Principal Product Security Engineer
Quick Summary
SoundCloud empowers artists and fans to connect and share through music. Founded in 2007,
Key Responsibilities:
- Identify security anti-patterns in our codebases and architecture and drive cross-functional initiatives to systemically address them
- Help guide our Engineering and Product teams around the safe and responsible use of agentic AI in our products and Software Development Lifecycle (SDLC)
- Drive efforts to automate the security of our SDLC, including our CI/CD pipelines
- Secure our AWS, GCP, and on-prem infrastructure through implementing proper access control and guardrails
- Conduct secure code reviews and threat modeling exercises to identify and remediate potential security vulnerabilities
- Define, implement, and oversee processes and policies in our Vulnerability Management Program
- Triage and drive to remediation submissions from our external bug bounty program
- Participate in our security incident response process
- Make recommendations to external teams and stakeholders about how to improve the consumer security of our platform
- Promote security best practices through educational initiatives such as CTFs and technical talks
- Improve internal tooling, processes, and documentation
- Help to define the Product Security program and team strategy
- Mentor and onboard team members
Experience and Background:
- 8+ years of product or application security experience, or other relevant software engineering experience
- Deep expertise in designing secure architecture
- Enthusiasm about collaborating with engineering and product teams to proactively address security issues in products
- Experience conducting threat modeling exercises and secure code reviews
- Experience configuring DevSecOps tools (e.g. SAST, SCA, Secret Scanning)
- Experience managing bug bounty programs
- Familiarity with languages such as Javascript, Go, Ruby, Python, or Scala
- Experience working with cloud providers (AWS, GCP) and Developer SaaS solutions (GitHub, Jira)
- Familiarity with IaC tools such as Terraform and CloudFormation
- Ability to effectively communicate risk to technical and non-technical audiences
- Experience with data analysis (SQL) in order to determine scope and impact of vulnerabilities
- Knowledge of industry-standard security frameworks and regulations, such as GDPR, CCPA, SOC2, NIS2, and OWASP is a plus
- Experience with vulnerability management is a plus
- Experience threat modelling and securing Generative AI applications & use-cases in the context of the EU AI Act is a plus
- Experience with data governance is a plus
The salary range for this role is $190,000 - $220,000 annually. The final salary offered will be determined based on relative experience, skills, internal equity, and location. We also offer a generous total rewards program - read more about additional benefits and perks below!
- We are a multinational company with offices in the US (New York and Los Angeles), Germany (Berlin), and the UK (London)
- We provide a flexible work culture that offers the opportunity to collaborate and connect in person at our offices as well as accommodating work from home
- We are deeply committed to ensuring diversity, equity and inclusion at all levels of our organization and fostering a community where everyone’s voice, perspective and experience is respected and heard
- We believe a strong team is made by investing in employees through mentorship, workshops and enrichment opportunities
What We Offer
~1 min readSoundCloud is for everyone. Diversity and open expression are fundamental to our organization; they help us lead what’s next in music by understanding and empowering our creators and fans, no matter their identity. We acknowledge the challenges in the music industry, and strive to influence an inclusive culture where everyone can contribute respectfully and thrive, especially the historically marginalized communities that many of our creators, fans and SoundClouders identify with. We are dedicated to creating an inclusive environment at SoundCloud for everyone, regardless of gender identity, sexual orientation, race, ethnicity, migration background, national origin, age, disability status, or care-giver status.
At SoundCloud you can find your community or elevate your allyship by joining a Diversity Resource Group. Diversity Resource Groups are employee-organized groups focused on supporting and promoting the interests of a particular underrepresented community in order to build a more inclusive culture at SoundCloud. Anyone can join, whether you share the identity or strive to be an ally.
Location & Eligibility
Listing Details
- Posted
- May 18, 2026
- First seen
- May 18, 2026
- Last seen
- May 19, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- May 18, 2026
Signal breakdown
Please let Soundcloud71 know you found this job on Jobera.
3 other jobs at Soundcloud71
View all →Explore open roles at Soundcloud71.
Similar Product Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.