Senior Product Security Engineer
AppOmniAbout the role
About AppOmni
AppOmni is the leading SaaS security platform for the modern enterprise. We help security teams and application owners quickly detect and mitigate threats, maintain least privilege access, and gain deep visibility across their SaaS environments. The world’s leading companies, including over 25% of the Fortune 100, chose AppOmni to secure their critical business applications, protect sensitive data, and enable secure productivity at scale. Our mission is to secure the applications that power the modern enterprise, and with the current pace of innovation, we’re just getting started. You have a rare opportunity to design category-defining products that protect the most important companies in the world – while transforming how security software is built, used, and experienced.
About the Role
As an Senior Product Security Engineer, you will lead integrations for complex SaaS applications, troubleshooting edge-case APIs and audit logs, applying posture management logic and contributing integration code or tooling directly into the AppOmni platform. You’ll serve as a subject matter expert and collaborate across engineering, product, sales and customer success teams.
Allowing our employees & teams to collaborate and innovate is important to us, and we promote a hybrid work model to encourage engagement and connectivity. We’re looking for talented individuals located within our hub cities, open to working 3 days per week in-office.
Hub Cities: San Francisco & San Jose (CA), Denver (CO), Lexington (KY) and New York City (NY)
What you’ll do
- Lead full-cycle integrations: procurement, API/audit log documentation, posture mapping and remediation guidance
- Troubleshoot complex API integrations, permission models and audit log retrieval issues
- Contribute integration code, transformation scripts or API tooling in GitHub
- Identify and drive improvements in integration playbooks and tooling processes
- Enable internal and external developers via documentation, demos and collaboration
- Act as SME for assigned app categories
- Identify and prioritize which SaaS application settings are crucial for security and articulate the reasons for their importance or lack thereof.
- Provide clear remediation steps to update settings, including any concerning combinations of settings that need to be addressed.
- Communicate findings and recommendations to internal stakeholders, including product managers, engineers, and customers to ensure alignment and understanding.
- Collaborate with engineers to explore and validate exploitation paths in test environments, helping to refine integration coverage and threat models across supported SaaS applications
- Support security research into SaaS application posture by identifying and documenting critical security-relevant settings, their potential misconfigurations, and how these could lead to exploit chains (e.g., excessive privilege access or unmonitored third-party integrations).
- Contribute to research summaries detailing observed SaaS threat patterns and proposed mitigation strategies, supporting product and engineering teams with actionable insights.
- Stay informed about the latest trends, threats, and best practices in SaaS security to maintain and enhance AppOmni's competitive edge.
What We’re Looking For
- 5 - 8 years in SaaS integration, security engineering or posture management roles
- Strong API debugging skills and experience with scripting (Python preferred)
- Hands-on experience with SaaS audit logs, permission modeling and posture frameworks
- Proven skills in writing and reviewing GitHub pull requests
- Hands-on experience managing operational workflows in JIRA or a similar tool.
- Proficiency in leveraging AI-powered tools to accelerate SaaS research, documentation creation, integration troubleshooting and workflow optimization.
- Strong understanding of SaaS security concepts including authentication/authorization models, audit log configurations, permission frameworks and SaaS platform security hardening best practices.
- Experience integrating or contributing to SaaS Security Posture Management tools or cloud security platforms.
- Passion for staying at the forefront of SaaS security research and driving continuous improvement in the field.
- Excellent communication across technical and non-technical stakeholders
- Ability to independently drive integration projects with end-to-end ownership
- Strong understanding of SaaS application security, with the ability to identify critical security settings and articulate their importance.
- Experience in defining and implementing security posture policies and integrating them into policy libraries.
- Ability to provide
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s