Tines

Tines

Tines is a smart, secure workflow builder that empowers technical teams to automate processes without code, making security teams more effective and efficient.

Construction & Engineering
51-250
Founded 2018
$96M raised

Description

  • Define and execute the product security strategy, roadmap, operating model, and success metrics.
  • Hire, manage, mentor, and develop product security engineers and build a high-performing team.
  • Partner with engineering, product, infrastructure, legal, compliance, and executive stakeholders on risk-based security decisions.
  • Establish secure software development practices, including security requirements, architecture reviews, threat modeling, testing, and remediation.
  • Use AI and automation for security reviews, vulnerability triage, risk identification, and agentic workflows.
  • Identify and mitigate risks in AI-powered products, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
  • Guide secure architectures and platform controls for cloud-native, multi-tenant products.
  • Own vulnerability management, disclosure, bug bounty submissions, remediation, and product security incident response.
  • Build secure-by-default developer tooling, automated controls, security education, and security champion programs.
  • Measure and communicate security effectiveness, risks, investments, progress, and tradeoffs to technical and executive audiences.

Requirements

  • 8+ years of experience in application security, product security, or related security engineering roles, including cloud-native SaaS security.
  • 5+ years of people management or technical leadership experience building security teams or programs.
  • Experience defining product security strategy, roadmaps, and risk-based investment priorities.
  • Strong foundation in application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
  • Experience using AI and automation for security, such as LLM-assisted code review, automated vulnerability triage, or agentic workflows.
  • Experience securing cloud environments, preferably AWS, and containerized infrastructure with Docker and Kubernetes.
  • Knowledge of modern programming languages; Ruby, TypeScript, and/or Rust experience is highly desirable.
  • Experience with SAST, DAST, SCA, secrets detection, CI/CD security integrations, DevSecOps, and secure developer workflows.
  • Experience leading product security incident response and operating vulnerability disclosure or bug bounty programs.
  • Preferred: Experience securing AI/ML and LLM-powered systems, LLM red-teaming, MITRE ATLAS, OWASP LLM guidance, Tines automation, multi-tenant SaaS, FedRAMP or DoD environments, and customer-facing security programs.
  • U.S. work authorization required; visa sponsorship is unavailable.

Benefits

  • Target annual compensation of $250,000–$275,000 plus equity.
  • Remote work available within the United States.
  • Opportunities for learning, growth, and career development.
  • Equal employment opportunities across legally protected characteristics.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
1 day, 11 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
1 day, 12 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
2 days, 11 hours ago

Off-Cycle Fall 2026 Cybersecurity Internship

Galaxy 251-1K Capital Markets

Galaxy Digital is seeking a remote Cybersecurity Intern for its Product Security team to improve secure engineering standards and develop resources that help software and production engineers apply them effectively.

C++ Cybersecurity Python Rust
4 days, 12 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers