Hightouch logo

Product Security Engineer

Hightouch

Remote · USJob$180–400K/yrPosted 2 days agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$180–400K/yr
Location
Remote · US
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Hightouch is hiring its first dedicated Product Security Engineer to define and own application security as the company scales. The hands-on, high-autonomy role focuses on security challenges in distributed systems, including multi-tenant isolation, access control, security architecture, internet-facing APIs, and multi-region, multi-cloud infrastructure. The role is remote across North America and emphasizes impact and potential for growth over a specific number of years of experience.

Skills & qualifications

RequiredNice to have

Skills

Application SecurityThreat ModelingAccess ControlsData InfrastructureRate LimitingApplication CodeDistributed SystemsProduction FixesTenant IsolationAuthorization ModelsCloud SecurityPII HandlingData ResidencyGDPR/CCPA Technical ControlsSecurity ProgramsBug BountyPenetration TestingExternal Researcher CollaborationCross-Engineering Partnership

Qualifications

Early Security Hire at SaaS or Data Infrastructure CompanyEarly Engineer in Data Infrastructure

Full job description

Product Security Engineer Remote (North America)

Apply now About the Role This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers. This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

  • Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

  • Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them. We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation.

About You You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust. Experience that's relevant:

  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company

  • Securing multi-tenant platforms: tenant isolation, authorization models, etc

  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts

  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built. Interview Process

  • Recruiter Screen [30m] - Introductory mutual fit assessment

  • Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

  • Core interview [90m] - deep dive on distributed systems knowledge

  • Hiring Manager Interview [60m] - What you've built in the past, how you work

  • Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

Apply for this role Loading... Loading application form…

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.