Skip to content

Open nowPosted 10 days ago

Product Security Engineer

WorkOS31 open roles

Pay
$175,000 – $275,000 a year
Where
United States & Canada
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowProduct Security EngineerWorkOS · United States & Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on WorkOS's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. WorkOS postings stay open a median of 16 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 10 days ago

WorkOS median: 16 days open

The posting

About WorkOS 🚀

WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations.

We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Sierra, and Plaid.

As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.

About the Security team

The Security team at WorkOS is responsible for keeping the data and identities of hundreds of millions of users secure. Security is fundamental to our products, and customer trust is the foundation of our success.

We are a highly collaborative group with a strong engineering mindset. Our security program is shaped by hands-on experience attacking and defending systems, and applying lessons from across the industry. We embrace the latest advancements in practices and tooling that make modern security teams effective.

We are comfortable in code and collaborate often with engineering to create products that are secure by default.

Who we’re looking for

- Risk-focused and pragmatic. You excel at identifying and reasoning about security risk in real-world contexts. You prioritize ruthlessly, always asking: what's the most effective way to reduce risk right now and in the long term?

- A builder who can break things. You're comfortable reading and writing code, and you have a passion for deeply understanding the products you secure. You think like an attacker to find subtle, high impact vulnerabilities and like a defender to design pragmatic, effective mitigations.

- A strong partner to engineering. You build trust with engineers by understanding their priorities, making security frictionless, and finding ways to make the secure path, the easiest path.

- Excited about AI. You're embracing AI and automation to scale security and reduce toil.

- Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.

Responsibilities

- Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.

- Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.

- Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.

- Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.

- Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.

- Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.

- Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.

Qualifications

- 5+ years of experience in a security engineering or security-focused software engineering role.

- Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.

- Familiarity with and experience using common industry tooling.

- Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.

- Strong written and verbal communication skills, particularly in partnering with engineering teams.

- Comfortable reading and writing code, and able to effectively leverage AI during the process.

- Bonus: Experience in the authentication and identity domain.

- Bonus: Experience writing production level code, especially developing security features.

Benefits and Perks (US Only) 💖

At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.

- 401k matching

- Competitive Equity

- Healthcare, dental and vision coverage

- FSA, ST/LT Disability, Voluntary Life

- Carrot fertility benefits

- 20 days paid vacation + 10 holidays + unlimited sick leave

- 12 weeks fully paid parental leave

- Fitness: Monthly stipend for gyms, yoga classes, race registrations or whatever keeps you active

- Wellness: Monthly stipend for a massage, meditations class, therapy, or activities that enhance your well-being

- Commuter benefits for hybrid employees in SF/NYC

- Unlimited token usage!

Please inquire directly with our recruiting team for benefits available to those working outside the US.

Equal Opportunity Employer

WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against WorkOS's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on WorkOS's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    WorkOS's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.