Remote Product Security Engineer Jobs
Remote product security engineer jobs are open across the U.S. at remote-first software companies, distributed fintech teams, and cloud-native organizations in sectors like technology, healthcare, and financial services. Employers hiring remote product security engineers right now include Affirm, Faire, and Submer. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 52+ Remote Product Security Engineer jobs











Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you'll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We're looking for a Senior Product Security Engineer who is passionate about partnering with engineers to assess and mitigate the security risk of our virtualization stack.
You'll own the security risk posture for our virtualization stack. You'll get there by building the frameworks the org uses to reason about hypervisor risk — systematic threat models that surface risks, shared rubrics for assessing their impact and likelihood, and clear ways of communicating them to security, kernel, virtualization, and provisioning teams. From there, you'll own the response: designing and proposing defense-in-depth mitigations and driving their implementation.
As a member of the Product Security team, you will report to the Manager of Secure Design. Our Secure Design team enables DigitalOcean to build secure-by-design products. We leverage strong relationships with both product teams and the rest of security engineering to be successful. The team's scope is primarily focused on reviewing early-stage decisions, developing threat models, scaling impact via automation, curating security patterns, authoring security guidance, training, and championing security initiatives.
What you'll do:
-
Propose and implement mitigations and defense-in-depth to threats discovered through threat modeling the virtualization stack (90%)
-
Provide deep technical expertise in systems architecture, kernel security features and network architecture to build out a threat model for our virtualization stack
- Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements. We do not deliver mandates; we work alongside cross-functional partners to find mutually beneficial solutions.
-
Collaborate with development teams to implement remediations and defense in depth to protect DigitalOcean's customers' workloads.
-
Cultivate and promote a security culture (10%)
-
Mentor software engineering teams in security best practices.
- Help oversee our vulnerability management program (we call it security debt).
- Help DigitalOcean engineers understand how security events impact them. Do they need to worry about the next Redfish or Copy Fail CVEs? How does RetBleed impact DigitalOcean's fleet?
What you'll add to DigitalOcean:
Required qualifications:
- Deep familiarity with at least one kernel security feature (ex: AppArmor, SELinux, Landlock, etc.)
- Capable of assessing and understanding the performance implications of code changes to virtualization stacks (especially in Qemu and KVM), built from hands-on experience.
- A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. Engineering teams are our partners, not our adversaries.
- Ability to clearly communicate security topics and vulnerability classes (e.g. memory corruption, privilege escalation, TOCTOU, etc) and ability to provide actionable direction to product teams.
- Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery).
Preferred qualifications:
- 5+ years of writing systems level code (embedded systems, kernel, assembly or similar).
- Experience guiding software teams on secure architecture design.
- Written code for an embedded system (raspberry pi, arduino, etc).
- Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases.
- An understanding of patches and mitigations for hardware side-channel attacks.
- Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, Rust, or C.
Compensation Range:
- $140,000 - $175,000
This is a remote role
JR: 2026-8011
LI-Remote
Why You'll Like Working for DigitalOcean
- We innovate with purpose. You'll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
- We prioritize career development. At DO, you'll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
- We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
- We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.
See All 52 Remote Product Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Product Security Engineer Job Market
Who's Hiring
- Affirm28

- Faire3

- Submer2S
- Hiddenlayer2

- iHerb1

Top Industries Hiring
- Banking & Financial Services28
- Technology & Software8
- Distribution & Wholesale3
- Healthcare & Medical Services2
- Retail1
What Employers Look For
The qualifications that appear most often in remote product security engineer jobs.
- Bachelor's degree in computer science, information security, or a related technical field
- Hands-on experience with threat modeling frameworks such as STRIDE or PASTA
- Proficiency in at least one scripting or programming language, commonly Python or Go
- Familiarity with OWASP Top 10, secure SDLC practices, and code review processes
- Experience with cloud security controls across AWS, Azure, or Google Cloud Platform
- Relevant certification such as CISSP, CSSLP, CEH, or an Offensive Security credential
Tips for Your Remote Product Security Engineer Job Search
Apply early to remote roles that fit
Migrate Mate lists remote product security engineer openings from across the U.S. in one place, so you can find roles that match your skills and apply directly before postings fill. Early applicants consistently get more responses on competitive remote listings.
Show your async security communication skills
Remote product security engineers document everything in writing, from threat model findings to code review feedback. Include writing samples, design documents, or security runbooks in your application materials so remote hiring managers can see how you communicate risk without a meeting.
Build a public record of security work
Verified bug bounty submissions, open-source security tooling contributions, or published vulnerability research give remote employers concrete proof of your skills. Product security teams at distributed companies rely on this kind of evidence more than on-site employers because they can't assess you in person.
Target companies with distributed engineering teams
Remote product security roles are most active at companies whose entire engineering organization is distributed, not those with a hybrid headquarters. Look for engineering blogs, public GitHub activity, or job listings that reference async-first culture and cross-functional remote product teams.
Prepare for async-heavy remote interviews
Many remote-first security teams use take-home threat modeling exercises or written technical screens before live interviews. Practice writing clear, structured threat assessments under time pressure and be ready to walk through your reasoning in a video call without relying on a whiteboard.
Remote Product Security Engineer Jobs: Frequently Asked Questions
How do I get a remote product security engineer job?
Target remote-first companies and distributed engineering teams that build software products, since they hire product security engineers far more consistently than traditional on-site employers. Remote hiring managers screen hard for self-direction and written communication, so demonstrate both clearly in your application materials. Hands-on skills in threat modeling, secure code review, and vulnerability management matter most, and candidates who can show documented remote contributions to security programs stand out.
Which companies hire remote product security engineers?
Companies hiring remote product security engineers right now include Affirm, Faire, and Submer, based on current remote listings on Migrate Mate as of June 2026. Remote openings tend to concentrate at remote-first SaaS firms, distributed fintech and healthtech companies, and cloud infrastructure organizations that embed security engineers directly into product teams.
Can you get a remote product security engineer job with no experience?
Yes, but remote entry-level product security roles are harder to land because employers expect you to work independently from day one with minimal hand-holding. Remote-first startups and mid-size SaaS companies are the most likely to hire junior candidates. Concrete security labs, bug bounty findings, open-source contributions, or a home lab documenting threat models give hiring managers something tangible to evaluate in place of formal work history.
Do you need a degree for remote product security engineer jobs?
Not always. Many remote employers weigh demonstrated skills, certifications like OSCP or CSSLP, and a portfolio of real security work over a formal degree. Remote hiring emphasizes what you can do asynchronously and independently, so candidates who can show threat modeling work, code review contributions, or vulnerability research findings regularly clear screening without a four-year degree.
Which industries hire the most remote product security engineers?
Most remote product security engineer openings sit in Banking & Financial Services, Technology & Software, and Distribution & Wholesale, per current remote listings on Migrate Mate as of June 2026. Those sectors hire product security engineers remotely because their distributed product and engineering teams need security expertise embedded across time zones rather than concentrated in a single office.
See All 52 Remote Product Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs