Product Security Engineer
Plaid
The Product Security team is responsible for the processes, policies, controls, and engineering systems that secure Plaid’s developer- and consumer-facing products. The team focuses on areas including application security, vulnerability management, secure development lifecycle, penetration testing, and cloud security. Beyond setting standards, the team builds the services, components, and workflows that protect Plaid’s products at scale. By moving security “left,” Product Security makes the secure path the easiest path for engineers across the company.
Plaid is looking for a Product Security Engineer who is fundamentally a builder. Unlike traditional product security roles, this position is designed for a software engineer who wants to solve security challenges at scale by developing production-grade services, libraries, and frameworks. In this role, you’ll build and maintain Plaid’s vulnerability management orchestration service, automate workflows to reduce operational toil, and create solutions that eliminate entire classes of vulnerabilities. You’ll also partner closely with product engineers to ensure services meet security standards, support incident response and security awareness efforts, and collaborate across the security platform organization to deliver the engineering foundations that make secure development the default at Plaid.
Responsibilities
Build the secure engineering foundations that secure the future of digital finance.
Develop maintainable and secure software to enhance Plaid's security posture and create paved roads for developers for easy and default integration of security controls.
Design, develop, and maintain security-critical services and components.
Develop internal tooling to automate vulnerability detection, dependency management, and remediation workflows within the CI/CD pipeline.
Replace manual security gates with engineered solutions that allow product teams to ship faster and more securely.
Communicate effectively with managers and team members regarding project deliverables and progress.
Design and implement technical solutions that align with the evolving needs of the business.
Proactively identify and address security vulnerabilities in products and services.
Actively participate in incident response and security awareness initiatives.
Qualifications
2 + years of professional experience building and scaling production services.
Ability to architect software systems to meet security, privacy, usability, scalability and cost requirements.
Experience building systems or services related to vulnerability management, data encryption, key management, secret management, user authentication, service authentication, authorization systems, and security policy enforcement.
Experience designing distributed systems and microservices with a focus on performance and reliability.
Familiarity with modern cloud infrastructure (AWS, Kubernetes, Terraform) and how to integrate security controls into them.
A passion for creating tools and libraries that other engineers love to use.
Passionate about educating others on security and privacy.
While these experience and characteristics are not prerequisites, candidates who possess them would be well-suited for the role:
188748 - 260652 USD a year