Cleo

Cleo

Cleo is a global software company that simplifies supply chain connectivity and integration, offering solutions for managed file transfer, network fax, and interactive messaging activities.

Internet Software & Services
251-1K
Founded 1976
$4M raised

Description

  • Own and mature Cleo’s secure software development lifecycle, including security requirements, threat modeling, and high-risk design reviews.
  • Run and tune SAST, SCA, secrets, container, and infrastructure-as-code scanning across development pipelines.
  • Build secure patterns, reference implementations, and policy-as-code guardrails.
  • Lead developer security enablement through Security Champions, training, remediation guidance, office hours, and self-service tools.
  • Manage vulnerability triage, remediation SLAs, exceptions, exploit reproduction, patch validation, and penetration testing.
  • Run the Vulnerability Disclosure Program and coordinate CVE handling, researcher communications, and coordinated disclosure.
  • Own application and product-security controls for the NIST CSF 2.0 program and provide audit evidence.
  • Own the security posture and roadmap for SaaS and customer-hosted products, including authentication, RBAC, tenant isolation, secure defaults, and hardening.
  • Represent security in product planning, prioritize security features, and address customer findings, RFIs, advisories, and release notes.
  • Lead threat modeling and controls for LLM features, AI agents, and AI-assisted development workflows.‌

Requirements

  • 6+ years of experience in application security, product security, or secure software engineering, including building or maturing AppSec programs across multiple engineering teams.
  • Strong object-oriented programming skills; Java is preferred, with the ability to work in TypeScript, Python, or Go.
  • Deep knowledge of authentication, authorization, API security, business-logic flaws, and modern service architectures.
  • Hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines.
  • Experience reproducing exploits, validating patches, conducting manual security testing, and working directly with developers on remediation.
  • Experience with coordinated disclosure, external security researchers, customers, and CVE publication.
  • Experience securing shipped enterprise software, including secure defaults, customer advisories, release notes, and responses to scan reports or RFIs.
  • Strong communication skills, including translating technical risk for developers and executives and making release-gating decisions.
  • Experience with LLM, AI-agent, or AI-assisted development security is preferred.
  • Familiarity with SBOM, VEX, artifact signing, SLSA, AWS, Kubernetes/EKS, Terraform, Jenkins, security tools, NIST/OWASP frameworks, audits, relevant certifications, or SaaS/customer-hosted enterprise products is preferred.

Benefits

  • $160,000–$180,000 salary plus bonus opportunity.
  • Medical, dental, and vision coverage.
  • Flexible PTO and remote work environment.
  • 401(k) matching, FSA, and HSA options.
  • Employee Assistance Program and paid parental leave.
  • Supportive culture focused on work-life balance.
  • Opportunities for accelerated title and salary growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a Security Engineer to partner with engineering and product teams remotely, building secure-by-default systems and driving measurable application security outcomes.

AWS Docker GCP Go Java Kubernetes Python Ruby Terraform
2 days, 22 hours ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is seeking an Application Security Engineer to triage and validate vulnerability submissions across client bug bounty programs, communicate with researchers and customers, and escalate critical security incidents.

Burp Suite Nmap
1 week, 3 days ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices throughout product development.

CI/CD DevSecOps Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
1 week, 3 days ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native platform by embedding AI, application, cloud, and customer assurance controls throughout the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
1 week, 3 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers