← Back to results

Product Security Engineer

Join LaunchDarkly as a Product Security Engineer II to enhance platform security through threat modeling and cloud security posture.

Location
Remote - US West
Compensation
$116k–$187.7k/yr
Level
mid
Type
full time · Remote

Posted by employer 4 days ago

First seen on Joblaze 3 days ago

Last verified on the company career page 10 hours ago

What you'll build

  • Lead threat modeling engagements
  • Own day-to-day triage of CNAPP findings
  • Contribute to SDLC tooling
  • Partner with product engineering teams
  • Push the security floor up over time

Must have

  • 2 to 4 years of full-time experience in a security-focused role
  • Experience participating in or leading threat modeling exercises
  • Working knowledge of cloud security posture
  • Strong fundamentals: OWASP Top 10, authentication and authorization patterns

Nice to have

  • Experience with developer tools, SaaS platforms, or feature management
  • Bug bounty triage experience
  • Familiarity with Go, Python, or TypeScript
  • Contributions to internal security tooling or open-source security projects

AI in the day-to-day

Use AI to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil.

Requirements

Experience
2–4 years

Not disclosed in this posting: visa sponsorship.

Benefits

Equity/Stock Options Health Insurance

Joblaze summary

In the role of Product Security Engineer II at LaunchDarkly, the individual will focus on threat modeling and enhancing cloud security posture while collaborating closely with software engineers and product managers. Key skills include a solid understanding of security fundamentals, experience with threat modeling, and familiarity with cloud security tools. This position is ideal for someone with 2 to 4 years of experience in security roles, particularly in application or cloud security, who is proactive and values building strong partnerships within teams.

Joblaze insights

  • Listed 3 days ago — first seen on Joblaze September 19, 2026. Last confirmed on LaunchDarkly's careers page September 22, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 34% of 107 comparable mid security roles in United States we track (median $130,000 across 40 companies).
  • cloud security appears in 5.4% of 184 comparable mid security roles in United States; Threat Modeling appears in 0.5% of 184 comparable mid security roles in United States.

Quick facts

Is the Product Security Engineer role remote?
Yes — LaunchDarkly lists this as a fully remote position.
What's the salary range?
LaunchDarkly lists $116,000–$187,660 for this role.
How much experience is required?
2–4 years of relevant experience for this Product Security Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, Bug Bounty, SAST, SCA, Threat Modeling, cloud security.
What seniority level is this role?
LaunchDarkly targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer role at LaunchDarkly.

From the original posting

About the Job:

LaunchDarkly's Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You'll bring depth in security fundamentals and program design as a member of a small, high-leverage team with strong engineering instincts.

LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us. You'll spend most of your time on threat modeling and cloud security posture, with rotating exposure to the rest of the ProdSec surface area. Your work will help developers move fast without sacrificing security, through automation, guidance, and the kind of partnership that makes the secure path the easy one.

You'll report to the Director of Security and work closely with software engineers, product managers, and other security engineers. We expect you to bring a sharp point of view on where AI can take work off the team's plate and make our coverage deeper.

Responsibilities:

  • Lead threat modeling engagements on the features and services where the risk warrants it.

  • Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.

  • Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.

  • Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.

  • Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.

  • Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.

  • Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.

About You:

  • You're proactive by default. You'd rather spot drift early and fix the cause than chase symptoms after an incident.

  • You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.

  • You invest in relationships with the engineering, product, and leadership teams you work with.

  • You know security work moves at the speed of trust.

  • You're a good partner. You're helpful and direct, you say no with reasons and alternatives, and you don't mistake gatekeeping for rigor.

  • You're security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what's wrong with them.

  • You treat AI as part of the toolkit. You're skeptical where you should be, aggressive where it pays off, and you want to work somewhere that's serious about both.

Qualifications:

  • 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.

  • Comfortable reading and critiquing pull requests in a modern stack. You don't need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.

  • Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).

  • Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus.

  • Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations.

  • Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated.

Nice to Haves:

  • Experience with developer tools, SaaS platforms, or feature management

  • Bug bounty triage experience (HackerOne, Bugcrowd)

  • Familiarity with Go, Python, or TypeScript

  • Contributions to internal security tooling or open-source security projects

Pay:

Target pay ranges based on Geographic Zones* for Level 2:

  • Zone 1: San Francisco/Bay Area or NYC Metropolitan Area, Boston, Seattle - $136,500 - $187,660*
  • Zone 2: Irvine, LA, Monterey, Santa Barbara, Santa Rosa, Austin, Portland, Philadelphia, Chicago - $122,800 - $168,850**
  • Zone 3: All other US locations - $116,000 - $159,500 **

Do you need a disability accommodation?

Standard company text repeated across LaunchDarkly's postings is omitted here.

Similar positions

LaunchDarkly
Staff Engineer, Experience Engineering
LaunchDarkly · Remote - US
LaunchDarkly
LaunchDarkly
Staff Product Manager - Data Products
LaunchDarkly · Remote - US
LaunchDarkly
Senior Solutions Engineer
LaunchDarkly · Remote - US East
LaunchDarkly
Senior Solutions Architect, AI Focus
LaunchDarkly · Remote - US