LaunchDarkly logo

LaunchDarkly

Product Security Engineer

Region Restricted

Remote work allowed only within certain countries or regions.

Employer listed it 6 days ago · Added 5 days ago

First listed 6 days ago and still open.

Salary

$136,500 to $187,660

Location

Timezone

Not stated

Contract

Full-time

Experience

Mid

Category

Software

Stated by the employer in the job description

Remote flexibility

Region Restricted

Remote work is allowed, but the listing limits candidates to Remote - US West.

What the employer says

  • Source listing states candidate location: "Remote - US West"

What Nomaders makes of it

  • Nomaders could not match this to a wider region
  • Check the original posting

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About the Job:

LaunchDarkly's Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You'll bring depth in security fundamentals and program design as a member of a small, high-leverage team with strong engineering instincts.

LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us. You'll spend most of your time on threat modeling and cloud security posture, with rotating exposure to the rest of the ProdSec surface area. Your work will help developers move fast without sacrificing security, through automation, guidance, and the kind of partnership that makes the secure path the easy one.

You'll report to the Director of Security and work closely with software engineers, product managers, and other security engineers. We expect you to bring a sharp point of view on where AI can take work off the team's plate and make our coverage deeper.

Responsibilities:

Lead threat modeling engagements on the features and services where the risk warrants it.

Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.

Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.

Contribute to SDLC tooling, SAST / SCA workflows, and bug bounty triage as the team's work demands.

Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.

Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.

Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.

About You:

You're proactive by default. You'd rather spot drift early and fix the cause than chase symptoms after an incident.

You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.

You invest in relationships with the engineering, product, and leadership teams you work with.

You know security work moves at the speed of trust.

You're a good partner. You're helpful and direct, you say no with reasons and alternatives, and you don't mistake gatekeeping for rigor.

You're security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what's wrong with them.

You treat AI as part of the toolkit. You're skeptical where you should be, aggressive where it pays off, and you want to work somewhere that's serious about both.

Qualifications:

2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.

Comfortable reading and critiquing pull requests in a modern stack. You don't need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.

Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).

Requirements

  • ·You're proactive by default. You'd rather spot drift early and fix the cause than chase symptoms after an incident.
  • ·You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.
  • ·You invest in relationships with the engineering, product, and leadership teams you work with.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at LaunchDarkly, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$136,500 to $187,660 · You'll be taken to the employer's careers page.