Persona
Product Security Engineer
About this role
Persona is seeking a Product Security Engineer to enhance its identity verification infrastructure by integrating security practices into product development. The role involves managing vulnerabilities, collaborating with product teams, and shaping security initiatives within the organization.
What you'll do
- Oversee the full vulnerability lifecycle and respond to external threats
- Design and develop systems and tools for scaling security efforts
- Collaborate with product engineers to ensure secure feature development
- Manage and promote Persona's bug bounty program within the security community
What they're looking for
- 4+ years in software engineering
- 2+ years in product security
- Experience translating security risks to non-technical stakeholders
- Ability to integrate security into the software development lifecycle
- Familiarity with SAST/DAST tools
- Knowledge of regulatory compliance (SOC 2, HIPAA)
Benefits
- Medical, dental, and vision coverage
- 3% 401(k) contribution
- Unlimited PTO and quarterly mental health days
- Professional development stipend
- Family planning benefits
- Wellness benefits
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Persona
Persona builds an identity verification platform supported by data products, infrastructure, and networking systems that handle large-scale operations. The company is hiring Software Engineers for data products and platform teams, a networking specialist, a Security Engineer, and Solutions Engineers to support customer implementations and platform reliability.
View all jobs at PersonaLikely interview questions
- Walk us through a time you discovered a significant vulnerability in a product. How did you communicate the risk to non-technical stakeholders, and what tradeoffs did you help the team navigate?
- Describe your experience embedding security into an engineering team's development lifecycle. How did you balance being a security advocate without becoming a blocker?