LaunchDarkly

ProductSecurityEngineerII

$116–187k United States Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Product Security Engineer II at LaunchDarkly. Skills: threat modeling, cloud security posture, AI tooling, security fundamentals. Lead threat modeling engagements. Own day-to-day triage of CNAPP findings end to end”

What You'll Achieve.

strengthen how we secure the platform; help developers move fast without sacrificing security; make our coverage deeper; evolve the practice from on-request to repeatable; reduce toil; prevent incidents rather than responds to them

Industry & Context.

Problems you'll solve

Look for patterns that point to systemic fixes instead of one-off cleanup; Catch issues early; proactive by default; spot drift early and fix the cause than chase symptoms after an incident

What They're Looking For.

Must Have

2 to 4 years of full-time experience in a security-focused role, AppSec, ProdSec, or cloud security preferred, Comfortable reading and critiquing pull requests in a modern stack, You should follow the code, ask sharp questions, and write small tools when it helps, Experience participating in or leading threat modeling exercises, Familiar with at least one structured approach (STRIDE, attack trees, or equivalent), Working knowledge of cloud security posture, fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations, Hands-on experience applying AI tooling to security or engineering work, You can point to specific examples where it changed how you operated

Nice to Have

Exposure to a CNAPP is a plus, Experience with developer tools, SaaS platforms, or feature management, Bug bounty triage experience (HackerOne, Bugcrowd), Familiarity with Go, Python, or TypeScript, Contributions to internal security tooling or open-source security projects

What You'll Do.

Lead threat modeling engagements

Own day-to-day triage of CNAPP findings end to end

Contribute to SDLC tooling

and bug bounty triage

Push the security floor up over time through documentation

small tooling improvements

How You'll Work.

Team & Collaboration

work closely with software engineers, product managers, and other security engineers; Partner with the ProdSec lead to evolve the practice; Partner with product engineering teams as a trusted reviewer; invest in relationships with the engineering, product, and leadership teams you work with

Communication Scope

explain the why; propose paths forward; Say no when needed, with reasons and alternatives

Full Job Description

About the Job: LaunchDarkly's Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You'll bring depth in security fundamentals and program design as a member of a small, high-leverage team with strong engineering instincts. LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us. You'll spend most of your time on threat modeling and cloud security posture, with rotating exposure to the rest of the ProdSec surface area. Your work will help developers move fast without sacrificing security, through automation, guidance, and the kind of partnership that makes the secure path the easy one. You'll report to the Director of Security and work closely with software engineers, product managers, and other security engineers. We expect you to bring a sharp point of view on where AI can take work off the team's plate and make our coverage deeper. Responsibilities: Lead threat modeling engagements on the features and services where the risk warrants it. Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running. Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup. Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands. Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives. Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts. Push the security floor up over time through documentation, office hours, small tooli

Free ATS check

Applying for this Product Security Engineer II role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about LaunchDarkly?

Real rants from real employees. Read before you apply.

Read Company Rants →