> Markdown version of [/jobs/ext/1920610-product-security-engineer-server](https://www.wearedevelopers.com/jobs/ext/1920610-product-security-engineer-server). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Engineer, Server - **Company:** MongoDB - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $106,000.0 - $209,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, C++ (Programming Language), Code Review, Databases, Data Security, Database Security, Fuzz Testing, Key Management, MongoDB, Memory Leaks, Database Engines, Scripting, Software Security - **Published:** August 4, 2026 - **Apply:** https://www.juju.com/job/00000000gllf0a ## About the Role + 3 years of experience in application security, software security, or product security + Demonstrated experience in C++ programming, performing security assessments on low-level codebases, and implementing remediation strategies for memory-related security flaws such as buffer overflows and memory leaks + Scripting experience and ability to contribute code back to our environments + Comfortable leading threat modeling and being a security ambassador to other engineering teams + Communicate complex technical issues in a simple manner that builds trust with a variety of audiences + A strong sense of ownership and delivery + Can facilitate a conversation rather than dominate it + Skilled at providing collaborative, actionable feedback, not just a list of flaws Don't feel that you meet all of the requirements? We encourage you to apply anyway because studies have shown that some strong candidates may self-select out of the interview process prematurely. We have a diverse, inclusive, equitable, and high-performing environment at MongoDB and want to continuously improve our ability to deliver for customers. Nice to Haves + Subject matter expertise in database security, or data security + Knowledge of database engines, database internals, or applied cryptography + Experience contributing or partnering with security researchers to identify vulnerabilities that eventually are published CVEs or administrative responsibilities of a CNA ## Description With a strong security engineering background, you're looking for a role that gives you the freedom to increase MongoDB's resonance with customers by strengthening our core database products. You're passionate about solving hard security engineering problems while putting a strong emphasis on customer experience, leveraging your own significant experience. You enjoy collaborating with different teams to innovate and implement pragmatic solutions., + You will take ownership, define strategy, and drive improvement for parts of our program such as fuzzing, threat modeling, secrets management, or container security + You will support engineering teams when they respond to security issues, such as providing risk analysis and proof of concept + Advocate for and contribute to complex security projects from inception through completion + Drive architecture, patterns, and processes across Server Engineering that make security the easiest path + Partner closely with engineering teams to design and implement security controls across our software and systems + Research and POC new attacks against our systems. Plan and perform product security assessments including architecture review threat modeling, code review, pen testing and general security consulting to proactively build security controls + Serve as a security subject matter expert for software security and architecture ## Related Videos - [Protector Of The Realm](https://www.wearedevelopers.com/videos/591-protector-of-the-realm) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [NoSQL Data Modeling for Front-end Developers](https://www.wearedevelopers.com/videos/297-nosql-data-modeling-for-front-end-developers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)