Product Security Engineer
Product Security Engineers at AI companies sit within engineering organizations and own security across the software development lifecycle—threat modeling, secure code review, vulnerability management, and the security-relevant tooling that engineers depend on. In practice at AI companies, the role frequently extends past pure application security into the surrounding infrastructure and identity layers: securing CI/CD pipelines, designing IAM and secrets management for application access, and reviewing the cloud architecture the application runs on. The boundary with the infrastructure-side security role is genuinely blurry across the population, with most engineers in this slug doing both. AI-specific surfaces—LLM input handling, agent and tool-use boundaries, model-pipeline integrity—are emerging as a meaningful part of the work but sit alongside, not in place of, classical product security. These roles typically sit within security or product engineering organizations, partnering directly with developers to embed security into the build.
Measured across 48 of 49 open postings.
This role is advertised at 3 levels, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.
| Level | Share | Median years | Median pay |
|---|---|---|---|
| Mid | 42%(20) | 5 | $294k |
| Senior | 27%(13) | 5 | $270k |
| Staff / Principal | 31%(15) | 8 | — |
A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate.
“Fluency with AI: you use AI-assisted development tools effectively while applying strong engineering judgment”
“Have experience with prompt engineering, jai”
“Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections”
“use AI to build context quickly, accelerate learning, and extend your reach”
Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.
Skills
What companies are looking for in this role.
Security engineering
Cloud and infrastructure security
Backend and API engineering
Threat modeling and architecture review
Application and product security
Identity and access management
Incident response and forensics
Cryptography and key management
Infrastructure automation and IaC
Security tooling and automation engineering
Detection engineering
CI/CD and release automation
Security policy and standards
Monitoring and observability
Data privacy compliance
Vulnerability management
Data pipeline engineering
AI safety and guardrails
Agent security controls
AI/ML infrastructure security
AI-assisted development workflow
Mentoring and code review
Technology
The tools and technologies that define this role.
Open Jobs
49 open Product Security Engineer jobs across 32 companies.
Other Engineering roles
General-purpose software engineering roles focused on building and maintaining software systems. Covers generalist SWE positions that don't clearly fall into frontend, backend, fullstack, or other specialized tracks.
Engineers focused on server-side systems, APIs, services, and data processing pipelines. Includes roles explicitly labeled as backend or server-side development.
Engineers specializing in user-facing interfaces, web applications, and client-side development. Includes UI/UX engineering and web development roles.
Engineers working across the entire application stack, handling both frontend and backend responsibilities.
Engineers building and maintaining internal platforms, cloud infrastructure, compute systems, and developer tooling.