Senior Product Security Engineer
United Talent Agency · Beverly Hills, CA
$160,000–$200,000from the description
Jul 16, 2026
Beverly Hills, CA
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor role focused on embedding security across web, mobile, and cloud-based products throughout their entire lifecycle — from threat modeling and architecture reviews to CI/CD pipeline tooling, vulnerability management, and incident response integration. The position spans AWS, Azure, and GCP environments and involves close collaboration with engineering and product teams. It suits an experienced application or product security engineer comfortable owning security programs and influencing technical direction across multiple teams.
Senior level · 5+ years · Los Angeles-Long Beach-Anaheim, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 70 people in the Los Angeles-Long Beach-Anaheim, CA area plausibly meet what this posting asks for (information security analysts). range 30–130
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,481 (middle half $96,915–$170,448). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The degree requirement states 'Bachelor's degree … or equivalent practical experience', so no formal degree is hard-gated.
Cloud provider requirement names AWS as preferred but accepts any major cloud provider; AWS is listed under required qualifications with 'AWS preferred', so it is treated as a hard gate on cloud security experience with AWS as the primary named option and Azure/GCP as stated alternatives.
Terraform, GitHub Actions, secrets management, container/Kubernetes security, and WAF appear under 'Familiarity with…' language in the requirements section — 'familiarity' signals a lower bar than deep expertise, so these are treated as preferred rather than hard gates.
REST/GraphQL API security appears in the responsibilities section (What You Will Do), not the requirements section, so it is treated as preferred.
The role sits at the intersection of security engineering and software development; 15-1252 (Software Developers) is a plausible runner-up given the emphasis on secure SDLC, CI/CD integration, and coding standards, but the primary day-to-day work is security analysis and control design.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.