产品安全工程师
Product Security Engineer
职位描述:
YipitData 是颠覆性经济领域领先的市场研究和分析公司,最近从 Carlyle Group 获得 4.75 亿美元融资,估值超过 10 亿美元。每天,我们的专有技术分析数十亿个替代数据点,以揭示软件、AI、云、电子商务、网约车和支付等领域的可操作见解。
我们的数据和研究团队将原始数据转化为战略情报,提供准确、及时且高度情境化的分析,我们的客户——包括世界顶级投资基金和财富 500 强公司——依赖这些分析来推动高风险决策。从获取和授权新型数据集到严格的分析和专家叙事框架,我们的团队确保客户获得的不仅是数据,还有清晰度和信心。
我们在美国、亚太地区和印度设有办公室。我们获奖的以人为本的文化——连续三年被 Inc. 评为最佳工作场所——强调透明度、主人翁意识和持续精进。
在 YipitData 工作是什么感觉:
YipitData 不是一个可以混日子的地方——它是有抱负、注重影响力的职场人士的跳板。
从第一天起,你将主导有意义的工作,加速成长,并获得塑造职业生涯的曝光机会。
为什么顶尖人才选择 YipitData:
- 有意义的主人翁意识:你将主导具有实际业务成果的高影响力项目
- 快速成长:我们将数年的学习压缩为几个月
- 实力胜于头衔:信任和责任通过执行而非资历获得
- 有目的的高效:我们快速行动,互相支持,目标远大——始终有明确的目的和意图
如果你的雄心与你的工作态度相匹配,并且你渴望一个以成长、影响力和主人翁意识为常态的地方,YipitData 可能就是你一直在寻找的机会。
关于该职位:
YipitData 正在寻找一名产品安全工程师,帮助将安全性融入我们为客户提供的产品和服务中。
在这个职位上,你将与工程和产品团队紧密合作,贯穿整个开发周期。你将评估新产品和新技术,主导威胁建模和安全设计评审,识别漏洞,并帮助团队在问题进入生产环境前实施实际的修复方案。
这是一个需要亲自动手的职位,要求你了解现代应用的设计和构建方式。你应该能够熟练审查系统架构,分析漏洞,并提出解决方案。
查看英文原文
About Us:
YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B. Every day, our proprietary technology analyzes billions of alternative data points to uncover actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments.
Our data and research teams transform raw data into strategic intelligence, delivering accurate, timely, and deeply contextualized analysis that our customers—ranging from the world’s top investment funds to Fortune 500 companies—depend on to drive high-stakes decisions. From sourcing and licensing novel datasets to rigorous analysis and expert narrative framing, our teams ensure clients get not just data, but clarity and confidence.
We operate globally with offices in the US, APAC, and India. Our award-winning, people-centric culture—recognized by Inc. as a Best Workplace for three consecutive years—emphasizes transparency, ownership, and continuous mastery.
What It’s Like to Work at YipitData:
YipitData isn’t a place for coasting—it’s a launchpad for ambitious, impact-driven professionals.
From day one, you’ll take the lead on meaningful work, accelerate your growth, and gain exposure that shapes careers.
Why Top Talent Chooses YipitData:
- Ownership That Matters: You’ll lead high-impact projects with real business outcomes
- Rapid Growth: We compress years of learning into months
- Merit Over Titles: Trust and responsibility are earned through execution, not tenure
- Velocity with Purpose: We move fast, support each other, and aim high—always with purpose and intention
If your ambition is matched by your work ethic—and you're hungry for a place where growth, impact, and ownership are the norm—YipitData might be the opportunity you’ve been waiting for.
About The Role:
YipitData is looking for a Product Security Engineer to help build security into the products and services we deliver to customers.
In this role, you will partner closely with Engineering and Product teams throughout the development lifecycle. You will assess new products and technologies, lead threat modeling and security design reviews, identify vulnerabilities, and help teams implement practical fixes before issues reach production.
This is a hands-on role for someone who understands how modern applications are designed and built. You should be comfortable reviewing system architecture, analyzing vulnerabilities, working directly with engineers, and improving the security tools embedded in our development pipelines.
This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one of our office hubs, or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding.
The work hours are flexible on this team, but most employees work East Coast hours.
As Our Product Security Engineer, You Will:
- Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production
- Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked
- Find and validate vulnerabilities, separate real risk from noise, and help teams prioritize what actually matters
- Work alongside engineers to design remediate plans that protect customers without bringing development to a halt
- Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning
- Tune security tools and workflows so engineers receive useful findings instead of a flood of false positives
- Build automation that allows Product Security to keep pace as our products, engineering teams, and use of AI continue to grow
- Turn security lessons into clear standards, secure design patterns, coding guidance, and documentation engineers will actually use
- Help lead the response when product security issues arise, from initial investigation and containment through root cause analysis and long-term remediation
- Become a trusted partner to Engineering and Product by bringing strong security judgment and workable solutions to difficult decisions
- Explore emerging risks across cloud and AI-enabled products and help YipitData prepare for attack techniques that do not yet have a standard playbook
You Are Likely To Succeed If:
- You have worked in product security, application security, software engineering, penetration testing, or another role that taught you how applications are built and broken
- You can look at a complex system, follow the data, identify trust boundaries, and quickly understand where the real risks may be hiding
- You know how to threat model, review architecture, and assess applications without relying entirely on a checklist
- You can validate a vulnerability, determine whether it is actually exploitable, and explain why it matters to both engineers and business leaders
- You are comfortable working across APIs, cloud services, containers, serverless technologies, and CI/CD pipelines
- You have worked with tools such as SAST, DAST, dependency scanning, secret scanning, or infrastructure-as-code scanning, and know that getting useful results takes more than simply turning them on
- You can read and write code and are excited to automate repetitive security work using Python, JavaScript, or a similar language
- You bring strong judgment and can balance security, customer impact, engineering effort, and business priorities
- You communicate clearly, ask thoughtful questions, and can build credibility with both technical and non-technical teams
- You have secured AI-enabled products, agents, large language model applications, or MCP integrations and are excited by risks that do not yet have a perfect playbook
- You have deep experience with identity, authentication, authorization, or multi-tenant application security
- You have applied frameworks such as the OWASP Top 10, OWASP MCP Top 10, OWASP ASVS, or NIST in real-world environments
- You enjoy working across multiple products and engineering teams in an environment where priorities move quickly and no two days look exactly the same
What We Offer:
Our compensation package includes comprehensive benefits, perks, and a competitive salary:
- We care about your personal life, and we mean it. We offer flexible work hours, flexible vacation, a generous 401K match, parental leave, team events, wellness budget, learning reimbursement, and more!
- Your growth at YipitData is determined by the impact that you are making, not by tenure, unnecessary facetime, or office politics. Everyone at YipitData is empowered to learn, self-improve, and master their skills in an environment focused on ownership, respect, and trust. See more on our high-impact, high-opportunity work environment above!
- The annual base salary range for this position is anticipated to be $$180,000 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant’s experience, knowledge, skills, abilities, and internal team benchmarks.
This role may be performed fully remotely within the United States. Please note that our US headquarters are located in NYC. If the remote work is performed outside of these offices, income may be subject to New York State tax withholding.
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity employer.
Job Applicant Privacy Notice