Jobs Companies Yahoo Paranoids Senior Product Security Engineer

À propos de ce poste Paranoids Senior Product Security Engineer chez Yahoo

Yahoo · Sur site · United States of America
Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

A Little About Us

When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".

Within the Paranoids, the Product Security team is on the front line — embedded directly in how Yahoo's products get built. We live inside the software development lifecycle, from the first line of code to production, hunting for weaknesses before an adversary can. Threat Modeling, Static and Dynamic reviews, architecture review, bug bounty — this is where security meets engineering, and where we make sure "shipping fast" and "shipping safe" are never a tradeoff.

A Lot About You

As a Paranoids Product Security Engineer, you have the opportunity to guide secure development for a product area and in addition, own and drive secure development initiatives affecting the overall enterprise.

Responsibilities

  • Independently lead application and mobile security assessments, from design to deployment, for key enterprise products.

  • Drive threat modeling and risk assessments for high-impact systems, guiding engineering teams through secure design trade-offs.

  • Partner with developers to embed security into build and release pipelines, and identify opportunities for automation.

  • Develop and maintain internal security tooling and reusable frameworks to scale security across teams.

  • Lead the remediation of critical vulnerabilities and help coordinate with incident response when needed.

  • Mentor other security engineers and advocate for secure development practices across product and engineering teams.

  • Collaborate cross-functionally with cloud security, infrastructure, and compliance teams to ensure holistic protection of applications and data.

  • Stay informed on emerging threats, frameworks, and technologies, and proactively improve security posture through innovation.

Minimum Requirements

  • 5+ years of experience in application or product security, with demonstrated impact securing large-scale web and/or mobile applications.

  • Deep understanding of secure application architecture, including authentication, authorization, encryption, and data protection across distributed systems.

  • Proven hands-on experience performing threat modeling, secure design reviews, and code assessments for complex applications and APIs.

  • Strong technical knowledge of web technologies (HTTP, TLS, CSP, cookies, OAuth, JWTs, GraphQL, REST APIs) and mobile security (iOS/Android app security models, keychains, secure storage, code obfuscation).

  • Proficiency using and integrating application security tooling (SAST, DAST, IAST, dependency scanning, container scanning) into CI/CD pipelines.

  • Practical experience with vulnerability triage and remediation workflows — coordinating across engineering teams to ensure timely fixes.

  • Hands-on skills in at least one backend or systems programming language (e.g., Go, Java, Python, C#) and one frontend or mobile language (e.g., JavaScript/TypeScript, Swift, Kotlin).

  • Experience contributing to or automating security testing and validation in continuous integration environments.

  • Strong ability to communicate security risks and solutions clearly to engineers, managers, and non-technical stakeholders.

  • Track record of driving security improvements across teams — through frameworks, documentation, training, or developer engagement.

  • Working knowledge of AI/LLM application security fundamentals — including prompt injection, insecure output handling, sensitive data exposure through model inputs/outputs, and the OWASP Top 10 for LLM Applications.

  • Experience reviewing applications that integrate LLMs or AI services, with the ability to identify common risks across AI pipelines (RAG, agentic tools, model APIs).

  • Bachelors Degree in a relevant field or equivalent work experience

Preferred

  • Experience designing and maintaining secure frameworks or libraries used by multiple engineering teams.

  • Familiarity with cloud-native application security (AWS/GCP/Azure), identity and access management, and secrets management.

  • Experience leading or mentoring junior engineers in secure coding, threat modeling, and vulnerability management.

  • Background with mobile application hardening, anti-tampering, and reverse engineering defenses.

  • Understanding of supply chain security, including dependency management and integrity verification.

  • Contributions to open-source security tools, security research, or industry standards bodies.

  • Experience threat modeling AI/ML systems, including RAG pipelines, agentic workflows, and tool-use frameworks (e.g., Model Context Protocol).

  • Familiarity with model supply chain security — model and dataset provenance, weight integrity, and risks of third-party models and embeddings.

  • Hands-on experience with AI-assisted security tooling (e.g., LLM-powered code review, automated triage, security agents) and an understanding of their limitations and failure modes.

  • Awareness of emerging AI security frameworks such as NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.

  • Certifications such as GWEB, GWAPT, OSWE, or CSSLP a plus, but not required.

The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies; exercising sound judgment; working effectively, safely and inclusively with others; exhibiting trustworthiness and meeting expectations; and safeguarding business operations and brand integrity.

At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!

Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo will consider for employment qualified applicants with criminal histories in a manner consistent with applicable law. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call +1.866.772.3182. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.

We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.

The compensation for this position ranges from $128,250.00 - $266,875.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.

Currently work for Yahoo? Please apply on our internal career site.

Prêt à postuler chez Yahoo ?
Postuler chez Yahoo

Comment se compare ce salaire pour Application Security

Ce poste paie $197,563/yrau-dessus de la fourchette habituelle pour les postes Application Security.

$104,940 la médiane $160,775 $178,025

Fourchette typique $129,825–$165,000/yr, à partir de 9 annonces Application Security comparables sur JobsRadar (rémunération annualisée en USD). Voir les aperçus de salaire pour Application Security →

À propos de Yahoo

Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

Voir tous les emplois chez Yahoo →

Emplois similaires

HP
Software Product Security Engineer Intern
HP
⚡ Postuler tôt Spring, Texas, United States o... Sur site $72,800–$83,200
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
HP
Software Product Security Engineer Intern
HP
⚡ Postuler tôt Spring, Texas, United States o... Sur site $72,800–$83,200
● Nouveau 👁 Vu ✓ Postulé il y a 2 j
HP
Software Product Security Engineer
HP
⚡ Postuler tôt Spring, Texas, United States o... Sur site $123,100–$150,400
● Nouveau 👁 Vu ✓ Postulé il y a 2 j
General Motors
Senior Product Cybersecurity Engineer – Secure Product Architecture
General Motors
⚡ Postuler tôt Warren, Michigan, United State... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 5 j
ME
Sr. Product Security Engineer (Embedded/IoT)
Medtronic
⚡ Postuler tôt Minneapolis, Minnesota, United... Sur site $132,000–$198,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
ME
Sr. Product Security Engineer (Cloud Security)
Medtronic
⚡ Postuler tôt Fridley, Minnesota, United Sta... Sur site $132,000–$198,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Johnson & Johnson
Principal Product Security Engineer
Johnson & Johnson
⚡ Postuler tôt Santa Clara, California, Unite... Sur site $118,000–$203,550
● Nouveau 👁 Vu ✓ Postulé il y a 2 sem.
General Motors
Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT)
General Motors
⚡ Postuler tôt Warren, Michigan, United State... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 sem.
General Motors
Senior Product Cybersecurity Engineer, Product Security Validation
General Motors
⚡ Postuler tôt Warren, Michigan, United State... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 sem.

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Yahoo

Voir tous les emplois chez Yahoo →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit