Product Security Engineer

Bugcrowd · Costa Rica · Engineering

Posted 2026-10-01

Apply for this role →

If you like owning problems end to end, making security a default property of everything we build, and working closely with engineering, we want to meet you. Bugcrowd is looking for security engineers who move beyond standard tooling and drive measurable security outcomes our customers can rely on. You will help us shape a culture where security helps others succeed, not just points out problems.

Essential Duties and Responsibilities

Partner Closely with Engineering: Refine architecture, validate new features, and drive security investment while prioritizing engineering velocity

Build Security Paved Roads: Contribute to the secure defaults, libraries, and "paved roads" that systematically eradicate entire classes of vulnerabilities rather than fixing bugs one by one

Create Feedback Loops: Tune security tooling such as SAST, DAST, SCA, and secret scanning to reduce noise and focus on what matters

Be our Best Customer: Ensure our bug bounty program can be a model for other customers. Experiment with new ways to leverage the creativity of the crowd. Provide feedback on new platform features to engineering and product

Own Projects End to End: Lead cross-functional product security projects from scoping through delivery, influencing product and engineering roadmaps and clearly communicating risk to both technical and non-technical stakeholders

Amplify our Impact: Use code and automation as a lever to scale coverage and eliminate repetitive work. Build systems based on incentives and accountability rather than just bureaucratic process

Education, Experience, Knowledge, Skills, and Abilities

3+ years of experience in product security, application security, or secure software development

Can review code, automate tasks, and build security tooling in at least one modern programming language (e.g., Python, Go, Ruby, Java)

Hands-on experience with core application security practices — threat modeling, secure code review, and automated testing (SAST, DAST, SCA) — and a solid grasp of common vulnerability classes (e.g., OWASP Top 10)

Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product.

Bachelor's degree in engineering, computer science or relevant field, or equivalent practical experience

Bonus Points (Preferred but not required)

Previous experience with Bug Bounty or vulnerability disclosure programs

A background in building "paved roads" or secure-by-default internal libraries to eliminate entire classes of vulnerabilities

Hands-on experience securing cloud-native platforms and Infrastructure as Code (e.g., Terraform, AWS, GCP, Kubernetes, Docker)

Experience working within a fast-paced, high-growth security or SaaS company

Working Conditions and Physical Requirements

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and / or standing - Must be able to remain in a stationary position 50% of the time

Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time

ADA Statement:

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Additional Requirements:

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, education verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Equal Opportunity Employer:

Bugcrowd is an Equal Opportunity and Affirmative Action employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Apply for this role →

← Back to all jobs