Senior Product Security Engineer
Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation—collapsing the stack and giving IT & security time and control back. Backed by top investors like General Catalyst, Tiger Global, and Felicis, Iru raised $100 million in July 2024 and serves customers including Cursor, Vercel, and Replit.
About the role
We're seeking a highly technical Senior Product Security Engineer to embed security into the product development lifecycle. This hands-on engineering role is responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure-by-design products. You’ll collaborate with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to integrate security throughout the SDLC while enabling developer velocity.
Responsibilities
- Application Security
- Perform security design and architecture reviews for new products and features.
- Conduct threat modeling for applications, APIs, and AI-enabled services.
- Review application security posture throughout the SDLC.
- Partner with engineering teams to prioritize and remediate vulnerabilities.
- Review authentication, authorization, and access control implementations.
- Security Testing
- Perform manual web, API, thick-client, and mobile application penetration testing.
- Validate findings from third-party penetration tests.
- Conduct secure code reviews.
- Verify remediation of security vulnerabilities.
- Secure Development
- Drive adoption of secure coding practices.
- Partner with developers to improve security throughout the SDLC.
- Help define Product Security standards and engineering guardrails.
- Develop reusable security patterns and reference architectures.
- Vulnerability Management
- Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
- Work with engineering teams to prioritize remediation.
- Track remediation SLAs and security metrics.
- AI Security
- Assess AI-enabled products for security risks.
- Review LLM integrations and AI workflows.
- Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
- Help define secure AI engineering standards.
- Security Automation
- Improve automation of security testing throughout CI/CD.
- Integrate security tooling into developer workflows.
- Build scripts and tooling that reduce manual security work.
- Cross-functional Partnership
- Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
- Support customer security questionnaires related to product security.
- Assist Sales Engineering with security discussions when needed.
Qualifications
- 5+ years in Product Security or Application Security.
- Strong understanding of modern application architectures.
- Experience securing:
- Web applications
- APIs
- Microservices
- Cloud-native applications
- Experience performing threat modeling.
- Experience conducting penetration testing.
- Strong understanding of:
- OWASP Top 10
- OWASP API Top 10
- Authentication & Authorization
- OAuth / OIDC
- Secure SDLC
- Experience with SAST, DAST, SCA, and container security.
- Experience partnering directly with engineering teams.
- Strong written and verbal communication skills.
Preferred Skills
- Experience securing AI/LLM applications.
- Experience with Kubernetes and containers.
- Familiarity with cloud security (AWS, Azure, or GCP).
- Experience with GitHub Actions or CI/CD security.
- Experience using:
- Snyk
- Burp Suite Pro
- Semgrep
- Wiz
- GitHub Advanced Security
- Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus.
What Success Looks Like
Within your first 12 months, you'll:
- Embed security into engineering workflows without slowing development.
- Improve vulnerability remediation timelines.
- Increase adoption of secure design reviews and threat modeling.
- Expand automated security testing across products.
- Help mature Iru's AI Security program.
- Strengthen Product Security standards and developer enablement.
- Build strong partnerships with engineering teams and become a trusted security advisor.
Benefits
- Competitive salary
- Hybrid work environment (3 days in office per week)
- 100% individual and dependent medical + dental + vision coverage
- 401(K) with a 4% company match
- 20 days PTO
- Iru Wellness Week the first week in July
- Equity for full-time employees
- In-office lunch stipend
- Up to 16 weeks of paid leave for new parents
- Paid Family and Medical Leave
- Modern Health mental health benefits for individuals and dependents
- Fertility benefits
- Working Advantage employee discounts
- Onsite fitness center
- Free parking
- Exciting opportunities for career growth