
Chainguard
Senior product security engineer
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps...

Close
·2 days agoClose
·2 days agoLocation
remote, United States
Commitment
Full Time
Level
Senior (5+ years)
Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication-first, AI-powered sales software designed to help you succeed and scale.
We're bootstrapped and profitable which means we answer to our customers and play by our rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can't figure out sales.
Close is a CRM built around the communication tools sales teams use every day: email, calling, SMS, workflows, reporting, and AI. Underneath that product is a broad technical surface —Python services and a large application backend, a TypeScript and React frontend, public APIs, Docker and Kubernetes, AWS infrastructure, and integrations with providers that handle sensitive customer data.
Security work happens across it all today, but the ownership is spread across Engineering, Infrastructure, and Security & Trust. We’re hiring our first dedicated Product Security Engineer to make that work systematic. You’ll report to the Backend Platform team manager within EPD (Engineering, Product, and Design), while working across the entire product and infrastructure surface. You’ll find vulnerabilities, determine which findings matter most, and drive them through remediation. Often you’ll fix the problem yourself. Other times you’ll give the owning team a clear reproduction, a practical path forward, and enough context to prioritize correctly.
You’ll analyze code, build proof-of-concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management. This is not a role where you forward scanner alerts and call the queue managed. Product and application security will be your responsibility. You’ll partner closely with our Infrastructure team on cloud security, access, and secrets, and with our Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.
This role is a new one at Close. You’ll have significant room to decide where better tooling, clearer ownership, and a small amount of code can reduce the most risk.
Our backend is primarily Python, with Flask and FastAPI services and TaskTiger and Temporal handling much of our asynchronous work. We expose REST and GraphQL APIs and store data in MongoDB, PostgreSQL, Elasticsearch, and Redis.
Our frontend is a large single-page TypeScript application built primarily with React. We bundle with Vite, target modern browsers, and test with Vitest, React Testing Library, Playwright, and Chromatic. The product updates in near real time and uses technologies including WebSockets and WebRTC. Our mobile application is built with React Native.
We build and test Docker images in CI/CD and continuously deploy them to Kubernetes on AWS. Our infrastructure uses managed services including EKS, MSK, and ElastiCache, alongside services running on EC2. Terraform and Ansible automate much of the underlying infrastructure, and our containerized local development environment lets engineers run the full system on their own machines.
For this role, our stack extends beyond simply backend or frontend: browser behavior, frontend state, API authorization, asynchronous processing, data access, third-party integrations, containers, and cloud configuration can all be part of the same attack path.
We love open sourcing our code and ideas on our GitHub and on The Making of Close, our behind-the-scenes Product & Engineering blog. Check out our open source projects like SocketShark, TaskTiger, LimitLion and ciso8601.
AI is both how we build and what we ship, and that's reshaped what engineering looks like. This is a transformation we’re embracing and find deeply exciting.
The work spans hands-on application security, security automation, vulnerability management, and infrastructure partnership. Depending on where you find the greatest risk and leverage, projects could include:
Tech you’ll touch: Python, TypeScript, React, Flask, FastAPI, GraphQL, Docker, Kubernetes, AWS, Vault, GitHub Actions, MongoDB, PostgreSQL, Redis, Kafka, Elasticsearch and the security tooling you help us choose.
Listen to our CEO and Founder, Steli Efti, tell the story of Close’s journey in the $0-30m Blueprint. Watch our culture video from our 2023 team retreat in Milan. Every year our entire team gathers in person to build connection, foster cross-functional collaboration, and have fun. In 2027, we're headed to Dusseldorf, Germany! Explore our product. Check out a demo!
We ask a few role-specific questions as part of our application process. These questions are designed to help us learn more about you from the start, so please answer each one thoughtfully. We see this as an opportunity to get to know you beyond your resume.
We use AI tools daily at Close and expect candidates to do the same. In evaluating your application, we aim to get a sense for you - the way you think, how you communicate, the work you've done. Applications that read as fully AI-generated will not be considered.
Regardless of fit, you can expect to hear back from our team with an update on the status of your candidacy. If you progress to the interview process, you'll receive a full outline of the role-specific steps in your first touchpoint with us. We do our best to make the hiring process clear and human.

Chainguard
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps...

Squads
About Squads Squads is a financial technology company building products and APIs for the stablecoin economy. We build on open infrastructure, global money, and internet capital markets to deliver...

Jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application & Product Security Engineer based in United States....

Jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Engineer - Organized Spaces based in United States. As a...

Netflix
At Netflix, our mission is to entertain the world. Together, we are writing the next episode - pushing the boundaries of storytelling, global fandom and making the unimaginable a reality. We are a...

Nest Health
Who is Nest Health? As the first value-based care provider built for families, Nest is on a mission to make comprehensive medical, behavioral, and social care radically accessible to America’s...

Jito Labs
About Jito Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority...