Senior Security Engineer, Product Security

🏢 GoodLeap · all GoodLeap jobs
📍 Remote · United States
💰 $146,000 - $185,000 / year
📅 Posted 2026-09-03 · via RemoteIO
🏷 Security,TypeScript,Node.js,Python,AppSec
Apply on original site ↗

About GoodLeap
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Essential Job Duties and Responsibilities
- Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
- Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
- Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
- Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
- Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
- Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
- Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
- Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
- Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
- Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
- Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.

Required Skills, Knowledge, and Abilities
- You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your résumé.
- You can read code you didn’t write, across more than one language and stack, well enough to jud

← All remote jobs

Similar for you