Software Engineer II - Product Security at StubHub
Los Angeles, CA
$165,000–$200,000
Jul 14, 2026
Los Angeles, CA
Jul 21, 2026
What this job asks for AI summary
A hands-on application security engineering role embedded within a product and services domain. The work centers on securing CI/CD pipelines, conducting penetration tests and code reviews on web applications, APIs, and mobile apps, performing architectural reviews, and building automation through production-grade APIs. The role also covers vulnerability management, bug bounty triage, and developer security guidance, suiting engineers with a strong offensive security background.
Mid level · New York-Newark-Jersey City, NY-NJ-PA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 260 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 70–340
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The role is titled 'Software Engineer II' but sits squarely in the product/application security domain — the primary day-to-day work is security analysis, penetration testing, vulnerability management, and security tooling integration, which maps best to Information Security Analysts (15-1212). However, the JD also requires writing production-grade APIs and automation code, giving it a meaningful software-development component (15-1252); Medium confidence reflects this genuine ambiguity.
Two work locations are listed — New York, NY and Century City (Los Angeles), CA. The New York CBSA is used as primary; the role may also be filled in the Los Angeles metro (CBSA 31080).
The role is hybrid (3 days in office / 2 days remote), so remote=false.
Security frameworks listed in the 'What You've Done' section include PCI DSS, CIS, ISO 27001, and NIST CSF. PCI DSS is captured as representative; CIS, ISO 27001, and NIST CSF are additional frameworks in the same requirement but omitted as separate skills to avoid over-listing near-identical compliance-framework entries.
Threat modeling methodologies STRIDE and PASTA are named as examples within the same requirement; captured as a single 'threat modeling' skill.
Security certifications (OSCP, CEH, CISSP, GWAPT) appear under 'Preferred Skills and Qualifications' and are treated as preferred.
AWS and Azure appear under 'Preferred Skills and Qualifications'; Kubernetes and Java/C# also appear there — all treated as preferred.
No compensation figures are stated in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): web application security testing.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.