Product Security Engineer

5 Minutes ago • 7 Years + • $220,000 PA - $350,000 PA
Cyber Security

Job Description

Grammarly is seeking a Security Engineer for its Product Security team to ensure user trust by integrating security throughout the product development lifecycle. This role involves collaborating with product engineering teams from design to deployment, conducting threat models, design reviews, secure code reviews, and manual testing. The engineer will develop and implement security solutions, improve security tooling, and experiment with AI-based tools to enhance security processes, while actively engaging stakeholders to communicate risks and maintain customer data security.
Must Have:
  • Set technical direction and prioritization for a Product Security team.
  • Collaborate with Product Engineering teams throughout the SDLC.
  • Create Threat Models, conduct Design Reviews, Secure Code Reviews, and manual testing.
  • Develop and implement end-to-end security solutions.
  • Drive improvements across Product Security tooling, automation, and bug bounty program.
  • Experiment with and develop AI-based tools for the Security team.
  • Actively engage stakeholders, communicating security risks and trade-offs.
  • 7+ years of relevant experience in securing applications at scale.
  • Experience working at each touch-point in a secure SDLC.
  • Familiarity with the standard Product Security tool suite: SAST, DAST, and SCA.
  • Software engineering or programming experience in at least one language (Java, Python, JavaScript, or Go).
  • Experience managing vulnerability disclosure programs or conducting security research on bug bounty platforms.
  • Ability to think like an adversary to identify risk, and then build like an engineer to mitigate those risks.
  • Excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
Perks:
  • Excellent health care (medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching
  • Paid parental leave
  • 20 days of paid time off per year
  • 12 days of paid holidays per year
  • Two floating holidays per year
  • Flexible sick time
  • Generous stipends (caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities

Add these skills to join the top 1% applicants for this job

cross-functional
budget-management
game-texts
software-development-lifecycle-sdlc
manual-testing
python
algorithms
javascript
java

About Grammarly

Grammarly is the trusted AI assistant for communication and productivity, helping over 40 million people and 50,000 organizations do their best work. Companies like Atlassian, Databricks, and Zoom rely on Grammarly to brainstorm, compose, and enhance communication that moves work forward. Grammarly works where you work, integrating seamlessly with over 500,000 applications and websites. Founded in 2009, Grammarly is No. 7 on the Forbes Cloud 100, one of TIME’s 100 Most Influential Companies, one of Fast Company’s Most Innovative Companies in AI, and one of Inc.’s Best Workplaces.

The Opportunity

To achieve our ambitious goals, we’re looking for a Security Engineer to join our Product Security team. Our commitment to user trust is unwavering, and this new team member will play a crucial role in maintaining the trust of millions of users who rely on our products. You will work alongside our product engineering teams, building security into the product from the design phase and throughout the product development lifecycle.

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

As a Security Engineer in Product Security, you will:

  • Set the technical direction and prioritization for a Product Security team covering three separate product lines.
  • Collaborate with Product Engineering teams throughout the SDLC, creating Threat Models, conducting Design Reviews, Secure Code Reviews, and manual testing to identify vulnerabilities.
  • Develop and implement end-to-end security solutions to mitigate security risks in our suite of products.
  • Help drive improvements across our Product Security tooling, automation, and bug bounty program.
  • Experiment with and develop AI-based tools to enable the Security team to move even faster.
  • Be the voice of our customers, actively engaging stakeholders across engineering teams, communicating security risks and trade-offs while keeping customer data secure.

Qualifications

  • Has 7+ years of relevant experience in securing applications at scale.
  • Experience working at each touch-point in a secure SDLC: threat modeling, design reviews, secure code reviews, and web app pentesting.
  • Familiarity with the standard Product Security tool suite: SAST, DAST, and SCA.
  • Software engineering or programming experience in at least one language, such as Java, Python, JavaScript, or Go.
  • Experience managing vulnerability disclosure programs or conducting security research on bug bounty platforms such as HackerOne or Bugcrowd.
  • The ability to think like an adversary to identify risk, and then build like an engineer to mitigate those risks.
  • Excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Has a demonstrated ability to work independently with minimal guidance, proactively manages tasks and priorities across multiple projects, analyzes and executes work efficiently, collaborates effectively with cross-functional teams, and thrives in fast-paced, results-driven environments.
  • Embodies our EAGER values—is ethical, adaptable, gritty, empathetic, and remarkable.
  • Is inspired by our MOVE principles: move fast and learn faster; obsess about creating customer value; value impact over activity; and embrace healthy disagreement rooted in trust.

Compensation and Benefits

Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more:

  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching
  • Paid parental leave
  • 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and flexible sick time
  • Generous stipends (including those for caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities

Grammarly takes a market-based approach to compensation, which means base pay may vary depending on your location. Our US locations are categorized into two compensation zones based on proximity to our hub locations.

Base pay may vary considerably depending on job-related knowledge, skills, and experience. The expected salary ranges for this position are outlined below by compensation zone and may be modified in the future.

United States:

Zone 1: $220,000 – $350,000/year (USD)

We encourage you to apply

At Grammarly, we value our differences, and we encourage all to apply—especially those whose identities are traditionally underrepresented in tech organizations. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).

Set alerts for more jobs like Product Security Engineer
Set alerts for new jobs by Grammarly
Set alerts for new Cyber Security jobs in United States
Set alerts for new jobs in United States
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙