Join WorkOS as a Product Security Engineer to lead secure design efforts and enhance security tooling in a fully remote environment.
Posted by employer 6 days ago
First seen on Joblaze 5 days ago
Last verified on the company career page 20 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
AI in the day-to-day
You're embracing AI and automation to scale security and reduce toil.
Requirements
Not disclosed in this posting: compensation, visa sponsorship.
Benefits
Joblaze summary
In the role of Product Security Engineer at WorkOS, the individual will focus on enhancing the security of the company's developer tools and APIs by conducting security assessments, penetration testing, and collaborating with engineering teams on secure design practices. Key skills include a strong coding background, familiarity with security tooling, and the ability to identify vulnerabilities effectively. This position is ideal for someone with over five years of experience in security engineering who can balance risk management with practical solutions. The security team emphasizes collaboration and innovation, particularly in the context of AI advancements.
Joblaze insights
Quick facts
From the original posting
About WorkOS 🚀
About the Security team
The Security team at WorkOS is responsible for keeping the data and identities of hundreds of millions of users secure. Security is fundamental to our products, and customer trust is the foundation of our success.
We are a highly collaborative group with a strong engineering mindset. Our security program is shaped by hands-on experience attacking and defending systems, and applying lessons from across the industry. We embrace the latest advancements in practices and tooling that make modern security teams effective.
We are comfortable in code and collaborate often with engineering to create products that are secure by default.
Who we’re looking for
Risk-focused and pragmatic. You excel at identifying and reasoning about security risk in real-world contexts. You prioritize ruthlessly, always asking: what's the most effective way to reduce risk right now and in the long term?
A builder who can break things. You're comfortable reading and writing code, and you have a passion for deeply understanding the products you secure. You think like an attacker to find subtle, high impact vulnerabilities and like a defender to design pragmatic, effective mitigations.
A strong partner to engineering. You build trust with engineers by understanding their priorities, making security frictionless, and finding ways to make the secure path, the easiest path.
Excited about AI. You're embracing AI and automation to scale security and reduce toil.
Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.
Responsibilities
Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.
Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.
Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.
Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.
Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.
Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.
Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.
Qualifications
5+ years of experience in a security engineering or security-focused software engineering role.
Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
Familiarity with and experience using common industry tooling.
Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.
Strong written and verbal communication skills, particularly in partnering with engineering teams.
Comfortable reading and writing code, and able to effectively leverage AI during the process.
Bonus: Experience in the authentication and identity domain.
Bonus: Experience writing production level code, especially developing security features.
Benefits and Perks (US Only) 💖
401k matching
Competitive Equity
Healthcare, dental and vision coverage
FSA, ST/LT Disability, Voluntary Life
Carrot fertility benefits
12 weeks fully paid parental leave
Commuter benefits for hybrid employees in SF/NYC
Unlimited token usage!
Standard company text repeated across WorkOS's postings is omitted here.