Senior Product Security Engineer
Listed on 2026-05-09
-
IT/Tech
Cybersecurity, Systems Engineer
Greenlight is the leading family fintech company on a mission to help parents raise financially smart kids. We proudly serve more than 6 million parents and kids with our award-winning banking app for families. With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family’s future. Kids and teens learn to earn, save, spend wisely, and invest.
At Greenlight, we believe every child should have the opportunity to become financially healthy and happy. It’s no small task, and that’s why we leap out of bed every morning to come to work. Because creating a better, brighter future for the next generation depends on it.
We are seeking a seasoned and highly accomplished Senior Staff Product Security Engineer to join our security leadership team. This is a senior individual contributor role that carries significant organizational influence. You will define the technical vision for product security at Greenlight and set the standard for how we build and ship secure software. The ideal candidate brings deep, hands‑on expertise paired with the strategic mindset to drive large‑scale security initiatives from concept to production.
You will operate across the full breadth of our engineering organization, embedding security into every layer of our SDLC, shaping architecture decisions, and building the programs and processes that protect millions of families who trust us with their financial, location and personal data.
This role reports to the VP, Security GRC & Trust.
Technologies we use- Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI
- AWS, GCP
- MySQL, Dynamo
DB, Redis - Kubernetes, Ambassador, Helm, Rancher
- Define and lead the long-term product security strategy, roadmap, and vision in alignment with company goals, risk appetite, and regulatory requirements.
- Serve as the internal authority on application and product security, providing expert guidance to engineering, product, and executive leadership.
- Drive a company-wide culture of security ownership embedding security thinking deeply into the habits of every engineering team.
- Architect and continuously evolve a best-in‑class Product Security program, spanning threat modeling, SAST, DAST, IAST, SCA, runtime protection, and API security.
- Lead the design and enforcement of secure development standards across web, mobile, and cloud including secure coding guidelines, IaC policies, and API security frameworks.
- Identify and drive resolution of systemic, high-impact vulnerabilities and architectural security gaps across Greenlight's platform.
- Lead and mature Greenlight's penetration testing program, both through internal efforts and external vendor partnerships.
- Partner with engineering and platform teams to build security-enhancing product features that protect our customers' financial data.
- Establish and lead incident response processes for product-level security events, including root cause analysis and systemic remediation.
- Evaluate and introduce emerging security tooling, techniques, and frameworks to keep Greenlight ahead of the threat landscape.
- Mentor staff and senior engineers across the security and engineering organizations, raising the overall security engineering capability of the company.
- 12+ years of experience in product security, application security, or a related engineering discipline.
- Proven track record of defining and driving security programs at scale across complex, multi-platform environments.
- Hands‑on experience architecting and implementing security solutions and processes in production environments, enabling engineering teams to build and ship securely at scale.
- Expert‑level knowledge of web and mobile application security, including OWASP Top 10, API security, and mobile threat vectors (iOS and Android).
- Deep hands‑on experience with the full App Sec toolchain: SAST, DAST, IAST, SCA, secrets scanning, and runtime protection.
- Strong command of cloud security architecture and controls, particularly in AWS environments.
- Experience leading or heavily influencing the security architecture of distributed, microservices‑based systems.
- Experience in developing and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).