Product Security Engineer
Job Description
Work as a hands-on Product Security Engineer to make secure outcomes the default across the codebase and delivery workflow.
Responsibilities
- Identify systemic security gaps in the codebase and engineering workflows, then partner with engineering teams to design and ship durable fixes
- Build security tooling, automation, and code-level controls that address vulnerability classes (for example: custom linters, static analysis rules, and automated checks)
- Conduct in-depth code reviews and security design reviews for major product initiatives, engaging on architectural tradeoffs rather than only flagging issues
- Drive threat modeling and security assessments for new features, translating security requirements into practical engineering guidance
- Help evolve the team’s security approach as AI-assisted development scales internally, including how higher-volume code production affects risk discovery, prioritization, and remediation
- Triaging and tracking vulnerabilities with product engineering teams, and contribute to penetration testing and bug bounty programs
Requirements
- 5+ years of hands-on application security and security engineering experience (built security solutions, not mainly consulting, audit, or compliance work)
- Ability to operate independently with strong judgment in a fast-moving environment, including knowing when to move quickly, when to slow down, and when to escalate or request help
- Communication style that earns trust, making security legible to engineers without being preachy, and measuring impact by business support rather than issue volume
- Proven track record shipping security tooling or automation that improved outcomes for more than one team
- Deep engineering capability to read, reason about, and review code to find real bugs and understand root causes
- Comfort working with TypeScript and Python (Retool platform is TypeScript; security tooling leverages Python)
- Strong AppSec fundamentals including threat modeling and secure code review, plus a practical understanding of common vulnerability classes and how to address them durably
- Pragmatic approach to AI tooling: use it where it improves results, remain skeptical where it does not, and consider how developer-side AI adoption compounds security risk at scale
Technologies
- TypeScript
- Python
Benefits
- Comprehensive benefit plan including medical, dental, vision, and 401(k)
- Generous benefits for all employees and hybrid work location
Nice to Have
- Offensive security experience such as bug bounty, CTF participation, redteam, or pentesting
- Experience building or contributing to SAST pipelines, custom static analysis rules, or automated security testing infrastructure
- Prior experience at a startup or high-growth scaleup where security programs are not fully predefined and priorities change
Location and Salary
- Location: San Francisco, CA (hybrid)
- Salary: USD 231,900 - 318,250 per year (base salary range for non-commissionable roles or on-target earnings for commissionable roles)
- Additional compensation: equity and/or commission may apply depending on the position offered
- Eligibility notes: Retool is set up to employ roles in the US and specific roles in the UK