Senior Product Security Engineer

9 October 2025
Apply Now
Deadline date:

Job Description

Job Description
About GitHub

As the global home for all developers, GitHub is the complete AI-powered developer platform to build, scale, and deliver secure software. Over 150+ million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate and experiment across 420+ million repositories. With all the collaborative features of GitHub, it has never been easier for individuals and teams to write faster, better code.

Locations

In this role you can work from Remote, United States

Overview

GitHub is transforming how the world builds secure software, and we are looking for a skilled Product Security Engineer to join our Security Services organization. This role is integral in ensuring the security of our software products by performing comprehensive security analyses, identifying vulnerabilities, and collaborating with product and engineering teams to embed security best practices throughout the development lifecycle.

The ideal candidate is passionate about security, with a strong focus on discovering and mitigating risks across GitHub’s products and services. You will engage with internal and external stakeholders, provide expert guidance, and play a key role in driving security initiatives across the organization.

Responsibilities

Analyze complex issues using multiple data sources to identify security problems and drive their resolution across systemic security issues.
Lead large-scale security reviews and work on architectural and design security reviews for feature areas, ensuring best practices for security architecture, design, and development are in place.
Collaborate with product and engineering teams to integrate security into the design, development, and deployment processes, providing insights on security designs through risk assessments, design reviews, and threat modeling.
Apply subject matter expertise to identify potential security issues, tools, mitigations, and processes, staying current with the evolving security landscape and sharing expertise with others through coaching.
Identify, prioritize, and manage moderately complex security issues that cause negative impact to customers, creating and driving the adoption of relevant mitigations.
Prepare leaders to respond to security threats that have significant reputational risks and translate highly technical information to nontechnical audiences to effectively communicate security risks.
Develop and maintain secure engineering documentation, guidance, and other collateral to support security best practices across the organization.

Qualifications

Required Qualifications:

7+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area
OR Associate’s Degree AND 6+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area
OR Bachelor’s Degree AND 5+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area
OR Master’s Degree AND 3+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area
OR Doctorate AND 1+ year(s) experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area
OR equivalent experience.
1+ year(s) experience in coding or software development.

Preferred Qualifications:

Experience with cloud security and modern software development practices.
Relevant security certifications such as OSWE, Burp Suite Certified Practitioner (BSCP), or equivalent.
Strong expertise in security principles, including the Security Development Lifecycle (SDL), and experience in vulnerability management.
Proven ability to influence others and effectively communicate and translate complex technical security concepts into actionable insights for diverse technical and non-technical audiences.
Proven ability to collaborate effectively with cross-functional teams to drive security initiatives.

Compensation Range

The base salary range for this job is USD $112,800.00 – USD $299,300.00 /Yr.

EWJD3