Auf einen Blick
- Aufgaben: Leite Sicherheitsarchitektur und Penetrationstests für innovative Finanzprodukte.
- Unternehmen: Greenlight, führendes Fintech-Unternehmen mit einer Mission für finanzielle Bildung.
- Vorteile: Umfassende Gesundheitsleistungen, unbegrenzter Urlaub und professionelle Entwicklungsmöglichkeiten.
- Weitere Informationen: Dynamisches Team mit Fokus auf Zusammenarbeit und persönlichem Wachstum.
- Warum dieser Job: Gestalte die Zukunft der finanziellen Bildung für Kinder und arbeite mit modernster Technologie.
- Qualifikationen: 10+ Jahre Erfahrung in Produktsicherheit und tiefes Wissen über KI-Sicherheit.
Das prognostizierte Gehalt liegt zwischen 165000 - 200000 € pro Jahr.
Greenlight is the leading family fintech company on a mission to help parents raise financially smart kids.
We proudly serve more than 6 million parents and kids with our award-winning banking app for families.
With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family’s future.
Kids and teens learn to earn, save, spend wisely, and invest.
At Greenlight, we believe every child should have the opportunity to become financially healthy and happy.
It’s no small task, and that’s why we leap out of bed every morning to come to work.
Because creating a better, brighter future for the next generation depends on it.
We are seeking an experienced and motivated
Staff Product Security Engineer to join our growing Security team.
This individual will be responsible for the end-to-end security of our consumer products, digital platform and an emerging hardware device line.
The Staff Product Security Engineer will drive security review, threat modeling programs, lead penetration testing, manage PSIRT operations, champion secure AI adoption and establish security guardrails for AI powered products and AI assisted development workflows within a highly regulated financial services environment.
This role reports to the Senior Manager of Product Security.
Your day-to-day
- Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA and attack tree methodologies.
- Translate threats into actionable, risk-rated engineering remediations prioritized by severity.
- Conduct hands‑on penetration testing and security assessments across our full product stack producing actionable reports for engineering and leadership.
- Red‑Team our AI powered products and development tools to test for prompt injection, data exfiltration, MCP server exploitation, and tool misuse.
Probe AI guardrails to ensure they hold.
Experience with product security tools such as Burp Suite, Metasploit, Kali Linux, Postman, etc.
- Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on‑call incidents.
This includes managing zero‑day findings, driving remediation, collaborating with engineering to patch or mitigate with compensating controls.
- Shape the posture of our AI assisted development environment defining and enforcing enterprise policies for claude and cursor.
- Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers and collaborating with the AI team on securing ML pipelines.
- Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products and ensuring every engineer understands that product security is an enabler and not a gate.
What you’ll bring to the team
- 10+ years of product security experience spanning application security, cloud security, and secure SDLC. you will have full SDLC experience from design through development, deployment and incident response.
- Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded and AI systems.
- Hands‑on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware.
You think like an attacker and you can provide it through published research, CVE discoveries, bug bounty results or red‑team engagements.
- PSIRT operational experience from vulnerability intake and triage. You are fluent in CVE, CVSS, FIRST PSIRT frameworks.
- Deep hands down AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile and have practical experience with MITRE.
- Strong hands‑on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor.
- You understand MCP security risks and know how to architect enterprise guardrails that enable safe AI‑assisted development.
You have defined policies for AI generated code, secrets scanning, and DLP for outbound AI traffic.
- Strong programming ability and capability to review code, build security tools, automate workflows and be credible with the engineering teams you partner with.
- Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications.
- Strong knowledge of programing language & frameworks (i. e.
Node. js, Java/Kotlin, React, Redux, Swift, Swift UI), cloud technologies and infrastructure (i. e.
AWS, GCP, Kubernetes, Ambassador, Helm), and databases (i. e.
- My SQL, Dynamo DB, Redis)
- Ability to influence without authority, mentor without managing, and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance and executives alike.
Preferred experience
- Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and Io T threat modeling experience.
- Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly.
Work perks at Greenlight
- Medical, dental, vision, and HSA match
- Paid life insurance, AD&D, and disability benefits
- Traditional 401k with company match
- Unlimited PTO
- Paid company holidays and pop‑up bonus holidays
- Professional development stipends
- Mental health resources
- 1:1 financial planners
- Fertility healthcare
- 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
- Flexible WFH, both remote and in‑office opportunities
- Fully stocked kitchen, catered lunches, and occasional in‑office happy hours
- Employee resource groups
Our stance on salaries
Greenlight provides a competitive compensation package with a market‑based approach to pay and will vary depending on your location, experience and skill set.
The total compensation package for this position will also include a discretionary performance bonus, equity rewards, medical benefits, 401K match, and more.
Greenlight conducts continuous compensation evaluations across departments and geographies to ensure we are keeping our pay current and competitive.
- The estimated base pay range for this position in (NY, CA, WA): $165,000-200,000
- The estimated base pay range for this position in (CO): $165,000-185,000
Who we are
It takes a special team to aim for a never‑been‑done‑before mission like ours.
We’re looking for people who love working together because they know it makes us stronger, people who look to others and ask, “How can I help?” and then “How can we make this even better?” If you’re ready to roll up your sleeves and help create a world where every child grows up to be happy and healthy in money and life, apply to join our team.
Greenlight is an equal opportunity employer and will not discriminate against any employee or applicant based on age, race, color, national origin, gender, gender identity or expression, sexual orientation, religion, physical or mental disability, medical condition (including pregnancy, childbirth, or a medical condition related to pregnancy or childbirth), genetic information, marital status, veteran status, or any other characteristic protected by federal, state or local law.
Greenlight is committed to an inclusive work environment and interview experience.
If you require reasonable accommodations to participate in our hiring process, please reach out to your recruiter directly or email accomodations@greenlight. me.
#J-18808-Ljbffr
Staff Product Security Engineer Arbeitgeber: Greenlight Financial Technology
Greenlight ist ein hervorragender Arbeitgeber, der kreative Talente in einem dynamischen Umfeld fördert. Mit einem starken Fokus auf Mitarbeiterentwicklung und einer positiven Unternehmenskultur bietet das Unternehmen umfassende Vorteile wie unbegrenzten Urlaub, flexible Arbeitsmöglichkeiten und Unterstützung für die mentale Gesundheit. Hier haben Sie die Möglichkeit, Ihre kreativen Ideen zu verwirklichen und einen bedeutenden Einfluss auf Familien zu haben, während Sie Teil eines engagierten Teams sind, das Innovation und Zusammenarbeit schätzt.
Kontaktdaten:
Greenlight Financial Technology Recruiting-Team
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Staff Product Security Engineer erhalten könntest
✨Engagier dich in Entwickler-Communities!
Lass uns mal ehrlich sein: In der Software-Entwicklung sind Netzwerke Gold wert! Tummel dich in GitHub-Projekten, nehme an lokalen Meetups oder Hackathons teil und vernetze dich mit anderen Entwicklern. So steigerst du nicht nur deine Sichtbarkeit, sondern lernst auch die neuesten Trends und Technologien kennen.
✨Zeig deine Fähigkeiten!
Erstelle ein Portfolio, das deine besten Projekte und Code-Examples zeigt. Nichts überzeugt mehr als ein praktischer Beweis deiner Skills. Das kann auch helfen, bei Greenlight Financial Technology anzuklopfen, wenn du dich auf die Stelle als Staff Product Security Engineer bewirbst – so wissen sie gleich, was sie von dir erwarten können!
✨Nutze Jobplattformen speziell für Tech-Jobs!
Plattformen wie Stack Overflow Jobs oder AngelsList sind perfekte Orte, um Vollzeitstellen in der Software-Entwicklung zu finden. Hier sind viele tolle Unternehmen auf der Suche nach Talenten wie uns, also schau regelmäßig vorbei und bewirb dich direkt über die Website.
✨Such dir Mentoren und Feedback!
Hol dir Feedback von erfahrenen Entwicklern, die dir Tipps geben können, was Recruiter wirklich suchen. Ob über LinkedIn oder persönliche Kontakte: Menschen, die sich in der Branche auskennen, können enorm wertvoll sein, um dir zu helfen, dich optimal auf deine Bewerbung bei Greenlight Financial Technology vorzubereiten!
Wir glauben, dass du diese Fähigkeiten brauchst, um Staff Product Security Engineer mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Highlights deiner Coding-Skills:In der Software-Entwicklung kommt es auf konkrete Fähigkeiten an. Vergiss nicht, relevante Programmiersprachen und Frameworks in deinen Lebenslauf aufzunehmen. Zeig uns, was du kannst – vielleicht mit einem Link zu deinem GitHub-Profil oder einer Übersicht deiner Side Projects, die deine Programmierkenntnisse illustrieren.
Dokumentation deiner Erfolge:Gerade bei einer Vollzeitstelle in der Software-Entwicklung sind konkrete Ergebnisse Gold wert. Nenn uns Zahlen und Ergebnisse aus deinen vorherigen Projekten. Hast du den Code optimiert oder Systemfehler behoben? Solche Erfolge zeigen, dass du die Sprache der Entwickler sprichst und einen echten Mehrwert bringst.
Attraktive Projektbeschreibungen:Wenn du an Projekten gearbeitet hast, die hervorstechen, beschreibe sie ausführlich in deinem Lebenslauf. Was war das Problem, das du gelöst hast? Welche Technologien hast du eingesetzt? Das gibt uns einen klaren Einblick in deine Herangehensweise und Problemlösungsfähigkeiten.
Motivation zeigen:In deinem Anschreiben solltest du deine Motivation für die Stelle im Bereich Software-Entwicklung bei Greenlight Financial Technology klar herausstellen. Warum sprichst gerade du die Anforderungen für diese Vollzeitrolle an? Mach deutlich, was dich an der Arbeit bei uns reizt und wie du über das rein Technische hinaus wachsen möchtest.
Wie man sich auf ein Vorstellungsgespräch bei Greenlight Financial Technology vorbereitet
✨Technische Vorbereitung auf die Coding-Challenges
In der Software-Entwicklung sind technische Fragen oft ein zentraler Teil des Interviews. Macht euch mit Plattformen wie LeetCode oder HackerRank vertraut, um eure Problemlösungsfähigkeiten zu trainieren. Zeigt im Interview viel Selbstbewusstsein beim Erklären eurer Ansätze!
✨Das eigene Portfolio im besten Licht präsentieren
Stellt sicher, dass ihr ein aussagekräftiges Portfolio habt, das einige eurer besten Projekte zeigt. Seid bereit, darüber zu sprechen, was eure Rolle war, welche Technologien ihr verwendet habt und welche Herausforderungen es gab. Das gibt den Interviewern einen Einblick in eure praktische Erfahrung.
✨Teamfähigkeit und Kommunikation betonen
In einer Vollzeit-Position wird Kommunikation im Team sehr wichtig sein. Seid bereit, Beispiele aus der Vergangenheit zu teilen, in denen ihr effektiv im Team gearbeitet habt. Dies zeigt, dass ihr nicht nur technische Fähigkeiten habt, sondern auch gut ins Team passt.
✨Vorbereitung auf Fragen zur Software-Architektur
Bereitet euch darauf vor, Fragen zur Software-Architektur zu beantworten. Themen wie RESTful APIs, Microservices und Cloud-Architekturen können Teil eures Interviews sein. Zeigt euer Verständnis durch Diskussionen und Beispiele aus eurer bisherigen Arbeit oder Projekte.