×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer, Product Security

Job in Portland, Multnomah County, Oregon, 97204, USA
Listing for: GoodLeap
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 146000 - 185000 USD Yearly USD 146000.00 185000.00 YEAR
Job Description & How to Apply Below

About Good Leap:

Good Leap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on Good Leap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations.

Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.

Good Leap is also proud to support our award-winning nonprofit, Give Power, which is building and deploying life‑saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.

Good Leap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem.

You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.

Good Leap builds in Type Script, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer‑finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s "safe enough to launch" is core to this role.

You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.

Essential

Job Duties and Responsibilities
  • Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
  • Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of Type Script, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
  • Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
  • Review pull request vulnerability findings. Triage what scanning and AI‑assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high‑risk changes, and feed what you learn back into the tooling.
  • Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
  • Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
  • Keep the App Sec tooling estate running and low‑friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
  • Secure the infrastructure your tooling runs on. IAM…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary