Applied Methods
~The MetaEngineeringProduct Security Engineer

Product Security Engineer

Product Security Engineers at AI companies sit within engineering organizations and own security across the software development lifecycle—threat modeling, secure code review, vulnerability management, and the security-relevant tooling that engineers depend on. In practice at AI companies, the role frequently extends past pure application security into the surrounding infrastructure and identity layers: securing CI/CD pipelines, designing IAM and secrets management for application access, and reviewing the cloud architecture the application runs on. The boundary with the infrastructure-side security role is genuinely blurry across the population, with most engineers in this slug doing both. AI-specific surfaces—LLM input handling, agent and tool-use boundaries, model-pipeline integrity—are emerging as a meaningful part of the work but sit alongside, not in place of, classical product security. These roles typically sit within security or product engineering organizations, partnering directly with developers to embed security into the build.

$ titles --canonical
Software Engineer, SecuritySecurity Software EngineerProduct Security EngineerStaff Product Security Engineer
Open Jobs49
Companies Hiring32
$ expectations --role product-security-engineer

Measured across 48 of 49 open postings.

56%
expect AI in the role's own work
8% state it as a requirement
4%
work directly with customers
8%
manage people
Mid
most common level
42% of open postings
BY LEVEL

This role is advertised at 3 levels, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.

LevelShareMedian yearsMedian pay
Mid42%(20)5$294k
Senior27%(13)5$270k
Staff / Principal31%(15)8—

A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate.

WHAT THEY ASK FOR, VERBATIM

“Fluency with AI: you use AI-assisted development tools effectively while applying strong engineering judgment”

Harvey · Staff Security Software Engineer, IAM

“Have experience with prompt engineering, jai”

Anthropic · Staff+ Software Engineer, Account Creation

“Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections”

Decagon · Senior Software Engineer, Application Security

“use AI to build context quickly, accelerate learning, and extend your reach”

Ambience Healthcare · Staff Security Engineer
$ barriers
41%
advertised as remote
of postings that state a work mode
19%
state a degree requirement
10%
need a security clearance
79%
still advertised a month later
6 points faster than the board

Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.

$02

Skills

What companies are looking for in this role.

$ skills --core

Security engineering

96%

Cloud and infrastructure security

48%

Backend and API engineering

48%

Threat modeling and architecture review

40%

Application and product security

35%

Identity and access management

25%

Incident response and forensics

23%

Cryptography and key management

21%

Infrastructure automation and IaC

19%

Security tooling and automation engineering

17%

Detection engineering

13%

CI/CD and release automation

13%

Security policy and standards

10%

Monitoring and observability

10%

Data privacy compliance

10%

Vulnerability management

8%

Data pipeline engineering

8%
$ skills --emerging

AI safety and guardrails

29%

Agent security controls

15%

AI/ML infrastructure security

8%

AI-assisted development workflow

8%
$ skills --soft

Mentoring and code review

13%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonhigh
Gomoderate
TypeScriptmoderate
Javalow
Rustlow
$ tech --framework
Node.jslow
Reactlow
$ tech --platform
AWSmoderate
Azuremoderate
Google Cloud Platformmoderate
Kubernetesmoderate
Dockerlow
$ tech --tool
Terraformmoderate
GitHub Actionslow
Grafanalow
$ tech --concept
DASTmoderate
SASTmoderate
AI agentslow
CI/CDlow
OIDClow
SAMLlow
SCAlow
$04

Open Jobs

49 open Product Security Engineer jobs across 32 companies.

Harvey1w
Staff Security Software Engineer, IAM
San Francisco·Engineering
Anthropic2w
Staff+ Software Engineer, Account Creation
San Francisco, CA | New York City, NY | Seattle, WA·Engineering
Anthropic2w
Staff+ Software Engineer, Access Programs
San Francisco, CA | New York City, NY | Seattle, WA·Engineering
Decagon2w
Senior Software Engineer, Application Security
San Francisco·Engineering
Ambience Healthcare3w
Staff Security Engineer
San Francisco·Engineering
Cohere3w
Software Engineer, Security
Toronto·Engineering
Lovable3w
Staff / Principal Software Engineer, Detection and Response
Stockholm·Engineering
CHAOS Industries4w
DevSecOps Engineer
Washington, District of Columbia, United States·Engineering
Cohere1mo
Product Security Engineer, North Security
Toronto·Engineering
PhysicsX1mo
Security Engineer – DevSecOps and Security Architect
New York, New York·Engineering
Shield AI1mo
Senior DevSecOps Engineer
London·Engineering
OpenAI1mo
Software Engineer, Host Assurance
San Francisco·Engineering
True Anomaly1mo
Staff Platform Engineer, Security
Denver, CO; Long Beach, CA·Engineering
Cohere1mo
Senior Security Engineer
Toronto·Engineering
Harvey1mo
Software Engineer, Security
San Francisco·Engineering
Vannevar Labs1mo
Application Security Engineer
Remote·Engineering
Abnormal Security1mo
Senior Security Engineer
Remote - USA·Engineering
Harvey1mo
Staff Product Security Engineer
San Francisco·Engineering
Legora1mo
Security Engineer
Stockholm HQ·Engineering
Snorkel AI1mo
Software Engineer — Security
New York City, NY (Hybrid); San Francisco, CA (Hybrid)·Engineering