Paranoids Senior Product Security Engineer
Listed on 2026-08-09
-
IT/Tech
Cybersecurity
Paranoids Senior Product Security Engineer (Finance)
Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.
A Little About UsWhen you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".
Within the Paranoids, the Product Security team is on the front line - embedded directly in how Yahoo's products get built. We live inside the software development lifecycle, from the first line of code to production, hunting for weaknesses before an adversary can. Threat Modeling, Static and Dynamic reviews, architecture review, bug bounty - this is where security meets engineering, and where we make sure "shipping fast" and "shipping safe" are never a tradeoff.
ALot About You
As a Paranoids Product Security Engineer, you have the opportunity to guide secure development for a product area and in addition, own and drive secure development initiatives affecting the overall enterprise.
Responsibilities- Independently lead application and mobile security assessments, from design to deployment, for key enterprise products.
- Drive threat modeling and risk assessments for high-impact systems, guiding engineering teams through secure design trade-offs.
- Partner with developers to embed security into build and release pipelines, and identify opportunities for automation.
- Develop and maintain internal security tooling and reusable frameworks to scale security across teams.
- Lead the remediation of critical vulnerabilities and help coordinate with incident response when needed.
- Mentor other security engineers and advocate for secure development practices across product and engineering teams.
- Collaborate cross-functionally with cloud security, infrastructure, and compliance teams to ensure holistic protection of applications and data.
- Stay informed on emerging threats, frameworks, and technologies, and proactively improve security posture through innovation.
- 5+ years of experience in application or product security, with demonstrated impact securing large-scale web and/or mobile applications.
- Deep understanding of secure application architecture, including authentication, authorization, encryption, and data protection across distributed systems.
- Proven hands-on experience performing threat modeling, secure design reviews, and code assessments for complex applications and APIs.
- Strong technical knowledge of web technologies (HTTP, TLS, CSP, cookies, OAuth, JWTs, GraphQL, REST APIs) and mobile security (iOS/Android app security models, keychains, secure storage, code obfuscation).
- Proficiency using and integrating application security tooling (SAST, DAST, IAST, dependency scanning, container scanning) into CI/CD pipelines.
- Practical experience with vulnerability triage and remediation workflows - coordinating across engineering teams to ensure timely fixes.
- Hands-on skills in at least one backend or systems programming language (e.g., Go, Java, Python, C#) and one frontend or mobile language (e.g., JavaScript/Type Script, Swift, Kotlin).
- Experience contributing to or automating security testing and validation in continuous integration environments.
- Strong ability to communicate security risks and solutions clearly to engineers, managers, and non-technical stakeholders.
- Track record of driving security improvements across teams - through frameworks, documentation, training, or developer engagement.
- Working knowledge of AI/LLM application security fundamentals - including prompt injection, insecure output handling, sensitive data exposure through model inputs/outputs, and the OWASP Top 10 for LLM Applications.
- Experience reviewing applications that integrate LLMs or AI services, with the ability to identify common risks across AI pipelines (RAG, agentic tools, model…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).