Full Stack Security Engineer (Application & Product)
- Company
- Runpod
- Location
- Remote
- Work type
- Full Time
- Posted
- 2026-08-10
Job description
Responsibilities:
Product Security: Lead threat modeling, architecture reviews, and code reviews for our web applications, APIs, and microservices.
Vulnerability Remediation: Actively develop and commit code to fix security flaws in our Python, Go, or JavaScript/TypeScript codebases alongside the engineering team.
DevSecOps: Implement, tune, and manage security testing tools (SAST, DAST, SCA) within our CI/CD pipelines to catch vulnerabilities early in the SDLC.
Edge & Application Defense: Configure and manage application-layer security controls, including Web Application Firewalls (WAF), bot protection, and API gateways.
Security Championing: Provide security guidance, secure coding training, and standard operating procedures to development teams.
Compliance & Operations: Collaborate with operations to ensure product-level adherence to relevant frameworks (e.g., SOC 2, ISO 27001, GDPR) and participate in bug bounty triage.
Required Qualifications:
5+ years of experience in application security, product security, or as a software engineer with a heavy security focus.
Strong programming and code-review skills in languages like Python, Go, JavaScript/TypeScript, or similar modern stacks.
Deep understanding of web application vulnerabilities (OWASP Top 10), API security (REST/GraphQL), and modern authentication flows (OAuth, OIDC, JWT).
Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP).
Experience building and maintaining automated security pipelines (DevSecOps).
Ability to translate complex security risks into actionable engineering tasks.
Preferred Qualifications:
Relevant application security certifications (e.g., OSWE, GWAPT, CISSP).
Experience securing cloud-native applications running on Kubernetes/Docker environments.
Background in managing bug bounty programs or coordinated vulnerability disclosures.
What You’ll Receive:
The competitive base pay for this position ranges from ($152,000 - $175,000). This salary range may be inclusive of several career levels at Runpod and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location
Meaningful equity in a fast-growing company- everyone on the team receives stock options — your impact drives our growth, and you share in the upside.
Generous medical, dental & vision plans
Flexible PTO- take the time you need to recharge
Most roles are remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication
Join a passionate team on the cutting edge of AI infrastructure — where culture, learning, and ownership are at the heart of how we scale.
$1,200 Home Office & Equipment Stipend- We set you up for success from day one with gear and support to create your ideal workspace
Skills Required
5+ years experience in application security, product security, or as a software engineer with heavy security focus
Strong programming and code-review skills in Python, Go, JavaScript/TypeScript or similar modern stacks
Deep understanding of web application vulnerabilities (OWASP Top 10), API security (REST/GraphQL), and authentication flows (OAuth, OIDC, JWT)
Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP)
Experience building and maintaining automated security pipelines (DevSecOps) including SAST, DAST, SCA in CI/CD
Ability to translate complex security risks into actionable engineering tasks
Relevant application security certifications (e.g., OSWE, GWAPT, CISSP)
Experience securing cloud-native applications running on Kubernetes/Docker
Background in managing bug bounty programs or coordinated vulnerability disclosures