Summary
SailPoint is a cybersecurity and identity security company seeking a Product Security Engineer to help protect its products and organization. The role partners with Engineering and security teams to identify risks, improve secure software development practices, coordinate testing and remediation, and advance application security through tooling, AI integration, training, and scalable security frameworks.
Responsibilities
- Partner with Engineering teams throughout the software development lifecycle to identify and mitigate security risks, and implement secure deployment practices
- Support threat modeling activities and help engineering teams implement appropriate security controls
- Define and promote secure coding standards, security policies, best practices, and secure-by-design principles
- Participate in the Cyber organization’s efforts to leverage AI across the team, as well as the use of AI in our SSDLC
- Partner with Engineering on improving security testing programs
- Coordinate internal and external application and penetration testing initiatives
- Validate vulnerability findings and prioritize remediation based on risk
- Perform root cause analysis and recommend long-term security improvements
- Collaborate with the Security Operations team on security monitoring and detection capabilities for applications and services
- Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty program
- Develop security training, guidance, and technical documentation
- Interact with other organizations at SailPoint as a consultant on security-related matters
- Deepen collaboration with key engineering and tooling leads by Day 90, reinforcing recurring touchpoints to integrate product security proactively into early planning cycles, roadmaps, and feature designs
- Review the end-to-end Software Development Life Cycle (SDLC) by Day 60 to identify enhancement opportunities, accelerate "shift-left" practices, and further standardize secure-by-design deployment pipelines
- Refine and centralize the inventory of supported products, underlying architecture, and third-party dependencies by Day 90 to deliver a highly visible, comprehensive single source of truth
- Evaluate the current security tooling and implement state-of-the-art AI-assisted scanning across product code to further automate and scale security workflows
- Formalize a highly scalable, risk-based vulnerability prioritization framework, optimizing Time to Remediate (TTR) metrics to provide clear, actionable risk visibility for executive leadership and the Board
- Elevate developer security education and revamp "Security Champions" program by Day 180, embedding security advocates across core product lines to champion secure development practices
- Conduct comprehensive reviews of the production environment (including Kubernetes and containerized applications) to systematically address complex architectural security opportunities and build long-term environment resilience
- Define, document, and roll out standardized, secure "paved road" configurations and guardrails, making secure deployment the friction-free path of least resistance for product teams
- Maintain and scale updated product architecture documentation while continuously elevating team capabilities, autonomy, and cross-functional alignment through active, hands-on mentorship
Skills
- * 4-5 years of experience in product security, application security, software engineering, or a related field
- * Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners
- * Experience with CI/CD security controls and DevSecOps practices
- * Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby
- * Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts
- * Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows
- * Deep expertise in threat modeling, secure architecture design, and vulnerability management
- * Experience influencing engineering organizations and driving security initiatives across multiple teams
- * Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues
- * Have a continuous learning mindset and passion for security
- * Have strong analytical and problem-solving skills
- * Be flexible, with the ability to balance security vs the needs of the business
- * Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation
- * Be able to translate technical risks into business impact
- * Be collaborative and able to foster relationships with teams we partner with
- * Knowledge of artificial intelligence software security frameworks is strongly preferred, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework
Qualifications
Must Haves
- * 4-5 years of experience in product security, application security, software engineering, or a related field
- * Experience with security testing tools such as: SAST, SCA, DAST, Container security scanners
- * Experience with CI/CD security controls and DevSecOps practices
- * Familiarity with one or more programming languages such as Python, Go, Java, JavaScript/TypeScript, Ruby
- * Demonstrated ability to effectively use AI-powered tools and automation to enhance security engineering productivity, research, analysis, and remediation efforts
- * Knowledge of emerging AI security risks and best practices for securing AI-enabled applications, services, and development workflows
- * Deep expertise in threat modeling, secure architecture design, and vulnerability management
- * Experience influencing engineering organizations and driving security initiatives across multiple teams
- * Be a highly active observer of industry security trends and threats, remaining up to date on current cyber issues
- * Have a continuous learning mindset and passion for security
- * Have strong analytical and problem-solving skills
- * Be flexible, with the ability to balance security vs the needs of the business
- * Have excellent written and oral communications skills with demonstrated commitment to producing high quality documentation
- * Be able to translate technical risks into business impact
- * Be collaborative and able to foster relationships with teams we partner with
Nice to Haves
- * Knowledge of artificial intelligence software security frameworks is strongly preferred, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework
Benefits
- May be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission
- Potential eligibility for equity participation
- Medical, dental, and vision insurance
- Short-term and long-term disability coverage
- Life insurance and Accidental Death & Dismemberment (AD&D)
- Supplemental life insurance for employees, spouses, and children
- Flexible spending accounts for health care and dependent care; limited purpose flexible spending account
- 401(k) Savings and Investment Plan with company matching
- Flexible vacation policy
- 8 paid holidays annually
- Sick leave
- Paid parental leave
- Employee Assistance Program (EAP) and Care Counselors
- Voluntary benefits including Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options
- Health Savings Account (HSA) with employer contribution
- Remote work from anywhere within the continental United States