operational experience including vulnerability intake, triage, CVE/CVSS fluency, and FIRST PSIRT framework knowledge
• Deep AI security expertise with expert-level understanding of OWASP Top 10 for LLM, API, Web, Mobile, and practical MITRE experience; hands-on experience with SAST, DAST, SCA tools and AI development tool security (Claude, Cursor)
• Strong programming ability and code review capability; deep technical knowledge of CI/CD pipelines, programming languages and frameworks (Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies (AWS, GCP, Kubernetes, Ambassador, Helm), and databases (MySQL, DynamoDB, Redis)
• Hardware and embedded security experience including secure boot, firmware integrity, hardware root of trust, and IoT threat modeling
• Experience in the financial industry with knowledge of PCI DSS and COPPA, or demonstrated ability to learn regulated domains quickly
Nice to Have
• Published security research, CVE discoveries, bug bounty results, or red-team engagements demonstrating offensive security expertise
• Experience with Kali Linux and proficiency in Linux-based security tools and environments
• Ability to influence without authority and mentor without managing; exceptional communication skills translating complex risks for engineers, product managers, legal, compliance, and executives
Medical, dental, vision, and HSA match; paid life insurance, AD&D, and disability benefits; traditional 401k with company match; unlimited PTO; paid company holidays; professional development stipends; mental health resources; 1:1 financial planners; fertility healthcare; 100% paid parental and caregiving leave with cleaning service and meals; flexible work-from-home options; fully stocked kitchen and catered lunches