LaunchDarkly
Product Security Engineer
About this role
LaunchDarkly seeks a Product Security Engineer to protect its critical infrastructure platform through threat modeling, cloud security posture management, and proactive security automation. You'll work on a small, high-leverage team to make the secure path the easy path for developers, leveraging AI to reduce toil and improve coverage.
What you'll do
- Lead threat modeling engagements on high-risk features and services
- Triage and investigate CNAPP findings end-to-end, identifying systemic fixes
- Partner with product engineering teams as a trusted security reviewer
- Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage
- Integrate AI tools to accelerate triage, threat modeling, and code scanning
- Build security documentation and run office hours to elevate baseline practices
What they're looking for
- Threat modeling and risk assessment
- Cloud security posture management (CNAPP)
- Application security (SAST/SCA tools)
- Security fundamentals and program design
- Collaboration and partnership with engineering teams
- AI tool integration and evaluation
- Bug bounty and vulnerability triage
- SDLC and DevSecOps practices
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
LaunchDarkly
LaunchDarkly builds a platform for feature management, AI configuration, and observability that helps teams control, monitor, and safely deploy software. The company is hiring Full Stack Engineers, SDK developers, and security specialists to expand its core platform capabilities, including AI-powered onboarding, release safety monitoring, enterprise integrations, and developer security tooling.
- Website
- launchdarkly.com
Likely interview questions
- Walk us through your approach to threat modeling—how do you decide which features or services warrant a full engagement, and how have you made threat modeling more systematic rather than ad-hoc?
- Describe your experience triaging cloud security findings. How do you prioritize between fixing individual issues versus identifying and fixing systemic patterns?