高级产品安全工程师(合同制)
Senior Product Security Engineer (Contract)
关于Iru
Iru是专为全球增长最快的公司打造的AI驱动的安全与IT平台,用于保护用户、应用程序和设备。面向AI时代而构建,Iru整合了身份与访问管理、端点安全与管理以及合规自动化,简化了技术栈,让IT和安全团队重新获得时间和控制权。
Iru获得了科技领域最聪明投资者的支持——General Catalyst、Tiger Global、Felicis、Greycroft和First Round Capital。2024年7月,Iru从General Catalyst融资1亿美元,公司估值达8.5亿美元。客户包括Cursor、Vercel、Lovable、Replit和Mercor,Iru还与ServiceNow和AWS等行业领导者合作。Iru被列为Forbes 2025年美国最佳创业雇主名单,以员工参与度和满意度著称。
机会介绍
我们正在寻找一位高度专业的高级产品安全工程师,进行为期6个月的合同工作(每周40小时),将安全嵌入产品开发周期。这是一项实践性很强的工程岗位,负责早期识别安全风险,与开发团队合作修复问题,进行安全审查,执行应用安全测试,并帮助构建安全设计的产品。
该职位将与工程、云安全、基础设施、合规和产品管理团队紧密合作,确保安全贯穿整个SDLC,同时保持开发速度。
你将负责的工作
应用安全
- 对新产品和功能进行安全设计和架构审查。
- 对应用程序、API和AI支持的服务进行威胁建模。
- 在整个SDLC中审查应用安全状况。
- 与工程团队合作优先处理并修复漏洞。
- 审查身份验证、授权和访问控制的实现。
安全测试
- 执行手动网页、API、胖客户端和移动应用的渗透测试。
- 验证第三方渗透测试的结果。
- 进行安全代码审查。
- 验证安全漏洞的修复情况。
安全开发
- 推动安全编码实践的采用。
- 与开发人员合作,在整个SDLC中提升安全性。
- 协助制定产品安全标准和工程防护措施。
- 开发可重复使用的安全模式和参考架构。
漏洞管理
- 处理来自SAST、DAST、SCA、容器扫描和云安全工具的发现结果。
- 与工程团队合作
查看英文原文
About Iru
Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps, and devices. Built for the AI era, Iru unifies identity & access, endpoint security & management, and compliance automation—collapsing the stack and giving IT & security time and control back.
Iru is backed by some of the smartest investors in tech—General Catalyst, Tiger Global, Felicis, Greycroft, and First Round Capital. In July 2024, Iru raised $100 million from General Catalyst, valuing the company at $850 million. Customers include Cursor, Vercel, Lovable, Replit, and Mercor, and Iru partners with industry leaders such as ServiceNow and AWS. Iru was named to Forbes’ America’s Best Startup Employers 2025 list for employee engagement and satisfaction.
The Opportunity
We're seeking a highly technical Senior Product Security Engineer for a 6-month contract (40 hours/week) to embed security into the product development lifecycle. This is a hands-on engineering role responsible for identifying security risks early, partnering with development teams on remediation, conducting security reviews, performing application security testing, and helping build secure-by-design products.
This role will work closely with Engineering, Cloud Security, Infrastructure, Compliance, and Product Management to ensure security is integrated throughout the SDLC while enabling developer velocity.
What You'll Do
Application Security
- Perform security design and architecture reviews for new products and features.
- Conduct threat modeling for applications, APIs, and AI-enabled services.
- Review application security posture throughout the SDLC.
- Partner with engineering teams to prioritize and remediate vulnerabilities.
- Review authentication, authorization, and access control implementations.
Security Testing
- Perform manual web, API, thick-client, and mobile application penetration testing.
- Validate findings from third-party penetration tests.
- Conduct secure code reviews.
- Verify remediation of security vulnerabilities.
Secure Development
- Drive adoption of secure coding practices.
- Partner with developers to improve security throughout the SDLC.
- Help define Product Security standards and engineering guardrails.
- Develop reusable security patterns and reference architectures.
Vulnerability Management
- Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools.
- Work with engineering teams to prioritize remediation.
- Track remediation SLAs and security metrics.
AI Security
- Assess AI-enabled products for security risks.
- Review LLM integrations and AI workflows.
- Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses.
- Help define secure AI engineering standards.
Security Automation
- Improve automation of security testing throughout CI/CD.
- Integrate security tooling into developer workflows.
- Build scripts and tooling that reduce manual security work.
Cross-functional Partnership
- Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams.
- Support customer security questionnaires related to product security.
- Assist Sales Engineering with security discussions when needed.
Qualifications
- 5+ years in Product Security or Application Security.
- Strong understanding of modern application architectures.
- Experience securing:
- Web applications
- APIs
- Microservices
- Cloud-native applications
- Experience performing threat modeling.
- Experience conducting penetration testing.
- Strong understanding of:
- OWASP Top 10
- OWASP API Top 10
- Authentication & Authorization
- OAuth / OIDC
- Secure SDLC
- Experience with SAST, DAST, SCA, and container security.
- Experience partnering directly with engineering teams.
- Strong written and verbal communication skills.
Preferred
- Experience securing AI/LLM applications.
- Experience with Kubernetes and containers.
- Familiarity with cloud security (AWS, Azure, or GCP).
- Experience with GitHub Actions or CI/CD security.
- Experience using:
- Snyk
- Burp Suite Pro
- Semgrep
- Wiz
- GitHub Advanced Security
- Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus
Benefits & Perks
• Competitive salary
• 100% individual and dependent medical + dental + vision coverage
• 401(K) with 4% company match
• 20 days PTO
• Iru Wellness Week the first week in July
• Equity for full-time employees
• Up to 16 weeks of paid leave for new parents
• Paid Family and Medical Leave
• Exciting opportunities for career growth
We are excited to be serving a significant need for a fast-growing market, and are proud of the high-performing team we have brought together so far. If you’re someone who wants to engage in new, exciting projects that will challenge your skills in the best way possible, we would love to connect with you.
At Iru, we believe in fostering an inclusive environment in which employees feel encouraged to share their unique perspectives, leverage their strengths, and act authentically. We know that diverse teams are strong teams, and welcome those from all backgrounds and varying experiences.
Iru is proud to be an equal opportunity employer committed to diversity and inclusion in the workplace. Qualified applicants will be considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, physical or mental disability, protected veteran or military status or any other status protected by applicable law.
Originally posted on Himalayas