Staff Product Security Engineer
WHO ARE WE?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
ABOUT THE ROLE
This is UpGuard's first dedicated product security hire. You'll have significant ownership over the direction of product security at UpGuard as we scale. You won't be inheriting someone else's decisions. You'll be defining the security standards, tooling, and practices that protect UpGuard's products and infrastructure for years to come.
In this role, you'll work across our product and production environments: performing security reviews, managing vulnerabilities, and running detection and response operations in our cloud-native infrastructure. You'll collaborate closely with our product engineering and platform teams to secure our products, CI/CD pipelines, and production systems, and to embed security into how we build from the ground up.
The full remit of product security is broad, so we've been deliberate about sequencing. In your first 6–12 months you'll:
- Refresh threat modelling and security review as a standard part of how we ship.
- Figure out where AI actually helps in AppSec (code review, triage, coverage) and build what works
- Harden our GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code
The function sits at the heart of our engineering organisation, and you'll have genuine autonomy and influence: defining the security roadmap, driving best practices, and scaling our security posture as we grow.
This is a Staff-level individual contributor role.
WHAT YOU'LL DO
- Lead threat modelling and security reviews across UpGuard's product portfolio and cloud infrastructure, proactively surfacing attack vectors and designing mitigation strategies that scale with growth.
- Build automation, policy-as-code, and AI-driven security tooling that lets product engineering teams "shift left" and embeds security across the SDLC, leveraging agentic workflows to triage, review, and scale the reach of a lean security function.
- Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure.
- Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation with engineering teams, and building preventative controls across the software supply chain from development through production.
- Build scalable detection and response systems that catch malicious activity, triage the noise, and run incidents end to end.
- Build deep partnerships with our product engineering and platform teams, helping them deliver secure-by-design solutions.
You'll be building a function, not inheriting one; with real executive backing, at a company where product security is core to the business rather than a cost centre. Our engineering culture values iteration, collaboration, and speed, with a no-ego approach and pragmatic trade-offs. We're fully remote with optional offices in Sydney and Hobart, and no mandatory office attendance.
WHAT YOU'LL BRING
- 7+ years of experience in security engineering and/or software engineering/or security operations, work in cloud environments, with a focus on the below:
- Cloud security experience (GCP preferred, but AWS or Azure is welcome)
- Cloud native Kubernetes services (EKS/GKE/AKS) and strong container security principles
- Strong understanding of securing IAM and cloud identities
- Experience leading technical security reviews of products and architectures, running threat modelling exercises, and turning findings into security controls engineering teams can implement.
- Strong knowledge of common web application vulnerabilities and how to prevent them (OWASP Top 10 and similar).
- Hands-on experience with IAC and related tools (preferably Terraform/OpenTofu)
WHAT WILL GIVE YOU AN EDGE?
- Experience as the first security hire or founding member of a security function at a scaling company.
- Familiarity with AI/LLM security risks (e.g. OWASP LLM Top 10) and securing AI-powered product features.
- Strong backend engineering skills, particularly in Go
- Experience supporting SOC 2 / ISO 27001 audits from an engineering perspective.
- Public security research, CVEs, open-source security tooling, or conference talks.
- Offensive security skills, with the ability to validate findings through hands-on exploitation.
WHAT'S IN IT FOR YOU?
- WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
- Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
- $1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
- Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
- 18 weeks paid Parental Leave: Irrespective of parenting role
- Personal Leave Allowance: This includes sick & carer’s leave
- Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
- Top-spec hardware: All team members will be provided with top-spec laptops for their role
- Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work.
- Stock options: Share in UpGuard's growth
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: jobs.ashbyhq.com