Tines

Tines

Tines is a smart, secure workflow builder that empowers technical teams to automate processes without code, making security teams more effective and efficient.

Construction & Engineering
51-250
Founded 2018
$96M raised

Description

  • Define and execute the product security strategy, roadmap, operating model, and success metrics.
  • Hire, manage, mentor, and develop product security engineers and build a high-performing team.
  • Partner with engineering, product, infrastructure, legal, compliance, and executive stakeholders on risk-based security decisions.
  • Establish secure software development practices, including security requirements, architecture reviews, threat modeling, testing, and remediation.
  • Use AI and automation for security reviews, vulnerability triage, risk identification, and agentic workflows.
  • Identify and mitigate risks in AI-powered products, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
  • Guide secure architectures and platform controls for cloud-native, multi-tenant products.
  • Own vulnerability management, disclosure, bug bounty submissions, remediation, and product security incident response.
  • Build secure-by-default developer tooling, automated controls, security education, and security champion programs.
  • Measure and communicate security effectiveness, risks, investments, progress, and tradeoffs to technical and executive audiences.

Requirements

  • 8+ years of experience in application security, product security, or related security engineering roles, including cloud-native SaaS security.
  • 5+ years of people management or technical leadership experience building security teams or programs.
  • Experience defining product security strategy, roadmaps, and risk-based investment priorities.
  • Strong foundation in application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
  • Experience using AI and automation for security, such as LLM-assisted code review, automated vulnerability triage, or agentic workflows.
  • Experience securing cloud environments, preferably AWS, and containerized infrastructure with Docker and Kubernetes.
  • Knowledge of modern programming languages; Ruby, TypeScript, and/or Rust experience is highly desirable.
  • Experience with SAST, DAST, SCA, secrets detection, CI/CD security integrations, DevSecOps, and secure developer workflows.
  • Experience leading product security incident response and operating vulnerability disclosure or bug bounty programs.
  • Preferred: Experience securing AI/ML and LLM-powered systems, LLM red-teaming, MITRE ATLAS, OWASP LLM guidance, Tines automation, multi-tenant SaaS, FedRAMP or DoD environments, and customer-facing security programs.
  • U.S. work authorization required; visa sponsorship is unavailable.

Benefits

  • Target annual compensation of $250,000–$275,000 plus equity.
  • Remote work available within the United States.
  • Opportunities for learning, growth, and career development.
  • Equal employment opportunities across legally protected characteristics.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
13 hours, 10 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
13 hours, 40 minutes ago

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
2 days, 13 hours ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
4 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers