← Back to results

Product Security Engineer

Join TRM Labs as a Product Security Engineer to lead application security initiatives and ensure the safety of our products.

Location
United States
Compensation
Not disclosed
Level
senior
Type
full time

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at TRM Labs → Save job Scanned from trmlabs.com

What you'll build

  • Lead application security reviews and threat modeling
  • Develop automated testing and mature our Secure SDLC
  • Own and perform application security vulnerability management
  • Coordinate penetration testing engagements
  • Develop and maintain the bug bounty program

Must have

  • Minimum 8 years of experience in Software Development and testing
  • BS (or equivalent) in Computer Science, Computer Engineering, or related field
  • Proficiency in software development languages: Python, NodeJS, React
  • Strong understanding of encryption, authentication, and authorization protocols
  • Deep experience with common software flaws and testing methodologies

Nice to have

  • Security certifications such as OSCP, CEH, GWAPT
  • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF)

Requirements

Experience
8+ years
Education
Bachelor's degree

Not disclosed in this posting: compensation, work arrangement, visa sponsorship.

Joblaze summary

In the role of Product Security Engineer at TRM Labs, the individual will focus on enhancing application security through threat modeling, secure code reviews, and vulnerability management. Key skills include proficiency in programming languages like Python and NodeJS, as well as experience with security tools and methodologies. This position is ideal for seasoned professionals with a strong background in software development and security practices, particularly those who thrive in fast-paced, mission-driven environments. The security team emphasizes collaboration and transparency, fostering a culture of security across the organization.

Joblaze insights

  • Listed yesterday — first seen on Joblaze October 3, 2026. Last confirmed on TRM Labs's careers page October 3, 2026.
  • Python appears in 39.7% of 330 comparable senior security roles in United States; OWASP appears in 0.3% of 330 comparable senior security roles in United States.

Quick facts

How much experience is required?
At least 8 years of relevant experience for this Product Security Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Burpsuite, GCP, NodeJS, OWASP, OWASP ZAP.
What seniority level is this role?
TRM Labs targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer role at TRM Labs.

From the original posting

About the Team

The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.

The impact you will have here:

  • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing

  • Develop automated testing and mature our Secure SDLC

  • Own and perform application security vulnerability management

  • Coordinate penetration testing engagements

  • Support software engineers and product teams by developing application security best practices

  • Develop and maintain the bug bounty program

  • Bootstrap platform security initiatives that help protect TRM data

  • Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.

What we’re looking for:

  • Minimum 8 years of experience in Software Development and testing.

  • BS (or equivalent) in Computer Science, Computer Engineering, or related field.

  • Proficiency in software development languages: Python, NodeJS, React

  • Strong understanding of encryption, authentication, and authorization protocols

  • Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.

  • Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.

  • Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis

  • Experience triaging and remediating vulnerabilities in software packages or libraries

  • Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools

  • Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.

  • Experience with Threat modeling tools such as OWASP Threat Dragon, etc.

  • Experience working in a previous agile-based software development role required

  • Experience Red Teaming or penetration testing applications and infrastructure

  • Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.

  • Strong written and verbal communication skills.

  • Security certifications such as OSCP, CEH, GWAPT are a plus.

  • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus

About the Team:

  • The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.

  • We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.

  • Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.

  • Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.

Team’s Time Zones:

  • Eastern Standard Time (EST - GMT-4)

  • Pacific Standard Time (PST - GMT-7)

  • Central European Summer Time (CET - GMT+2)

Learn about TRM Speed in this position:

  • Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.

  • Integrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.

  • Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.

  • Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.

  • Recruiter Intro: Explore your experience, motivations, and alignment with the role.

Learn more about interviewing at TRM

At TRM, you should expect:

  • Priorities and targets to change quickly as we experiment and iterate

  • Close collaboration across teams and functions

  • Frequent, high-touch communication

  • Creative problem solving and out-of-the-box thinking

 
  • Accelerate repeatable workflows

  • Structure and solve problems

  • Improve output quality

  • Increase speed and leverage

  • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

Standard company text repeated across TRM Labs's postings is omitted here.

Similar positions

TRM Labs
Account Director, National Security
TRM Labs · Washington DC
Saronic Technologies
Security Engineer, Application Security
Saronic Technologies · Austin, TX
Abnormal Security
Application Security Engineer II
Abnormal Security · Remote - USA
ARQ
Security Engineer, Lead
ARQ · São Paulo