1

Staff Product Security Engineer Jobs (NOW HIRING)

Staff Product Security Engineer - Offensive Testing Department: Services Reports to: Head of PSC Engineering About the Role Connected products run the world: vehicles, medical devices, industrial ...

New

Product Security Engineer

San Jose, CA · On-site +1

$74.16 - $92.70/hr

Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits for ...

They are seeking a Product Security Engineer to ensure that security is embedded in their product engineering practices, working closely with development teams to implement secure design and ...

Product Security Engineer

Seattle, WA · On-site

$188K - $250K/yr

As a Product Security Engineer, you will: * Collaborate with Product Engineering teams throughout the SDLC, creating Threat Models, conducting Design Reviews, Secure Code Reviews, and manual testing ...

As a Product Security Engineer, you will: * Collaborate with Product Engineering teams throughout the SDLC, creating Threat Models, conducting Design Reviews, Secure Code Reviews, and manual testing ...

Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices and agile delivery. * Develop and advocate for cost ...

Product Security Engineer Full-time Lehi, UT You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits ...

Showing results 41-60

Staff Product Security Engineer information

See salary details

$23K

$99.3K

$192.5K

How much do staff product security engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for staff product security engineer in the United States is $99,330.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,000.00 and $125,000.00 per year, depending on experience, location, and employer.

What does a staff product security engineer do?

A Staff Product Security Engineer is responsible for ensuring the security of software products throughout their development lifecycle. This role involves identifying and mitigating security vulnerabilities, designing secure architectures, and implementing best practices to protect against threats. Staff-level engineers often lead security initiatives, conduct risk assessments, and collaborate with development and operations teams to integrate security into every stage of product development. They may also mentor junior engineers and help shape the organization's security strategy.

How does a staff product security engineer typically collaborate with development and product teams to ensure secure software delivery?

A Staff Product Security Engineer works closely with development and product teams by providing security guidance throughout the software development lifecycle. They participate in design reviews, threat modeling sessions, and code reviews to identify and mitigate potential security risks early. These engineers also help establish best practices, deliver security training, and coordinate vulnerability remediation efforts. Collaboration is typically cross-functional, requiring strong communication skills to bridge gaps between security and engineering priorities while supporting a culture of shared responsibility for product security.

What are the key skills and qualifications needed to thrive as a staff product security engineer, and why are they important?

To thrive as a Staff Product Security Engineer, you need deep expertise in application security, secure software development, and threat modeling, typically supported by a degree in computer science or a related field. Hands-on experience with security tools like static and dynamic analysis, vulnerability scanning, and familiarity with cloud security platforms and certifications such as CISSP or OSCP are highly valuable. Strong problem-solving skills, effective communication, and the ability to lead cross-functional teams distinguish top performers in this role. These skills are crucial to proactively identify risks, implement robust security measures, and foster a culture of security throughout the product lifecycle.

What is the difference between Staff Product Security Engineer vs Security Engineer?

AspectStaff Product Security EngineerSecurity Engineer
CredentialsRelevant certifications (CISSP, CEH), security trainingSimilar certifications, entry to mid-level security training
Work EnvironmentFocus on product security, cross-functional teams, strategic security planningImplementing security measures, monitoring, incident response
Employer & Industry UsageTech companies, product-focused organizationsVaried industries, IT departments, security teams

The main difference is that a Staff Product Security Engineer typically leads security efforts related to specific products, requiring strategic planning and cross-team collaboration. A Security Engineer often handles broader security tasks like monitoring and incident response. Both roles require similar credentials but differ in scope and focus.

More about Staff Product Security Engineer jobs

What cities are hiring for Staff Product Security Engineer jobs?

Cities with the most Staff Product Security Engineer job openings:

What states have the most Staff Product Security Engineer jobs?

States with the most job openings for Staff Product Security Engineer jobs include:

What job categories do people searching Staff Product Security Engineer jobs look for?

The top searched job categories for Staff Product Security Engineer jobs are:

Infographic showing various Staff Product Security Engineer job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 77% Full Time, 16% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 2% Hybrid, and 2% Remote job distribution, with an average salary of $99,330 per year, or $47.8 per hour.

Staff Product Security Engineer - Offensive Testing

Finite State

Full-time

Posted 3 days ago

New


Job description

Staff Product Security Engineer - Offensive Testing

Department: Services
Reports to: Head of PSC Engineering

About the Role

Connected products run the world: vehicles, medical devices, industrial systems, and critical infrastructure-and securing them is one of the hardest engineering problems there is.

At Finite State, PSC Engineers are the technical owners of that problem for our customers: engineers who earn trust by building and shipping from the field.

You will work directly with the security and engineering teams of some of the world's largest device manufacturers, analyzing their firmware, testing their products, assessing their risk, and building solutions on our platform that measurably harden what they ship.

You'll do it with an outstanding and unique toolkit: our product security platform, the most advanced AI tooling available, and a team of genuinely world-class expert peers. This combination allows a single sharp engineer to deliver what once required an entire consulting team-and that is exactly the point.

What You'll Do
  • Own the technical relationship with a portfolio of customer accounts. You are the engineer they trust-the person who understands their products, architecture, and risk.
  • Analyze real-world devices through firmware and binary analysis, SBOM and software supply chain investigations, vulnerability triage, and remediation guidance for products that ship in the millions.
  • Execute penetration tests and hands-on security assessments of embedded systems, including both hardware and software, and deliver findings that engineers can act on and executives can understand and defend.
  • Run threat modeling and product risk assessments that shape how customers design, build, and ship secure products.
  • Build integrations, data-source feeds, automation, SDK-based extensions, and AI-driven agentic workflows on the Finite State platform that solve your customers' specific problems faster than anyone thought possible.
  • Guide customers through the regulatory wave affecting connected devices, including the EU Cyber Resilience Act, RED, and FDA cybersecurity requirements, turning compliance pressure into engineering clarity.
  • Communicate at every altitude-from firmware engineers and security teams to CISOs and boardrooms-in writing and in the room.
  • Own customer outcomes across technical delivery, platform adoption, support, account health, renewals, and expansion opportunities.
  • Partner across Sales, Product, Engineering, and the broader PSC organization to identify customer risks, coordinate internal support, and ensure a consistent customer experience.
  • Capture reusable solutions, integrations, workflows, and customer insights that can improve the Finite State platform and benefit future customers.
Qualifications
  • 5+ years of experience in customer engineering, solutions engineering, technical account management, security consulting, field engineering, or a similar customer-facing technical role.
  • Hands-on experience building integrations, SDKs, automation, APIs, or platform extensions.
  • Strong technical troubleshooting and problem-solving skills.
  • Experience translating customer needs into practical technical solutions.
  • Strong written and verbal communication skills.
  • Ability to build trusted customer relationships and communicate effectively with both technical and nontechnical stakeholders.
  • Ability to manage multiple accounts, customer priorities, and technical deliverables simultaneously.
  • Experience working within established technical standards, delivery playbooks, or support processes.
  • Ability to own customer outcomes across adoption, delivery, support, and account health.
Skills and Competencies
  • Strong customer ownership and accountability
  • Technical judgment and problem-solving
  • Consultative communication
  • Solution design and implementation
  • Cross-functional collaboration
  • Ability to manage competing priorities
  • Clear documentation and knowledge sharing
  • Commercial awareness related to customer health, renewals, and expansion
  • Ability to work independently in customer-facing environments
What Makes You a Fit

You know your craft. You bring deep, hands-on product security expertise across embedded software and hardware security, firmware analysis, penetration testing, and threat and risk assessment. You've broken real devices and helped fix them.

You know the stack. You have a hands-on background evaluating the security posture of firmware, applications, networks, IoT, and embedded systems.

You improve the architecture. You have a proven track record of architecting features and hardening the security of complex networked or embedded environments, along with a strong command of the principles that drive secure product development and systemic design decisions.

You ship production code. You are experienced in building and deploying resilient, production-ready Linux and embedded systems.

You understand the adversary. You bring deep technical familiarity with reverse engineering techniques and the implementation of anti-tamper mechanisms.

You communicate at every altitude. You demonstrate exceptional professional clarity in writing and speech, with the ability to earn trust across technical and executive teams.

You build. You are proficient in one or more relevant modern programming languages, such as C/C++, Python, Go, Rust, TypeScript, or similar. You are comfortable working with APIs and automation and turning repetitive problems into scalable tools.

You are AI-native. You already use LLMs and agentic tooling as force multipliers in technical work, and you have the judgment to know where human ownership and validation are essential.

You are driven and self-directing. Give you a customer outcome and you find the path-no waiting to be told what to do. You hold yourself to a higher standard than anyone else sets for you.

You make others better. You share what you learn, draw on the expertise of your peers without ego, and build the kind of trust that makes customers ask for you by name.

You champion the team. You are committed to fostering a supportive, inclusive, and collaborative environment where every engineer and team member can excel.

Nice to Have

You are certified for the offensive. You hold advanced credentials such as CISSP, CSSLP, OSCP, or OSWE, or have a proven history in exploit development and hands-on vulnerability research.

You navigate the regulatory landscape. You have practical familiarity with global standards and requirements, including the EU Cyber Resilience Act, RED EN 18031, FDA premarket cybersecurity requirements, or IEC 62443.

You speak hardware and firmware. You have deep technical knowledge of RTOS and embedded Linux internals, including JTAG, UART, SPI interfaces, and wireless communication protocols.

You secure complex systems. You have an expert understanding of the security architectures found in aerospace, medical, automotive, smart energy, smart city, home and commercial cyber-physical environments, and mission-critical embedded systems.

You master federal cyber policy. You bring fluency in modern U.S. government methodologies, including JSIG, ICD 503, NIST SP 800-160, and Cyber Survivability guidance.

You know the hardware logic. You have hands-on experience developing for programmable logic devices using industry-standard engineering tools.

You ship resilient code. You have a consistent record of building, testing, and deploying production-ready embedded and Linux systems from the field.

Why This Job

Because you'll spend your time on the hard, interesting work: real devices, real adversaries, and real regulatory stakes.

You'll have the leverage of a platform and AI stack that most security engineers do not yet have, while working on a team small enough that your contributions are visible and your standards help set the standard.

We depend on smart engineers who use cutting-edge technology and each other's expertise to deliver something no one else can. If that sounds like a job description written for you, we should talk.

Why Finite State?
  • Be a part of building the leading platform for connected device cybersecurity.
  • Join a fast-moving team that values transparency, innovation, and impact.
  • Work fully remotely with a high degree of autonomy and ownership.
  • Comprehensive Benefits
  • Investment: We offer learning stipends to support your professional development
  • Equity: We offer equity so you can share in our growth and success
  • Help solve some of the most pressing cybersecurity challenges facing connected device  manufacturers and the millions of people who depend on them