Application Product Security Engineer
Jump
$130,000–$170,000
Jul 19, 2026
—
Jul 21, 2026
What this job asks for AI summary
The first dedicated security hire at an AI-focused fintech startup, this role embeds security across the full software development lifecycle — from threat modeling and secure design reviews to code review, security tooling in CI/CD pipelines, and incident response. It suits someone with a software engineering background who can work closely with product and engineering teams, handle a broad range of security responsibilities, and operate with significant autonomy in a small-team environment.
Mid level · 2+ years · Remote · Full-time
Pay in the description: $130,000–$170,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 770 people nationally plausibly meet what this posting asks for (information security analysts). range 160–1,150
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The title 'Application & Product Security Engineer' carries no seniority level word, so advertised seniority is Unspecified. The 2–4 year experience window and scope (first dedicated security hire at a startup, hands-on individual contributor) support a Mid-level classification.
The alternative occupation code 15-1252 (Software Developers) is noted because the role explicitly requires the ability to read and write code and build tooling, making it a genuine hybrid; however, the primary day-to-day work is security analysis, threat modeling, and vulnerability management.
Python, TypeScript/JavaScript, and Go are listed together as interchangeable examples of coding ability ('e.g., Python, TypeScript/JavaScript, Go, or similar'); emitted as one skill with alternatives rather than separate entries.
SOC 2 and GDPR are listed together under Nice to Have as compliance frameworks; emitted as one preferred skill with GDPR as an alternative.
Cloud security (AWS/GCP/Azure) and infrastructure-as-code familiarity appear under 'Nice to Have' and are marked preferred accordingly.
Bug bounty, CTF contributions, and open-source security tool involvement are grouped under 'Nice to Have'; only 'bug bounty' is emitted as a named skill since CTF and open-source contributions are activities rather than named technologies.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.