Sr. Product Security Engineer
YipitDataAbout the role
About Us:
YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B. Every day, our proprietary technology analyzes billions of alternative data points to uncover actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments.
Our data and research teams transform raw data into strategic intelligence, delivering accurate, timely, and deeply contextualized analysis that our customers—ranging from the world’s top investment funds to Fortune 500 companies—depend on to drive high-stakes decisions. From sourcing and licensing novel datasets to rigorous analysis and expert narrative framing, our teams ensure clients get not just data, but clarity and confidence.
We operate globally with offices in the US (NYC, Austin, Miami, Mountain View), APAC (Hong Kong, Shanghai, Beijing, Guangzhou, Singapore), and India. Our award-winning, people-centric culture—recognized by Inc. as a Best Workplace for three consecutive years—emphasizes transparency, ownership, and continuous mastery.
What It’s Like to Work at YipitData:
YipitData isn’t a place for coasting, it’s a launchpad for ambitious, impact-driven professionals.
From day one, you’ll take the lead on meaningful work, accelerate your growth, and gain exposure that shapes careers.
Why Top Talent Chooses YipitData:
- Ownership That Matters: You’ll lead high-impact projects with real business outcomes
- Rapid Growth: We compress years of learning into months
- Merit Over Titles: Trust and responsibility are earned through execution, not tenure
- Velocity with Purpose: We move fast, support each other, and aim high—always with purpose and intention
If your ambition is matched by your work ethic—and you're hungry for a place where growth, impact, and ownership are the norm—YipitData might be the opportunity you’ve been waiting for.
About The Role:
We are seeking a Sr. Product Security Engineer to manage the day-to-day execution of the organization's vulnerability management program and provide hands-on support for secure software development lifecycle (SSDLC) and CI/CD security initiatives.
This role works closely with the DevSecOps Lead, Engineering, Platform Team, and Security to ensure vulnerabilities are tracked from discovery through remediation, security controls are functioning as intended, and findings are reported with clear accountability. The Security Operations Engineer translates security requirements into operational workflows, managing intake queues, enforcing SLAs, coordinating remediation with engineering teams, and producing the dashboards and reports that give leadership visibility into security posture.
This is a remote-friendly opportunity that can sit in NYC (where our headquarter is located), one of our office hubs in Austin, Miami, Los Angeles (CA), and Cupertino (CA), or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding.
We expect U.S. based working hours with the majority of the team working East and Central Time Zones.
As Our Sr Product Security Engineer You Will:
-
Vulnerability Management Operations
- Own the end-to-end vulnerability lifecycle: intake, triage, assignment, remediation coordination, verification, and closure across all finding sources (dependency scanning, secrets scanning, IaC scanning, container scanning, SAST, DAST, and manual assessments).
- Enforce severity-based SLAs, escalation paths, and ownership expectations. Track remediation timelines and follow up with engineering teams to ensure findings are resolved within policy requirements.
- Aggregate findings centrally from all scanning tools and sources into a unified tracking system. Ensure every finding has a clear owner, status, and target remediation date.
- Manage exception and risk acceptance workflows. Process exception requests, document compensating controls, and ensure approvals are captured with appropriate evidence.
- Produce vulnerability posture reports and dashboards, including aging analysis, SLA compliance, scanner coverage, and trend reporting by severity, team, and business unit.
- Coordinate with engineering teams on remediation prioritization, providing context on severity, exploitability, and business impact to support informed decision-making.
- D
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s