Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Lead Product Security Engineer image - Rise Careers
Job details

Lead Product Security Engineer

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018.

 

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.


Position Summary

The GoodLeap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap’s customer, partner, and employee information.


The product and application lead engineer role provides a unique opportunity to shape the security and resilience of GoodLeap products, services, and applications. In this role, you will work closely with the product, engineering, and business teams within GoodLeap's business units, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of the products and services developed and operated by the business unit.  


You will be embedded within the business unit and have a dotted-line reporting relationship to the product or business lead for the unit. Your oversight will encompass:  


Product features: Identifying potential misuse and abuse cases, proposing features to address these scenarios, and defining product features to meet resilience requirements.  

Build-time controls: Managing application security controls and activities during development.  

Runtime controls: Overseeing security measures for deployed products.  

Additionally, you will represent all areas of security for the business unit(s) you are embedded in, spanning governance, risk, and compliance (GRC) to security monitoring. You will also have the authority to involve other security team members as needed.  


While you will take on multiple responsibilities—from advisor to builder and beyond—your primary focus will be designing and building product security services and processes, creating product and application security patterns and practices, and fostering strong relationships with product, business, and engineering teams.  


Essential Job Duties & Responsibilities
  • Lead, participate in, and contribute to partnerships between security, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap products and services.  
  • Define and refine processes such as threat modeling, embedment models, and the prioritization of features, defects, and vulnerabilities.  
  • Assist the red team with ongoing activities, including bug bounty programs and continuous penetration testing platforms.  
  • Contribute to investigations, threat hunting, and incident response activities in a supporting role. Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.  
  • Support the security operations team with the vulnerability management lifecycle for products and services under your purview.  
  • Select and operate product and application security solutions, from DAST/SAST, SCA, Threat Modeling, etc. 


Required Skills, Knowledge and Abilities
  • Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.  
  • Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.  
  • Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.  
  • Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).  
  • Proven ability to establish credibility and build trust with engineers and operational staff; confident yet humble.  
  • Hands-on experience with microservices and associated orchestration tools, such as ECS, EKS, Nomad, and Istio, with an understanding of the operational and security implications of these technologies.  
  • Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.  
  • Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.  
  • Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.  
  • Prior experience developing security services for products or enterprise platforms, ideally using Python, Node.js, TypeScript, or .NET.  
  • Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.  
  • Strong understanding of cryptography and key management use cases.  
  • Experience overseeing vulnerability and threat management at the platform and application levels.  
  • Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.  
  • Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution. 


$164,000 - $187,000 a year
This role may be eligible for a bonus and equity.

Additional Information Regarding Job Duties and Job Descriptions:


Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.


If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you!  Apply today!

GoodLeap Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
GoodLeap DE&I Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of GoodLeap
GoodLeap CEO photo
Hayes Barnard
Approve of CEO

Average salary estimate

$175500 / YEARLY (est.)
min
max
$164000K
$187000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Lead Product Security Engineer, GoodLeap

GoodLeap is on the lookout for a dynamic Lead Product Security Engineer to join our innovative team! As a technology company dedicated to sustainable solutions such as solar panels, HVAC systems, and energy-efficient products, your role will be pivotal in shaping the security and resilience of our offerings. Imagine being at the forefront of building and safeguarding products that not only enhance customer experiences but also contribute to a greener planet. In this role, you will collaborate closely with product, engineering, and business teams, acting as a trusted advisor while ensuring that the safety of GoodLeap's products meets the highest standards. You will have the authority to oversee product features, manage application security during development, and implement runtime controls for deployed products. Your expertise will also help in aligning our security posture with governance, risk management, and compliance practices. You’ll lead a collaborative security culture, orchestrating processes like threat modeling and vulnerability management, and constantly striving to improve our security landscape. Plus, your contributions won’t end there—you’ll play a key role in incident responses and threat hunting activities! This position is perfect for a highly skilled communicator who has experience with agile product lifecycles and a strong understanding of both application security and modern cloud infrastructures. Here at GoodLeap, we believe in the power of teamwork and are excited to see how your unique skills can help us continue our mission of making sustainable solutions accessible to all. If this sounds like your next adventure, we can't wait to meet you!

Frequently Asked Questions (FAQs) for Lead Product Security Engineer Role at GoodLeap
What responsibilities does a Lead Product Security Engineer have at GoodLeap?

The Lead Product Security Engineer at GoodLeap is responsible for ensuring both the security and resilience of the company's products and services. This includes collaborating closely with engineering, product, and operations teams to implement security controls, oversee application security throughout the development lifecycle, and manage runtime security measures for deployed products.

Join Rise to see the full answer
What qualifications are needed for the Lead Product Security Engineer position at GoodLeap?

To be considered for the Lead Product Security Engineer role at GoodLeap, candidates should possess strong communication skills, expertise in agile product lifecycles, experience in product management or engineering management, and a detailed understanding of security posture management methodologies and cloud services, including AWS and DevOps practices.

Join Rise to see the full answer
How does GoodLeap ensure a collaborative environment for the Lead Product Security Engineer?

GoodLeap fosters a collaborative work culture by embedding the Lead Product Security Engineer within cross-functional teams, allowing for close partnerships with product, engineering, and operations teams. This integration ensures that security considerations are streamlined into every aspect of product development.

Join Rise to see the full answer
What kind of technologies will a Lead Product Security Engineer work with at GoodLeap?

As a Lead Product Security Engineer at GoodLeap, you'll work with a variety of technologies including AWS, microservices orchestration tools, CI/CD pipelines, and automation frameworks. Familiarity with various programming languages for scripting and security automation processes is also beneficial.

Join Rise to see the full answer
What is the compensation range for the Lead Product Security Engineer position at GoodLeap?

The Lead Product Security Engineer role at GoodLeap offers a competitive salary ranging from $164,000 to $187,000 annually. Additionally, there may be opportunities for bonuses and equity, making it an attractive compensation package.

Join Rise to see the full answer
What is the career growth potential for a Lead Product Security Engineer at GoodLeap?

At GoodLeap, the Lead Product Security Engineer role offers significant career growth potential, including opportunities to influence security strategies, expand into leadership positions, and shape the future of security practices within the organization.

Join Rise to see the full answer
What personal attributes do successful Lead Product Security Engineers at GoodLeap possess?

Successful Lead Product Security Engineers at GoodLeap are noted for their strong communication skills, collaborative mindset, technical proficiency, and a passion for continuous learning. They are leaders who can effectively balance strategic vision with attention to detail to ensure superior security outcomes.

Join Rise to see the full answer
Common Interview Questions for Lead Product Security Engineer
How do you approach threat modeling in product security?

When discussing your approach to threat modeling in an interview, emphasize your methodology for identifying potential threats, assessing vulnerabilities, and prioritizing risks. Mention specific frameworks you've used, such as STRIDE or LINDDUN, and how these have informed security decisions throughout the product lifecycle.

Join Rise to see the full answer
Can you describe a time you improved security in a product development process?

Share a specific example that demonstrates your capacity to enhance security measures. Highlight the problem you identified, the actions you took—such as implementing automated testing or establishing secure coding practices—and the positive impact these changes made on the product's overall security posture.

Join Rise to see the full answer
What are the key components of your incident response plan?

Discuss the essential elements of an incident response plan you would implement, including preparation, detection, analysis, containment, eradication, and recovery. Highlight the importance of communication and the role of playbooks for specific types of incidents in ensuring a smooth response process.

Join Rise to see the full answer
How do you stay current with security trends and vulnerabilities?

Talk about the resources you use to keep abreast of security trends, such as industry publications, blogs, threat intelligence reports, and community forums. Mention any training or certifications you've pursued to stay knowledgeable and adaptable in a constantly evolving security landscape.

Join Rise to see the full answer
What strategies do you use to foster collaboration between security, engineering, and product teams?

In your answer, emphasize the importance of clear communication, regular meetings, and shared goals to foster collaboration. Discuss how you create a culture of security awareness and shared responsibility, ensuring everyone understands their role in maintaining product security.

Join Rise to see the full answer
How do you evaluate the effectiveness of security controls in a product?

Discuss methods for evaluating security controls, such as conducting security audits, penetration testing, or review processes to measure compliance with established security standards. Emphasize your analytical skills in interpreting results and your actions based on findings to continuously improve the security posture.

Join Rise to see the full answer
Have you ever handled a security breach? What was your approach?

If applicable, share a real-world anecdote detailing a security breach you managed. Focus on your initial response, the steps you took to address the issue, how you communicated with stakeholders, and the lessons learned from the situation to prevent future incidents.

Join Rise to see the full answer
What is your experience with automation in security processes?

Discuss your experience automating security processes using tools like CI/CD pipelines or other scripting languages. Specify examples where automation improved efficiency, reduced risks, and enabled faster response times to potential vulnerabilities.

Join Rise to see the full answer
How do you prioritize security features in product development?

Explain your criteria for prioritizing security features based on factors such as threat landscape, regulatory requirements, user needs, and potential impact. Discuss the importance of collaborating with product and engineering teams to ensure that security is integrated into the product from the outset.

Join Rise to see the full answer
What role does user education play in product security?

Articulate the significance of user education in enhancing product security. Discuss strategies you've implemented to educate users about potential risks, safe practices, and the importance of adhering to security protocols to minimize vulnerabilities stemming from user actions.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 4 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays
Photo of the Rise User
Posted 2 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays
Photo of the Rise User
YASSIR Remote Algiers, Algeria
Posted 9 days ago
Photo of the Rise User
Posted yesterday
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Collaboration over Competition
Growth & Learning
Transparent & Candid
Mission Driven
Social Impact Driven
Passion for Exploration
Dental Insurance
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Paid Holidays
Sabbatical
Medical Insurance
401K Matching
Paid Time-Off
Learning & Development
Maternity Leave
Paternity Leave
Mental Health Resources
Eagle Eye Remote No location specified
Posted 11 days ago
Photo of the Rise User
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Paid Holidays

GoodLeap has an ambitious mission: to connect a world in which everyone can live sustainably. GoodLeap provides frictionless, point-of-sale technology for countless mission-driven professionals and millions of people who seek to live a more susta...

70 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Family FriendlyBadge Office VibesBadge Work&Life Balance
BENEFITS & PERKS
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
November 24, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!