Senior or Staff Product Security Engineer
Skylight is a technology startup building the OS of the family. We make Skylight Calendar, the smart calendar loved by millions of families (plus Wired and the Wirecutter). Our latest product is Calendar 2, which just launched to rave reviews.
Our mission is to connect loved ones by creating the world’s simplest products and services that improve family life. Our founders are former venture capitalists and serial entrepreneurs who have scaled this business to $300M+ in annual revenue while being completely bootstrapped and profitable. We get to grow a happy, healthy company focused on making products our customers love without investors breathing down our necks.
Smart, hardworking people who care about making actually meaningful products love working here. People like you. We’re busy inventing new ways to simplify family life and help parents raise great kids – and we need your help! Come invent something new with us.
The Role
You'll own the day-to-day execution of our product security program across our cloud backend, mobile apps, and Android platform. You'll triage and drive remediation of vulnerabilities, run our bug bounty program, maintain and extend our AI-powered security scanning, and partner with product and engineering teams on design reviews before new features ship. When a team can't spare the time, you'll ship the fix yourself.
You'll work closely with the Head of Security, who owns strategy and the product security roadmap, and you'll be the person engineering teams turn to for hands-on security expertise.
What you'll do
- Own the vulnerability management pipeline end to end: intake, triage, prioritization, and driving fixes to closure against defined remediation SLAs across Backend, Mobile, and Android teams.
- Join our Platform pod where, with the team, you’ll write and ship security fixes directly in our codebases.
- Own and evolve our AI security scanning and verification pipeline. Tune it to reduce false positives, extend coverage to new repositories, and integrate it into CI.
- Run our HackerOne bug bounty program: triage reports, validate findings, work with researchers, decide on payouts, and manage the vendor relationship.
- Manage third-party penetration testing engagements from scoping through remediation.
- Lead security design reviews and threat modeling for new features and products, including AI/LLM-powered features and products that handle children's data.
- Review and advise on device and firmware security work led by our firmware team.
- Provide metrics and data on findings, remediation, and SLA adherence to support compliance and leadership reporting.
- Serve as a subject matter expert during product security incidents.
Requirements
- 6+ years in application or product security, with a software engineering background. You can ship production code, not just review it.
- Deep experience securing backend services and APIs, including OAuth 2.0/OIDC, PKCE, MFA, session management, and token handling.
- Experience building and maintaining security tooling and automation (static analysis, CI integrations, custom scanners), and comfort working with LLM-based systems.
- Hands-on experience running or triaging a bug bounty program.
- A track record of getting engineering teams to prioritize and fix security issues through influence and good judgment, not escalation.
- Clear written communication and the ability to explain risk to both engineers and non-technical stakeholders.
Nice to have
- Mobile application security experience (OWASP MASVS), ideally including shipping fixes in a mobile codebase.
- Android platform or app security experience.
- Experience assessing AI/LLM features for risks like prompt injection and data leakage.
- Familiarity with children's privacy requirements (e.g. COPPA) or other sensitive consumer data.
- Exposure to embedded, IoT, or firmware security.
- Familiarity with the EU Cyber Resilience Act or UK PSTI.
- Incident response experience.
Benefits
Our competitive compensation package includes:
- Competitive Salary + Equity Package
- 401K matching
- Wellness, learning, and home-office budgets
- Health, Dental & Vision Medical Plans
- Tremendous autonomy to set the direction of your work
- Unlimited PTO
- Company holidays on the first Friday of every month (Except November, December. & January)
The anticipated base salary range for this position is $200K-250K per year. This range reflects the compensation Skylight reasonably and in good faith expects to pay for the position at the time of posting. Actual compensation will be determined based on job-related factors, which may include experience, qualifications, skills, education, geographic location, and internal equity. Skylight also offers benefits, including medical, dental, vision, and paid time off.
Equal Employment Opportunity
Skylight is an equal opportunity employer committed to building a diverse and inclusive team. All qualified applicants will be considered for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, or any other characteristic protected by applicable federal, state, or local law. Pursuant to the San Francisco Fair Chance Ordinance, Skylight will consider for employment qualified applicants with arrest and conviction records.
Website
Careers
