Skip to main content

Persona

Product Security Engineer

San Francisco (Remote)$150k–$220kfulltimemidAdded 1 month ago

About this role

Persona is seeking a Product Security Engineer to enhance its identity verification infrastructure by integrating security practices into product development. The role involves managing vulnerabilities, collaborating with product teams, and shaping security initiatives within the organization.

What you'll do

  • Oversee the full vulnerability lifecycle and respond to external threats
  • Design and develop systems and tools for scaling security efforts
  • Collaborate with product engineers to ensure secure feature development
  • Manage and promote Persona's bug bounty program within the security community

What they're looking for

  • 4+ years in software engineering
  • 2+ years in product security
  • Experience translating security risks to non-technical stakeholders
  • Ability to integrate security into the software development lifecycle
  • Familiarity with SAST/DAST tools
  • Knowledge of regulatory compliance (SOC 2, HIPAA)

Benefits

  • Medical, dental, and vision coverage
  • 3% 401(k) contribution
  • Unlimited PTO and quarterly mental health days
  • Professional development stipend
  • Family planning benefits
  • Wellness benefits
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Persona

Persona builds an identity verification platform supported by data products, infrastructure, and networking systems that handle large-scale operations. The company is hiring Software Engineers for data products and platform teams, a networking specialist, a Security Engineer, and Solutions Engineers to support customer implementations and platform reliability.

View all jobs at Persona

Likely interview questions

  • Walk us through a time you discovered a significant vulnerability in a product. How did you communicate the risk to non-technical stakeholders, and what tradeoffs did you help the team navigate?
  • Describe your experience embedding security into an engineering team's development lifecycle. How did you balance being a security advocate without becoming a blocker?