Back to Jobs
Development Just now

Application & Product Security Engineer

United StatesUnited States
Full-time
$130,000–$170,000
Mid-Level

Job Description

Key Skills Required

Master these to land this role

SecurityApplication SecurityEngineeringProduct Security

Want to know if you're a match for this job?

Calculate My Match Score

About Jump

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up — which means our customers trust us with some of their most sensitive client data. Security isn’t a checkbox for us; it’s core to the product and to earning that trust every day.

About the Role

We’re hiring our first dedicated Application & Product Security Engineer. You’ll partner with engineering and product teams from the earliest design conversations to make sure security is built into what we ship — not bolted on afterward. This is a hands-on, high-ownership role at a startup: some days you’ll be threat modeling a new feature, other days reviewing code, tuning our security tooling, or jumping in on an incident. If you like variety and want your work to directly shape how a product is built, this role is for you.

What You’ll Do

  • Partner with product and engineering teams during design and planning to identify risks early and build security into new features from the start.

  • Lead threat modeling and secure design reviews for new products, features, and architecture changes.

  • Perform security-focused code reviews and help engineers fix vulnerabilities — and understand how to avoid them next time.

  • Build and maintain application security tooling (SAST, dependency scanning, secrets detection) integrated into CI/CD.

  • Participate in incident response: triage, investigate, contain, and drive post-incident learning.

  • Triage findings from bug bounty reports, pen tests, and vulnerability scans, and drive remediation with owning teams.

  • Develop lightweight security guidance, paved-road patterns, and training that make the secure way the easy way.

  • Wear multiple hats as needed — from customer security questionnaires to cloud and corporate security improvements.

What We’re Looking For

  • 2–4 years of experience in application security, product security, or a software engineering role with significant security responsibilities.

  • Solid grasp of common vulnerability classes (OWASP Top 10, authn/authz flaws, injection, SSRF) and how to prevent them in real codebases.

  • Experience with threat modeling and secure design review, and the ability to explain risk in terms engineers and PMs care about.

  • Hands-on incident response experience — you’ve helped detect, investigate, or contain real security events.

  • Ability to read and write code (e.g., Python, TypeScript/JavaScript, Go, or similar) well enough to review PRs and build small tools.

  • Strong communication and collaboration skills — you build trust with engineers rather than throwing findings over the wall.

  • Comfort with ambiguity and shifting priorities; you can self-direct and wear multiple hats.

Nice to Have

  • Prior security experience at a startup or on a small security team (a major plus).

  • Cloud security experience (AWS, GCP, or Azure) and infrastructure-as-code familiarity.

  • Experience securing AI/LLM-powered products or working with sensitive financial data.

  • Familiarity with compliance frameworks (SOC 2, GDPR) as they relate to product security.

  • Contributions to CTFs, bug bounty, open-source security tools, or security community involvement.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More