Crowdstrike logo
Crowdstrike
Posted 67 days agoVerified live 19h ago

Product Security Engineer, Application Security (Remote)

Brief overview

Remote
$120k–$180k/yrStated range
216 H-1B approvalsDept. of Labor
36 green cardsCertified filings
Application SecurityThreat ModelingSTRIDECode ReviewGo (Golang)PythonJavaCloud SecurityGoogle Cloud Platform (GCP)Microsoft AzureAmazon Web Services (AWS)SASTDASTCSPMDSPMASPMApplication Penetration Testing

About the company

Crowdstrike logo
Crowdstrikecrowdstrike.com

Global leader in cybersecurity delivering AI-native platform to stop breaches.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
216H-1B approved
99%approval rate
24new H-1B hires
36PERM certified
$195,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202374
202462
202571
20269
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202316
202417
202525
202613
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
202311
202414
202511
Top sponsored roles
Senior EngineerSenior Engineer IISenior Engineer - CloudEngineer III - CloudSr. Data Scientist II
Sponsored employees from
IndiaBangladesh

Job description

Summary

CrowdStrike is a global leader in cybersecurity, dedicated to stopping breaches with their advanced AI-native platform. The Product Security Engineer will focus on securing applications by identifying and fixing security defects, collaborating with engineering teams, and enhancing the overall security posture of CrowdStrike's products.

Responsibilities

  • Join engineering teams working on applications as a security expert and advisor, influencing the design and capabilities of our products
  • Create and maintain threat models to drive security decisions and minimize threat surface area
  • Review application source code, looking for security defects and risk
  • Attack applications throughout the Secure Development LifeCycle
  • Work with developers to help them understand defects, risks, design weaknesses, etc. and implement proven solutions
  • Build integrated tools and automation to make life easier for you, your team, and our engineering partners
  • Assist in responding to our bug bounty program, hunt for similar issues, and improve the security of our applications

Skills

  • A moderate understanding of how software products are created and shipped in Agile/DevOps like environments
  • Moderate experience with threat modeling, especially using STRIDE
  • Code review experience for apps built with Go (Golang), Python, or Java
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites
  • An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing
  • Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc
  • Experience with driving ambiguous research projects
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes
  • Self-motivated to identify security problems and engage with teams to find solutions
  • Demonstrable experience developing/maintaining automation for application security tasks and defect identification
  • Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)
  • Knowledge of Docker and Kubernetes (k8s)
  • Can explain and demonstrate the limitations of AI assisted development and associated security implications
  • Engaged in providing security enhancements to open source projects
  • Experience with threat intelligence driven testing and adversarial emulation

Qualifications

Must Haves

  • A moderate understanding of how software products are created and shipped in Agile/DevOps like environments
  • Moderate experience with threat modeling, especially using STRIDE
  • Code review experience for apps built with Go (Golang), Python, or Java
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites
  • An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing
  • Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc
  • Experience with driving ambiguous research projects
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes

Nice to Haves

  • Self-motivated to identify security problems and engage with teams to find solutions
  • Demonstrable experience developing/maintaining automation for application security tasks and defect identification
  • Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)
  • Knowledge of Docker and Kubernetes (k8s)
  • Can explain and demonstrate the limitations of AI assisted development and associated security implications
  • Engaged in providing security enhancements to open source projects
  • Experience with threat intelligence driven testing and adversarial emulation

Benefits

  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe
  • Health insurance
  • 401k
  • Paid time off
  • Market leader in compensation and equity awards
  • Eligibility for bonuses
  • Equity grants

More jobs like this