runpod - Full Stack Security Engineer (Application & Product)
Requirements
• RunPod is seeking a proactive AppSec professional who believes in Integrated Security. You won't just toss PDF reports over the fence; you will write code to fix vulnerabilities, build automated security guardrails into our CI/CD pipelines, and foster a security-first culture among our developers. • 5+ years of experience in application security, product security, or as a software engineer with a heavy security focus. • Strong programming and code-review skills in languages like Python, Go, JavaScript/TypeScript, or similar modern stacks. • Deep understanding of web application vulnerabilities (OWASP Top 10), API security (REST/GraphQL), and modern authentication flows (OAuth, OIDC, JWT). • Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP). • Experience building and maintaining automated security pipelines (DevSecOps). • Ability to translate complex security risks into actionable engineering tasks. • Relevant application security certifications (e.g., OSWE, GWAPT, CISSP). • Experience securing cloud-native applications running on Kubernetes/Docker environments. • Background in managing bug bounty programs or coordinated vulnerability disclosures. • What You’ll Receive: • The competitive base pay for this position ranges from ($152,000 - $175,000). This salary range may be inclusive of several career levels at Runpod and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location • Meaningful equity in a fast-growing company- everyone on the team receives stock options — your impact drives our growth, and you share in the upside. • Generous medical, dental & vision plans • Flexible PTO- take the time you need to recharge • Most roles are remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication • Join a passionate team on the cutting edge of AI infrastructure — where culture, learning, and ownership are at the heart of how we scale. • $1,200 Home Office & Equipment Stipend- We set you up for success from day one with gear and support to create your ideal workspace
Responsibilities
• Product Security: Lead threat modeling, architecture reviews, and code reviews for our web applications, APIs, and microservices. • Vulnerability Remediation: Actively develop and commit code to fix security flaws in our Python, Go, or JavaScript/TypeScript codebases alongside the engineering team. • DevSecOps: Implement, tune, and manage security testing tools (SAST, DAST, SCA) within our CI/CD pipelines to catch vulnerabilities early in the SDLC. • Edge & Application Defense: Configure and manage application-layer security controls, including Web Application Firewalls (WAF), bot protection, and API gateways. • Security Championing: Provide security guidance, secure coding training, and standard operating procedures to development teams. • Compliance & Operations: Collaborate with operations to ensure product-level adherence to relevant frameworks (e.g., SOC 2, ISO 27001, GDPR) and participate in bug bounty triage.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT