Jobs and Careers
GR
Staff Product Security Engineer
GreenlightUnited StatesRemotefull_timeVerifiedPosted 14 Aug 2025
💰 $165,000/yr
About the role
Greenlight is the leading family fintech company on a mission to help parents raise financially smart kids. We proudly serve more than 6 million parents and kids with our award-winning banking app for families. With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family’s future. Kids and teens learn to earn, save, spend wisely, and invest.
At Greenlight, we believe every child should have the opportunity to become financially healthy and happy. It’s no small task, and that’s why we leap out of bed every morning to come to work. Because creating a better, brighter future for the next generation depends on it.
We are seeking an experienced and motivated Staff Product Security Engineer to join our growing security team. This role will be critical in ensuring the security of our products across the entire software development lifecycle (SDLC). The ideal candidate will be a technical leader, capable of driving product security initiatives end to end. You will work closely with engineering, product, and operations teams to embed security best practices from design through to deployment.
As a Staff Product Security Engineer, you will be responsible for ensuring the security of Greenlight’s products and services from conception to launch and beyond, as well as operating the processes along with the team. You will play a critical role in shaping our security posture, embedding security into our development lifecycle, and protecting our customers' data.
This role reports to the Sr Director, Security GRC & Trust
At Greenlight, we believe every child should have the opportunity to become financially healthy and happy. It’s no small task, and that’s why we leap out of bed every morning to come to work. Because creating a better, brighter future for the next generation depends on it.
We are seeking an experienced and motivated Staff Product Security Engineer to join our growing security team. This role will be critical in ensuring the security of our products across the entire software development lifecycle (SDLC). The ideal candidate will be a technical leader, capable of driving product security initiatives end to end. You will work closely with engineering, product, and operations teams to embed security best practices from design through to deployment.
As a Staff Product Security Engineer, you will be responsible for ensuring the security of Greenlight’s products and services from conception to launch and beyond, as well as operating the processes along with the team. You will play a critical role in shaping our security posture, embedding security into our development lifecycle, and protecting our customers' data.
This role reports to the Sr Director, Security GRC & Trust
Your day-to-day:
- Support in developing and executing a comprehensive product security strategy that aligns with the company's goals and risk appetite.
- Foster a culture of security awareness and ownership across the Engineering and Product organizations.
- Integrate security best practices and automated tooling into the entire Software Development Lifecycle (SDLC), from design and threat modeling to testing and deployment.
- Establish and enforce secure development standards (i.e. API security, coding, IaC, etc.) and best practices across the organization.
- Oversee the application security program, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and manual penetration testing.
- Partner closely with engineering, product, and platform teams to prioritize and remediate security vulnerabilities in a timely and efficient manner.
- Establish and manage a mature incident response process for product-related security events and vulnerabilities.
- Partner with engineering, product, and platform teams to enhance Greenlight Application’s security features.
- Stay current with the latest security threats, vulnerabilities, and industry best practices to continuously evolve our security controls and processes.
What you’ll bring to the team:
- Deep technical knowledge of web and mobile application security, common vulnerabilities (OWASP Top 10), and secure coding practices.
- Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications
- End to end experience on implementing and managing tools for Product Security (i.e. API Security, Mobile Protection, SAST, runtime scanning, etc.)
- Hands-on experience with security tools for SAST, DAST, IAST, and penetration testing.
- Strong understanding of cloud security principles in AWS environments.
- Excellent communication skills with the ability to articulate complex security concepts to both technical and non-technical audiences.
- Plus: Experience with security tools such as Burp Suite, Metasploit, Kali Linux
- Plus: Background in financial services, fintech, or highly regulated industries
- Plus: Hands-on certifications (e.g. OSCP, Certified Ethical Hacker, SANS) and/or demonstrated code projects. Please share your github or public code samples with us!
Technologies we use:
- Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI
- AWS
- MySQL, DynamoDB, Redis
- Kubernetes, Ambassador, Helm, Rancher
Work perks at Greenlight:
- Medical, dental, vision, and HSA match
- Paid life insurance, AD&D, and disability benefits
- Traditional 401k with company match
- Unlimited PTO
- Paid company holidays and pop-up bonus holidays
- Professional development stipends
- Mental health resources
- 1:1 financial planners
- Fertility healthcare
- 100% paid parental and caregiving leave, plus cleaning service and meals during your leave
- Flexible WFH, both remote and in-office opportunities
- Fully stocked kitchen,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s