Product Security Engineer Jobs in USA with Visa Sponsorship
Product Security Engineers are highly sought after for H-1B visa and other work visa sponsorship due to critical cybersecurity skills shortages. The role typically qualifies as a specialty occupation with computer science, cybersecurity, or engineering degrees. Major tech companies and financial institutions actively sponsor for these positions. For detailed occupation requirements, see the O*NET profile.
See All Product Security Engineer JobsOverview
Showing 5 of 1,033+ Product Security Engineer jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 1,033+ Product Security Engineer jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Product Security Engineer roles.
Get Access To All Jobs
INTRODUCTION
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more.
Backed by top investors including Greylock, Norwest Venture Partners, and IVP, we've built a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Our team includes leaders who helped define the categories of endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black.
Now, we're transforming how SaaS is secured—in the era of agentic AI.
Today, Obsidian is trusted by global enterprises like Snowflake, T-Mobile, and Pure Storage. We protect more than 200 organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand—including many of the world's largest Fortune 1000 and Global 2000 companies.
With strong global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise on the horizon, we're scaling quickly toward long-term growth and IPO readiness. Join us as we define the future of SaaS security!
POSITION OVERVIEW
We're looking for a Principal Product Security Engineer to lead and scale Obsidian's product security program across our SaaS product, cloud infrastructure, CI/CD pipelines, and related services. This is a senior, highly technical role for someone who can combine deep security engineering expertise with strong ownership, judgment, and cross-functional leadership.
You'll partner closely with Engineering, Product, GRC, IT, DevOps, SRE, and Platform teams to embed security throughout the SDLC, strengthen cloud and infrastructure security, mature threat modeling and secure design practices, and drive automation across detection, response, vulnerability management, and security testing.
This role reports to the Head of Security and is ideal for a seasoned product security leader who thrives in a fast-moving, high-growth cybersecurity startup and wants to make a meaningful impact on the security of our product, customers, and organization.
KEY RESPONSIBILITIES
- Lead and evolve Obsidian's product security program, including standards, runbooks, technical documentation, and operational practices.
- Provide technical leadership, mentorship, and secure design guidance to security and engineering teams.
- Drive security architecture reviews, threat modeling, secure coding practices, and scalable security design reviews.
- Integrate security deeply into the SDLC through code review, SAST/DAST, fuzzing, SBOMs, dependency scanning, and CI/CD security controls.
- Partner with infrastructure teams to harden AWS, GCP, Kubernetes, GitLab, Terraform, data pipelines, secrets management, and service-to-service access controls.
- Improve security automation, monitoring, metrics, dashboards, and reporting.
- Lead technical response for product security incidents, vulnerability remediation, penetration testing, and red team findings.
- Support customer and prospect security reviews as a senior technical security expert.
WHAT WE'RE LOOKING FOR
- 10+ years of product security and/or engineering experience in cloud-native environments, ideally in cybersecurity, financial services, or another high-security industry.
- Strong software engineering skills, especially in Python.
- Hands-on expertise with Terraform, Kubernetes, AWS, GCP, GitLab, security automation, and security metrics.
- Deep knowledge across application security, cloud security, detection and response, vulnerability management, and secure SDLC practices.
- Experience partnering with engineering, product, IT, GRC, and external stakeholders during security reviews and incidents.
- Strong communication skills with the ability to influence, educate, and raise security maturity across the company.
- A mission-driven, ownership-oriented mindset and the ability to thrive in a dynamic startup environment.
WHAT WE OFFER
- A team-first, low-ego, mission-focused culture.
- High-impact work shaping the security of Obsidian's product and platform.
- Professional development opportunities and annual conference budget.
- Competitive salary, equity, and health benefits.
- Opportunities to publish research, share non-proprietary code, and present at conferences.
- The chance to join a fast-growing company backed by Greylock Partners, Google Ventures, Menlo Ventures, WingVC, and Norwest Venture Partners.

INTRODUCTION
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more.
Backed by top investors including Greylock, Norwest Venture Partners, and IVP, we've built a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Our team includes leaders who helped define the categories of endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black.
Now, we're transforming how SaaS is secured—in the era of agentic AI.
Today, Obsidian is trusted by global enterprises like Snowflake, T-Mobile, and Pure Storage. We protect more than 200 organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand—including many of the world's largest Fortune 1000 and Global 2000 companies.
With strong global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise on the horizon, we're scaling quickly toward long-term growth and IPO readiness. Join us as we define the future of SaaS security!
POSITION OVERVIEW
We're looking for a Principal Product Security Engineer to lead and scale Obsidian's product security program across our SaaS product, cloud infrastructure, CI/CD pipelines, and related services. This is a senior, highly technical role for someone who can combine deep security engineering expertise with strong ownership, judgment, and cross-functional leadership.
You'll partner closely with Engineering, Product, GRC, IT, DevOps, SRE, and Platform teams to embed security throughout the SDLC, strengthen cloud and infrastructure security, mature threat modeling and secure design practices, and drive automation across detection, response, vulnerability management, and security testing.
This role reports to the Head of Security and is ideal for a seasoned product security leader who thrives in a fast-moving, high-growth cybersecurity startup and wants to make a meaningful impact on the security of our product, customers, and organization.
KEY RESPONSIBILITIES
- Lead and evolve Obsidian's product security program, including standards, runbooks, technical documentation, and operational practices.
- Provide technical leadership, mentorship, and secure design guidance to security and engineering teams.
- Drive security architecture reviews, threat modeling, secure coding practices, and scalable security design reviews.
- Integrate security deeply into the SDLC through code review, SAST/DAST, fuzzing, SBOMs, dependency scanning, and CI/CD security controls.
- Partner with infrastructure teams to harden AWS, GCP, Kubernetes, GitLab, Terraform, data pipelines, secrets management, and service-to-service access controls.
- Improve security automation, monitoring, metrics, dashboards, and reporting.
- Lead technical response for product security incidents, vulnerability remediation, penetration testing, and red team findings.
- Support customer and prospect security reviews as a senior technical security expert.
WHAT WE'RE LOOKING FOR
- 10+ years of product security and/or engineering experience in cloud-native environments, ideally in cybersecurity, financial services, or another high-security industry.
- Strong software engineering skills, especially in Python.
- Hands-on expertise with Terraform, Kubernetes, AWS, GCP, GitLab, security automation, and security metrics.
- Deep knowledge across application security, cloud security, detection and response, vulnerability management, and secure SDLC practices.
- Experience partnering with engineering, product, IT, GRC, and external stakeholders during security reviews and incidents.
- Strong communication skills with the ability to influence, educate, and raise security maturity across the company.
- A mission-driven, ownership-oriented mindset and the ability to thrive in a dynamic startup environment.
WHAT WE OFFER
- A team-first, low-ego, mission-focused culture.
- High-impact work shaping the security of Obsidian's product and platform.
- Professional development opportunities and annual conference budget.
- Competitive salary, equity, and health benefits.
- Opportunities to publish research, share non-proprietary code, and present at conferences.
- The chance to join a fast-growing company backed by Greylock Partners, Google Ventures, Menlo Ventures, WingVC, and Norwest Venture Partners.
See all 1,033+ Product Security Engineer jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Product Security Engineer roles.
Get Access To All JobsTips for Finding Visa Sponsorship as a Product Security Engineer
Highlight security certifications alongside your degree
CISSP, CISM, or CEH certifications strengthen your specialty occupation case. Immigration officers recognize these as evidence of specialized cybersecurity knowledge beyond general IT skills.
Target companies with existing security compliance programs
Organizations under SOX, PCI DSS, or HIPAA regulations have documented needs for security engineers. This regulatory requirement supports the business necessity argument for sponsorship.
Emphasize threat modeling and vulnerability assessment experience
Specific technical skills like penetration testing, code review, and security architecture differentiate you from general software engineers when justifying the specialized role.
Focus on fintech, healthcare, and defense contractors
Industries handling sensitive data have higher sponsorship rates for security roles. These sectors often have dedicated immigration budgets due to talent scarcity and compliance requirements.
Document experience with security frameworks and standards
Knowledge of NIST, ISO 27001, or OWASP frameworks demonstrates specialized expertise. Include specific implementations you've led or contributed to in previous roles.
Consider cybersecurity consulting firms as entry points
Security consulting companies frequently sponsor international talent and offer client exposure. This path can lead to direct hire opportunities with larger organizations later.
Product Security Engineer jobs are hiring across the US. Find yours.
Find Product Security Engineer JobsFrequently Asked Questions
Do I need a cybersecurity degree for H-1B sponsorship as a Product Security Engineer?
No, you don't need a cybersecurity-specific degree. Computer Science, Information Technology, Engineering, or related technical degrees typically qualify. The key is demonstrating that your education and experience combine to create specialized knowledge in product security. Relevant certifications like CISSP or security bootcamps can strengthen applications with non-security degrees.
What makes Product Security Engineer a specialty occupation for visa purposes?
Product Security Engineers require specialized knowledge of secure coding practices, threat modeling, vulnerability assessment, and security architecture that goes beyond general software development. The role demands understanding of cryptography, compliance frameworks, and security testing methodologies. This specialized skill set typically requires at least a bachelor's degree in a technical field plus security-specific training.
Which visa types work best for Product Security Engineers?
H-1B is most common due to the technical degree requirement and specialty occupation nature. O-1 may apply for senior engineers with significant security research, publications, or recognition in cybersecurity. E-3 works for Australians, TN for Canadians with qualifying degrees. L-1 applies if transferring from an international office of the same company with security responsibilities.
How do security clearance requirements affect visa sponsorship?
Many government contractors and defense companies require security clearances that are only available to U.S. citizens or permanent residents. This limits H-1B opportunities in defense and classified work. However, commercial cybersecurity roles, fintech, healthcare, and private sector companies actively sponsor without clearance requirements. Focus on commercial security positions for better sponsorship prospects.
What's the approval rate for H-1B petitions in cybersecurity roles?
Cybersecurity roles, including Product Security Engineer, generally see higher approval rates than average due to clear specialty occupation requirements and documented talent shortages. USCIS recognizes the technical nature and degree requirements. However, approval depends on proper documentation of job duties, degree relevance, and employer's business need. Working with experienced immigration attorneys improves success rates significantly.
How to find Product Security Engineer jobs with visa sponsorship?
To find Product Security Engineer positions with visa sponsorship, use Migrate Mate, which specializes in connecting international tech professionals with sponsoring employers. Focus on technology companies, fintech firms, and cybersecurity startups that commonly sponsor H-1B, TN, and O-1 visas for security roles. These employers actively seek Product Security Engineers to protect their software and infrastructure from threats.
What is the prevailing wage requirement for sponsored Product Security Engineer jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.
See which Product Security Engineer employers are hiring and sponsoring visas right now.
Search Product Security Engineer Jobs