Product Security Engineer, Application Security (Remote)
CrowdStrikeUSA - Remote · Remote · full time
$120,000 – $180,000
Listed on CrowdStrike’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This role involves securing CrowdStrike's applications by identifying and remediating security defects through code review, threat modeling, and penetration testing. It suits engineers who combine deep security expertise with hands-on development experience and want to collaborate closely with product teams to ship safer code.
Our summary, not CrowdStrike’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- Moderate understanding of Agile/DevOps software development
- Threat modeling experience using STRIDE
- Code review ability for Go, Python, or Java applications
- Knowledge of cloud-native and containerized app security in GCP, Azure, or AWS
- Experience with AppSec tools such as SAST, DAST, CSPM, DSPM, or ASPM suites
- Understanding of common software weaknesses in cloud and web applications
- Application penetration testing experience
- Technical collaboration and cross-team communication
- Ability to drive ambiguous research projects
- Experience using AI technologies to enhance decision-making and workflows
Nice to have
- Self-motivated security problem identification and team engagement
- Automation development for application security and defect identification
- Prior product engineering or positive relationships with software developers
- Docker and Kubernetes knowledge
- Ability to explain AI-assisted development security limitations
- Open source security contributions
- Threat intelligence driven testing and adversarial emulation experience
- Technical security certifications or academic background