Senior Product Security Engineer II

2 days, 8 hours ago
Full-time
Senior
Cybersecurity
instacart.careers

instacart.careers

Instacart is a leading grocery technology company in North America that works with grocers and retailers to transform how people shop. They partner with over 1,000 national, regional, and local retail banners to facilitate online shopping, delivery, an...

Internet Software & Services
1K-5K

Description

  • Research, develop, and conduct offensive security techniques for a suite of Instacart products.
  • Design and conduct offensive security operations and engagements across product and internal tools.
  • Deploy and operationalize open-source and commercial security tools that can scale and be maintained long term.
  • Collaborate with engineering and product teams to integrate security testing into the SDLC.
  • Use threat modeling, security assessments, and architecture reviews to improve product security.
  • Scale the discovery of security defects and anti-patterns to improve Instacart’s security posture.
  • Share knowledge and mentor team members to support continuous learning and growth.
  • Produce written deliverables and technical documentation to align cross-functional teams on security objectives and plans.

Requirements

  • 7+ years of experience in Security Engineering or Penetration Testing with a strong understanding of product security concepts and principles.
  • Experience in mobile app penetration testing, AI security testing, or cloud penetration testing.
  • Experience with threat modeling, security assessments, product security concepts, and security architecture reviews.
  • Ability to make data-driven decisions and prioritize initiatives that improve key security metrics.
  • Ability to balance urgency with shipping high-quality, pragmatic solutions.
  • Strong self-management and organizational skills.
  • In-depth knowledge of remediation techniques for application vulnerabilities and the ability to explain them to product teams.
  • Ability to create written work products and detailed technical documents to drive alignment with cross-functional teams.
  • Bachelor’s degree in Computer Science, Engineering, Math, or related work experience (preferred).
  • Bug bounty research experience (preferred).

Benefits

  • Remote-first Flex First work policy with flexibility to work from home, an office, or another location.
  • Highly market-competitive compensation.
  • Base salary range of $230,000-$242,500 for CA, NY, CT, NJ; $220,000-$232,000 for WA; $211,000-$222,500 for certain other listed states; and $192,000-$202,500 for all other states.
  • Eligible for a new hire equity grant and annual refresh grants.
  • Access to Instacart benefits offerings.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a security engineering professional to help implement and operationalize application security tooling and practices across modern software development environments.

Azure Burp Suite CI/CD CircleCI GitHub Actions Jenkins
3 days, 8 hours ago

DevSecOps Lead

Workleap 251-1K Internet Software & Services

Workleap is hiring a DevSecOps Lead to embed security into its AI-enabled SDLC, CI/CD pipelines, and Azure-based product development workflows across its Workleap and ShareGate platforms.

Azure Bash C# CI/CD DevSecOps GitHub Actions .NET OAuth OpenID Connect Python SAML
6 days, 8 hours ago

Director, Product Management, Customer Security Outcomes

Zscaler 1K-5K Internet Software & Services

Zscaler is hiring a Director of Product Management for Customer Security Outcomes to lead the vision and strategy for its security operations services in a fully remote U.S. role.

Generative AI Machine Learning
1 week, 1 day ago

Senior Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its open source software delivery and cloud-native product stack, with ownership of secure pipelines, product hardening, and security architecture across the company.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
1 week, 2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers