Remote Source

    Senior Staff Product Security Engineer

    ~$112,210 - $208,390Market Estimate
    Atlanta (Remote Friendly)
    Full-Time
    Senior (7+ yrs)
    IT & Security
    Posted on May 5, 2026

    We are seeking a seasoned and highly accomplished Senior Staff Product Security Engineer to join our security leadership team. This is a senior individual contributor role that carries significant organizational influence. You will define the technical vision for product security at Greenlight and set the standard for how we build and ship secure software. The ideal candidate brings deep, hands-on expertise paired with the strategic mindset to drive large-scale security initiatives from concept to production. You will operate across the full breadth of our engineering organization, embedding security into every layer of our SDLC, shaping architecture decisions, and building the programs and processes that protect millions of families who trust us with their financial, location and personal data.

    This role reports to the VP, Security GRC & Trust.

    Technologies we use:
  1. Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI
  2. AWS, GCP
  3. MySQL, DynamoDB, Redis
  4. Kubernetes, Ambassador, Helm, Rancher
  5. Your day-to-day:
  6. Define and lead the long-term product security strategy, roadmap, and vision in alignment with company goals, risk appetite, and regulatory requirements.
  7. Serve as the internal authority on application and product security, providing expert guidance to engineering, product, and executive leadership.
  8. Drive a company-wide culture of security ownership embedding security thinking deeply into the habits of every engineering team.
  9. Architect and continuously evolve a best-in-class Product Security program, spanning threat modeling, SAST, DAST, IAST, SCA, runtime protection, and API security.
  10. Lead the design and enforcement of secure development standards across web, mobile, and cloud including secure coding guidelines, IaC policies, and API security frameworks.
  11. Identify and drive resolution of systemic, high-impact vulnerabilities and architectural security gaps across Greenlight's platform.
  12. Lead and mature Greenlight's penetration testing program, both through internal efforts and external vendor partnerships.
  13. Partner with engineering and platform teams to build security-enhancing product features that protect our customers' financial data.
  14. Establish and lead incident response processes for product-level security events, including root cause analysis and systemic remediation.
  15. Evaluate and introduce emerging security tooling, techniques, and frameworks to keep Greenlight ahead of the threat landscape.
  16. Mentor staff and senior engineers across the security and engineering organizations, raising the overall security engineering capability of the company.
  17. What you’ll bring to the team:
  18. 12+ years of experience in product security, application security, or a related engineering discipline.
  19. Proven track record of defining and driving security programs at scale across complex, multi-platform environments.
  20. Hands-on experience architecting and implementing security solutions and processes in production environments, enabling engineering teams to build and ship securely at scale.
  21. Expert-level knowledge of web and mobile application security, including OWASP Top 10, API security, and mobile threat vectors (iOS and Android).
  22. Deep hands-on experience with the full AppSec toolchain: SAST, DAST, IAST, SCA, secrets scanning, and runtime protection.
  23. Strong command of cloud security architecture and controls, particularly in AWS environments.
  24. Experience leading or heavily influencing the security architecture of distributed, microservices-based systems.
  25. Experience in developing and implementing security solutions
  26. Demonstrated ability to build strong cross-functional relationships and influence engineering culture without direct authority.
  27. Exceptional communication skills — you can distill complex security risk into clear, actionable language for engineers, executives, and non-technical stakeholders alike.
  28. Experience operating in regulated industries (e.g. financial services, fintech, healthcare).
  29. Plus: Hands-on certifications such as OSCP, GWAPT, GPEN, CISSP, or equivalent — and/or public code/research. Share your GitHub or any public security work with us!
  30. Plus: Experience building or scaling Product Security programs in high-growth startup environments.
  31. Plus: Familiarity with security tools including Burp Suite, or Kali Linux.
  32. Work perks at Greenlight:
  33. Medical, dental, vision, and HSA match
  34. Paid life insurance, AD&D, and disability benefits
  35. Traditional 401k with company match
  36. Unlimited PTO
  37. Paid company holidays and pop-up bonus holidays
  38. Professional development stipends
  39. Mental health resources
  40. 1:1 financial planners
  41. Fertility healthcare
  42. 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
  43. Flexible WFH, both remote and in-office opportunities
  44. Fully stocked kitchen, catered lunches, and occasional in-office happy hours
  45. Employee resource groups
  46. Apply for this position

    Company:  Greenlight

    Provides a debit card and money app that empowers parents to raise financially-smart kids.
    201-500 employees
    Finance & Fintech
    HQ: United States