WorkOS
Product Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 13h ago · Found 2h ago
First listed today.
Salary
$175,000 to $275,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States & Canada, Remote"
- Job description states: "US Only"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About WorkOS 🚀
WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations. We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Sierra, and Plaid. As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.
About the Security team
The Security team at WorkOS is responsible for keeping the data and identities of hundreds of millions of users secure. Security is fundamental to our products, and customer trust is the foundation of our success.
We are a highly collaborative group with a strong engineering mindset. Our security program is shaped by hands-on experience attacking and defending systems, and applying lessons from across the industry. We embrace the latest advancements in practices and tooling that make modern security teams effective.
We are comfortable in code and collaborate often with engineering to create products that are secure by default.
Who we’re looking for
Risk-focused and pragmatic. You excel at identifying and reasoning about security risk in real-world contexts. You prioritize ruthlessly, always asking: what's the most effective way to reduce risk right now and in the long term?
A builder who can break things. You're comfortable reading and writing code, and you have a passion for deeply understanding the products you secure. You think like an attacker to find subtle, high impact vulnerabilities and like a defender to design pragmatic, effective mitigations.
A strong partner to engineering. You build trust with engineers by understanding their priorities, making security frictionless, and finding ways to make the secure path, the easiest path.
Excited about AI. You're embracing AI and automation to scale security and reduce toil.
Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.
Responsibilities
Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.
Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.
Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.
Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.
Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.
Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.
Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.
Qualifications
5+ years of experience in a security engineering or security-focused software engineering role.
Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
Familiarity with and experience using common industry tooling.
Requirements
- ·5+ years of experience in a security engineering or security-focused software engineering role.
- ·Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
- ·Familiarity with and experience using common industry tooling.
- ·Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.
- ·Strong written and verbal communication skills, particularly in partnering with engineering teams.
Benefits
- ·Competitive Equity
- ·Healthcare, dental and vision coverage
- ·FSA, ST/LT Disability, Voluntary Life
- ·Carrot fertility benefits
- ·20 days paid vacation + 10 holidays + unlimited sick leave
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at WorkOS, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 3h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$175,000 to $275,000 · You'll be taken to the employer's careers page.