×
Register Here to Apply for Jobs or Post Jobs. X

Senior Product Security Engineer

Job in Washington, District of Columbia, 20022, USA
Listing for: Kandji
Full Time, Contract position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 180000 USD Yearly USD 140000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Senior Product Security Engineer (Contract)

About Iru

Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation—collapsing the stack and giving IT & security time and control back.

Iru is backed by some of the smartest investors in tech—General Catalyst, Tiger Global, Felicis, Greycroft, and First Round Capital. In July 2024, Iru raised $100 million from General Catalyst, valuing the company at $850 million. Customers include Cursor, Vercel, Lovable, Replit, and Mercor, and Iru partners with industry leaders such as Service Now and AWS. Iru was named to Forbes’ America’s Best Startup Employers 2025 list for employee engagement and satisfaction.

The

Opportunity

We're seeking a highly technical Senior Product Security Engineer for a 6-month contract (40 hours/week) to embed security into the product development lifecycle. This is a hands‑on engineering role responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure‑by‑design products.

This role will work closely with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to ensure security is integrated throughout the SDLC while enabling developer velocity.

What You’ll Do Application Security
  • Perform security design and architecture reviews for new products and features.
  • Conduct threat modeling for applications, APIs, and AI-enabled services.
  • Review application security posture throughout the SDLC.
  • Partner with engineering teams to prioritize and remediate vulnerabilities.
  • Review authentication, authorization, and access control implementations.
Security Testing
  • Perform manual web, API, thick-client, and mobile application penetration testing.
  • Validate findings from third-party penetration tests.
  • Conduct secure code reviews.
  • Verify remediation of security vulnerabilities.
Secure Development
  • Drive adoption of secure coding practices.
  • Partner with developers to improve security throughout the SDLC.
  • Help define Product Security standards and engineering guardrails.
  • Develop reusable security patterns and reference architectures.
Vulnerability Management
  • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
  • Work with engineering teams to prioritize remediation.
  • Track remediation SLAs and security metrics.
AI Security
  • Assess AI-enabled products for security risks.
  • Review LLM integrations and AI workflows.
  • Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
  • Help define secure AI engineering standards.
Security Automation
  • Improve automation of security testing throughout CI/CD.
  • Integrate security tooling into developer workflows.
  • Build scripts and tooling that reduce manual security work.
Cross-functional Partnership
  • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
  • Support customer security questionnaires related to product security.
  • Assist Sales Engineering with security discussions when needed.
Qualifications
  • 5+ years in Product Security or Application Security.
  • Strong understanding of modern application architectures.
  • Experience securing:
  • Web applications
  • APIs
  • Microservices
  • Cloud-native applications
  • Experience performing threat modeling.
  • Experience conducting penetration testing.
  • Strong understanding of:
  • OWASP Top 10
  • OWASP API Top 10
  • Authentication & Authorization
  • OAuth / OIDC
  • Secure SDLC
  • Experience with SAST, DAST, SCA, and container security.
  • Experience partnering directly with engineering teams.
  • Strong written and verbal communication skills.
Preferred
  • Exper…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary