Jump logo

Application Product Security Engineer

Jump

RemoteRemoteFull-time$130–170K/yrPosted 1mo agoVerified open 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$130–170K/yr
Location
RemoteRemote
Schedule
Full-time
Work Authorization
Not specified

Job overview

Jump is hiring an Application Product Security Engineer. Jump is hiring its first dedicated Application & Product Security Engineer to partner with engineering and product teams, embed security from design through delivery, and handle threat modeling, code reviews, tooling, incident response, and security guidance in a remote‑first startup environment.

Key focus areas include Partner with product and engineering teams during design and planning to identify risks early, Lead threat modeling and secure design reviews for new products and features, and Perform security‑focused code reviews and guide engineers to fix vulnerabilities.

Successful candidates bring 2-4 Years Application Security Experience and 2-4 Years Software Engineering With Security Responsibilities. Important skills include Threat Modeling, Secure Design Review, Security-Focused Code Reviews, Application Security Tooling, SAST, and Dependency Scanning. Preferred (not required): AWS, GCP, Azure, and Infrastructure-As-Code Familiarity.

Skills & qualifications

RequiredNice to have

Skills

Threat ModelingSecure Design ReviewSecurity-Focused Code ReviewsApplication Security ToolingSASTDependency ScanningSecrets DetectionCI/CDIncident ManagementBug Bounty Reports TriagePen Tests TriageVulnerability Scans TriageVulnerability RemediationSecurity Guidance DevelopmentPaved-Road Patterns DevelopmentSecurity Training DevelopmentCustomer Security QuestionnairesCloud Security ImprovementsCorporate Security ImprovementsOWASP Top 10Authn/Authz FlawsInjectionSSRFPythonTypeScriptJavaScriptGoCommunicationCollaborationComfort With AmbiguitySelf-DirectionAWSGCPAzureInfrastructure-as-Code FamiliaritySecuring AI/LLM-Powered ProductsWorking With Sensitive Financial DataSOC 2GDPRCTFs ContributionsBug Bounty ContributionsOpen-Source Security Tools ContributionsSecurity Community InvolvementSecure Design ReviewsCode ReviewsCloud SecurityInfrastructure as CodeCTFsOpen-Source Security Tools

Qualifications

2-4 Years Application Security Experience2-4 Years Software Engineering With Security ResponsibilitiesPrior Security Experience at a Startup or Small Security Team

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off

Full job description

Application & Product Security Engineer

Remote (US) | Full-Time | Security / Engineering

About Jump

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up — which means our customers trust us with some of their most sensitive client data. Security isn’t a checkbox for us; it’s core to the product and to earning that trust every day.

About the Role

We’re hiring our first dedicated Application & Product Security Engineer. You’ll partner with engineering and product teams from the earliest design conversations to make sure security is built into what we ship — not bolted on afterward. This is a hands-on, high-ownership role at a startup: some days you’ll be threat modeling a new feature, other days reviewing code, tuning our security tooling, or jumping in on an incident. If you like variety and want your work to directly shape how a product is built, this role is for you.

What You’ll Do

  • Partner with product and engineering teams during design and planning to identify risks early and build security into new features from the start.

  • Lead threat modeling and secure design reviews for new products, features, and architecture changes.

  • Perform security-focused code reviews and help engineers fix vulnerabilities — and understand how to avoid them next time.

  • Build and maintain application security tooling (SAST, dependency scanning, secrets detection) integrated into CI/CD.

  • Participate in incident response: triage, investigate, contain, and drive post-incident learning.

  • Triage findings from bug bounty reports, pen tests, and vulnerability scans, and drive remediation with owning teams.

  • Develop lightweight security guidance, paved-road patterns, and training that make the secure way the easy way.

  • Wear multiple hats as needed — from customer security questionnaires to cloud and corporate security improvements.

What We’re Looking For

  • 2–4 years of experience in application security, product security, or a software engineering role with significant security responsibilities.

  • Solid grasp of common vulnerability classes (OWASP Top 10, authn/authz flaws, injection, SSRF) and how to prevent them in real codebases.

  • Experience with threat modeling and secure design review, and the ability to explain risk in terms engineers and PMs care about.

  • Hands-on incident response experience — you’ve helped detect, investigate, or contain real security events.

  • Ability to read and write code (e.g., Python, TypeScript/JavaScript, Go, or similar) well enough to review PRs and build small tools.

  • Strong communication and collaboration skills — you build trust with engineers rather than throwing findings over the wall.

  • Comfort with ambiguity and shifting priorities; you can self-direct and wear multiple hats.

Nice to Have

  • Prior security experience at a startup or on a small security team (a major plus).

  • Cloud security experience (AWS, GCP, or Azure) and infrastructure-as-code familiarity.

  • Experience securing AI/LLM-powered products or working with sensitive financial data.

  • Familiarity with compliance frameworks (SOC 2, GDPR) as they relate to product security.

  • Contributions to CTFs, bug bounty, open-source security tools, or security community involvement.

Compensation & Benefits

Base salary: $130,000–$170,000, depending on experience and location, plus equity.

Benefits include health, dental, and vision coverage; flexible PTO; and a remote-first work

environment.

Equal Opportunity

Jump is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, disability, age, or veteran status.

You've read the whole posting — now see how you match it.