Product Security Engineer III

GitHub $107.7K - $285.9K/year Posted 3 days ago

100% remote US only · US (remote)

About the role

GitHub is looking for a Product Security Engineer III to join the Product Security Engineering team. This is a hands-on engineering role focused on building the internal security platforms, tooling, and automation that protect GitHub's products at scale: static analysis pipelines, agentic security tooling, supply chain defenses, and developer-integrated security controls. The ideal candidate is a strong software engineer who is passionate about application security and wants to solve security problems through code, partnering closely with product and engineering teams to ship security improvements that scale with the organization.

Responsibilities

  • Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems.
  • Contribute to scalable solutions that reduce recurring vulnerability patterns, preventing classes of vulnerabilities rather than addressing individual instances.
  • Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings.
  • Develop security libraries, CI/CD integrations, and developer-facing tools that make the secure path the default path for engineering teams.
  • Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain.
  • Collaborate with teams across the organization to address security risks and define new requirements and feature sets.
  • Analyze key metrics and KPIs to identify trends in security issues and evaluate the effectiveness of security tooling and automation.

Qualifications

  • 5+ years of experience in security analysis, security research, cyber security, security engineering, or a relevant area, or an equivalent combination of education and experience.
  • 1+ years of experience building security tooling and implementing solutions in complex environments.
  • 3+ years of experience programming in at least two of Ruby, Go, and Python.
  • Preferred: experience with static analysis tools (SAST/DAST), code scanning frameworks, or custom rule authoring.
  • Preferred: experience building agentic or AI-driven security tooling such as automated triage, classification, or remediation.
  • Preferred: familiarity with software supply chain security concepts and tooling, and experience in large-scale monolith or distributed service codebases.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on GitHub's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

GitHub team? Claim this listing or ask us to remove it.