Product Security Engineer Jobs in New York
Product Security Engineer jobs in New York are among the most actively recruited in the country, concentrated in financial services, enterprise technology, and healthcare technology across a market that ranges from entry-level security analysts stepping into product-focused roles through senior engineers and principal architects. The heaviest hiring is in New York City, with additional demand in Albany and Buffalo tied to state government IT modernization and regional financial institutions. Well-established employers with a consistent New York footprint include JPMorgan Chase, IBM, and Citigroup. The most in-demand specialties are application security, threat modeling, and secure software development lifecycle engineering. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 27+ Product Security Engineer jobs











- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: New York, NY, USA; Kirkland, WA, USA.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 2 years of experience with security assessments, penetration testing, or vulnerability research on the Android platform or Android applications.
- 2 years of experience with security engineering, computer and network security and security protocols.
- 2 years of coding experience in one or more general purpose languages.
Preferred qualifications:
- Experience designing and building LLM-based agentic workflows, frameworks, or automation tools specifically targeted at vulnerability research and remediation.
- Direct experience participating in, triaging, or receiving rewards from high-impact Vulnerability Reward Programs (VRPs).
- Experience in Android platform security research, as demonstrated by public CVEs, published whitepapers, or presentations at reputable security conferences (e.g., DEF CON, etc.).
- Familiarity with Artificial Intelligence (AI) and Large Language Model (LLM) concepts, with a demonstrated interest in applying them to security domains.
- Foundational understanding of the Android operating system architecture, security model, and common attack surfaces.
About the job
In this role, you will join the Android Product Security Engineering (APSE) a cross-functional team tasked with ensuring Android is the most secure and defended operating system in the world, protecting the entire ecosystem of three billion devices. You will achieve this by collaborating with internal partners across Android Security, Development, and Partner Engineering, as well as stakeholders outside of Android such as Chrome, and engage with a vast network of external partners, including SoC manufacturers and telecom carriers. You will secure this ecosystem by leading the industry-defining Android Vulnerability Reward Program (VRP) and pioneering AI-driven security engineering projects to drive advanced vulnerability research and mitigation at scale.
As a Security Engineer, you will play a pivotal role in enhancing the Android ecosystem's security posture, focusing heavily on driving AI-powered security innovation alongside operational vulnerability response.
In this role, you will build AI/LLM-driven Security Engineering projects, rather than just streamlining existing pipelines, build and deploy cross-functional AI tooling designed to proactively scale in-depth Android vulnerability research and automate complex mitigation strategies, as these tools require deep domain expertise to build effectively, the engineer is expected to have a strong, foundational understanding of Android threat vectors and attack surfaces.
You will actively participate in the Android Vulnerability Reward Program (VRP) by participating in the triage rotations and engaging with the external researcher community. You will apply platform expertise to conduct comprehensive security research, respond to vulnerabilities in both pre-release and in-market Android products, and partner directly with feature teams to implement robust mitigation solutions.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $147000 - $210000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Build cross-functional AI and Large Language Model (LLM) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.
- Participate in the Android and Device VRP program in analyzing and triaging incoming Vulnerabilities, working with cross-functional teams for vulnerability management and tool building, while proactively incorporating AI/LLMs into our VRP pipeline to improve efficiency.
- Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting VRP reports into prioritized platform mitigation solutions and partner with Product/Feature teams to land them.
- Embed security by design through providing expert product security consultation and conducting comprehensive security design reviews for new Android features.
See All 27 Product Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find JobsProduct Security Engineer Jobs by City in New York
Where New York roles are concentrated, by current openings.
Product Security Engineer Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What New York Employers Look For
The qualifications that appear most often in product security engineer jobs across New York.
- Bachelor's degree in computer science, cybersecurity, or a closely related engineering field
- Hands-on experience with application security testing tools such as SAST, DAST, or IAST
- Proficiency in at least one programming language such as Python, Java, or Go
- Relevant certification such as CISSP, CSSLP, or CEH recognized by New York employers
- Experience conducting threat modeling and security design reviews for software products
- Familiarity with cloud security principles across AWS, Azure, or Google Cloud environments
Product Security Engineer Jobs in New York: Frequently Asked Questions
How do you become a product security engineer in New York?
The most direct path is a bachelor's degree in computer science, cybersecurity, or software engineering, followed by experience in a security or software development role. New York does not require a state-issued license for this role, but employers consistently expect industry certifications such as CISSP or CSSLP. Starting in application security, DevSecOps, or software quality assurance at a New York financial institution or technology company is the most common on-ramp.
Which companies hire product security engineers in New York?
Employers hiring product security engineers in New York right now include Google, Datadog, and MongoDB, based on current listings on Migrate Mate as of September 2026. New York's deep concentration of financial services firms and enterprise technology companies means demand is consistent year-round, with the largest volumes coming from global banks, insurance carriers, and fintech platforms headquartered in the city.
Which New York cities have the most product security engineer jobs?
The cities with the most product security engineer openings in New York are New York, New York City, and Berlin. New York City dominates because of its density of global financial institutions, enterprise tech firms, and healthcare technology companies that embed security engineers directly into product teams, while smaller metros like Albany reflect demand from state government IT agencies and regional financial employers.
Are there remote product security engineer jobs in New York?
Yes, and more than most engineering roles, since product security work is largely code review, threat modeling, and tooling rather than on-site hardware. About 86% of product security engineer openings tied to New York are remote or hybrid as of September 2026, reflecting how broadly distributed product teams have become. Threat modeling, security architecture review, and secure code auditing are the functions most commonly offered on a fully remote basis.
How can I get hired as a product security engineer in New York with little or no experience?
The most realistic entry path is through a security operations, software quality assurance, or DevOps role at a New York financial services or technology employer, then transitioning into product security once you have exposure to vulnerability management or CI/CD pipelines. Large New York employers including JPMorgan Chase and IBM run associate security and early-career technology programs that accept candidates without dedicated product security experience. Earning a CSSLP or building a portfolio of capture-the-flag or bug bounty work gives candidates a meaningful edge.
Where can I find and apply to product security engineer jobs in New York?
You can find and apply to product security engineer jobs in New York on Migrate Mate, which lists current openings from employers actively hiring in the state. Find roles that match your experience and apply directly to the ones that fit.
See All 27 Product Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Jobs