Staff Product Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
Skylight is a technology startup building the OS of the family. We make Skylight Calendar, the smart calendar loved by millions of families (plus Wired and the Wirecutter). Our latest product is Calendar 2, which just launched to rave reviews.
Our mission is to connect loved ones by creating the world’s simplest products and services that improve family life. Our founders are former venture capitalists and serial entrepreneurs who have scaled this business to $300M+ in annual revenue while being completely bootstrapped and profitable. We get to grow a happy, healthy company focused on making products our customers love without investors breathing down our necks.
Smart, hardworking people who care about making actually meaningful products love working here. People like you. We’re busy inventing new ways to simplify family life and help parents raise great kids - and we need your help! Come invent something new with us.
The Role
You’ll own the day-to-day execution of our product security program across our cloud backend, mobile apps, and Android platform. You’ll triage and drive remediation of vulnerabilities, run our bug bounty program, maintain and extend our AI-powered security scanning, and partner with product and engineering teams on design reviews before new features ship. When a team can’t spare the time, you’ll ship the fix yourself.
You’ll work closely with the Head of Security, who owns strategy and the product security roadmap, and you’ll be the person engineering teams turn to for hands-on security expertise.
What you’ll do
- Own the vulnerability management pipeline end to end: intake, triage, prioritization, and driving fixes to closure against defined remediation SLAs across Backend, Mobile, and Android teams.
- Join our Platform pod where, with the team, you’ll write and ship security fixes directly in our codebases.
- Own and evolve our AI security scanning and verification pipeline. Tune it to reduce false positives, extend coverage to new repositories, and integrate it into CI.
- Run our HackerOne bug bounty program: triage reports, validate findings, work with researchers, decide on payouts, and manage the vendor relationship.
- Manage third-party penetration testing engagements from scoping through remediation.
- Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products that handle children’s data.
- Review and advise on device and firmware security work led by our firmware team.
- Provide metrics and data on findings, remediation, and SLA adherence to support compliance and leadership reporting.
- Serve as a subject matter expert during product security incidents.
Requirements
- 6+ years in application or product security, with a software engineering background. You can ship production code, not just review it.
- Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling.
- Experience building and maintaining security tooling and automation (static analysis, CI integrations, custom scanners), and comfort working with LLM-based systems.
- Hands-on experience running or triaging a bug bounty program.
- A track record of getting engineering teams to prioritize and fix security issues through influence and good judgment, not escalation.
- Clear written communication and the ability to explain risk to both engineers and non-technical stakeholders.
Nice to have
- Mobile application security experience (OWASP MASVS), ideally including shipping fixes in a mobile codebase.
- Android platform or app security experience.
- Experience assessing AI/LLM features for risks like prompt injection and data leakage.
- Familiarity with children’s privacy requirements (e.g. COPPA) or other sensitive consumer data.
- Exposure to embedded, IoT, or firmware security.
- Familiarity with the EU Cyber Resilience Act or UK PSTI.
- Incident response experience.
Benefits & conditions
Our competitive compensation package includes:
- Competitive Salary + Equity Package
- 401K matching
- Wellness, learning, and home-office budgets
- Health, Dental & Vision Medical Plans
- Tremendous autonomy to set the direction of your work
- Unlimited PTO
- Company holidays on the first Friday of every month (Except November, December. & January)
The anticipated base salary range for this position is $200K-250K per year. This range reflects the compensation Skylight reasonably and in good faith expects to pay for the position at the time of posting. Actual compensation will be determined based on job-related factors, which may include experience, qualifications, skills, education, geographic location, and internal equity. Skylight also offers benefits, including medical, dental, vision, and paid time off.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 138 - Are you secure about this?
Dev Digest 120 - Apple and peers
The Overflow: Security and Privacy