> Markdown version of [/jobs/ext/3113167-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/3113167-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** SKYLIGHT INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $200,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Android Software Development, Software System Penetration Testing, Static Program Analysis, Information Leak Prevention, Firmware, Mobile Application Software, OAuth, OpenID, Open Web Application Security, Session Management, Software Engineering, Systems Integration, Software Vulnerability Management, Large Language Models, Software Security, Backend, Production Code - **Published:** September 27, 2026 - **Apply:** https://www.dice.com/job-detail/f167ed50-fe1d-4415-8ade-6ef131c131f6 ## About the Role * 6+ years in application or product security, with a software engineering background. You can ship production code, not just review it. * Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling. * Experience building and maintaining security tooling and automation (static analysis, CI integrations, custom scanners), and comfort working with LLM-based systems. * Hands-on experience running or triaging a bug bounty program. * A track record of getting engineering teams to prioritize and fix security issues through influence and good judgment, not escalation. * Clear written communication and the ability to explain risk to both engineers and non-technical stakeholders. Nice to have * Mobile application security experience (OWASP MASVS), ideally including shipping fixes in a mobile codebase. * Android platform or app security experience. * Experience assessing AI/LLM features for risks like prompt injection and data leakage. * Familiarity with children's privacy requirements (e.g. COPPA) or other sensitive consumer data. * Exposure to embedded, IoT, or firmware security. * Familiarity with the EU Cyber Resilience Act or UK PSTI. * Incident response experience. ## Description Skylight is a technology startup building the OS of the family. We make Skylight Calendar, the smart calendar loved by millions of families (plus Wired and the Wirecutter). Our latest product is Calendar 2, which just launched to rave reviews. Our mission is to connect loved ones by creating the world's simplest products and services that improve family life. Our founders are former venture capitalists and serial entrepreneurs who have scaled this business to $300M+ in annual revenue while being completely bootstrapped and profitable. We get to grow a happy, healthy company focused on making products our customers love without investors breathing down our necks. Smart, hardworking people who care about making actually meaningful products love working here. People like you. We're busy inventing new ways to simplify family life and help parents raise great kids - and we need your help! Come invent something new with us. The Role You'll own the day-to-day execution of our product security program across our cloud backend, mobile apps, and Android platform. You'll triage and drive remediation of vulnerabilities, run our bug bounty program, maintain and extend our AI-powered security scanning, and partner with product and engineering teams on design reviews before new features ship. When a team can't spare the time, you'll ship the fix yourself. You'll work closely with the Head of Security, who owns strategy and the product security roadmap, and you'll be the person engineering teams turn to for hands-on security expertise. What you'll do * Own the vulnerability management pipeline end to end: intake, triage, prioritization, and driving fixes to closure against defined remediation SLAs across Backend, Mobile, and Android teams. * Join our Platform pod where, with the team, you'll write and ship security fixes directly in our codebases. * Own and evolve our AI security scanning and verification pipeline. Tune it to reduce false positives, extend coverage to new repositories, and integrate it into CI. * Run our HackerOne bug bounty program: triage reports, validate findings, work with researchers, decide on payouts, and manage the vendor relationship. * Manage third-party penetration testing engagements from scoping through remediation. * Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products that handle children's data. * Review and advise on device and firmware security work led by our firmware team. * Provide metrics and data on findings, remediation, and SLA adherence to support compliance and leadership reporting. * Serve as a subject matter expert during product security incidents. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)