Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Product Security Engineer securing Fellow’s AI meeting assistant and software platforms. Building security tooling, remediating vulnerabilities, and enabling safe AI-assisted development.

Responsibilities

  • Identify the highest-leverage opportunities to strengthen Fellow’s security, define practical paths forward, and drive work across teams
  • Build on and evolve existing security systems and practices as the product, architecture, and threat landscape change
  • Partner with engineering teams to threat model features, review designs, and reduce risk before production
  • Perform security-focused code reviews and advise on authentication, authorization, data protection, input handling, secrets, and business logic
  • Build reusable security primitives, paved-road patterns, libraries, and platform controls
  • Introduce and improve security tooling including static analysis, dependency scanning, secret detection, infrastructure scanning, and CI/CD guardrails
  • Find, prioritize, and drive remediation of vulnerabilities from internal testing, automated tooling, penetration tests, customer reports, and external researchers
  • Contribute to security incident response, investigation, containment, root-cause analysis, and post-incident hardening
  • Help engineers build security judgment through practical guidance, shared learning, and collaboration
  • Evaluate AI-agent and AI-assisted-development security implications and build tools, controls, and workflows for safe use at scale

Requirements

  • Professional experience in product security, application security, software engineering, infrastructure security, or a combination of these areas
  • Strong software engineering skills
  • Proficiency in at least one modern programming language, ideally Python
  • Experience identifying and remediating application vulnerabilities involving authentication, authorization, injection, data exposure, secrets, and business logic
  • Experience conducting threat models, security design reviews, and security-focused code reviews for production software
  • Ability to write code, build tooling, and help engineering teams implement durable solutions
  • Experience with SAST, SCA, DAST, secret scanning, cloud posture management, or infrastructure-as-code scanning
  • Familiarity with cloud infrastructure and security concepts including IAM, networking, containers, Kubernetes, and infrastructure as code
  • Track record of taking ambiguous, important problems from investigation through implementation and measurable improvement
  • Ability to operate with significant ownership and set direction within the area
  • Deep, practical use of AI coding agents such as Claude Code, Cursor, Codex, or similar tools
  • Track record of developing agentic workflows, tools, or practices that materially improve software development
  • Curiosity about emerging threats and commitment to continued learning
  • Nice to have: experience with penetration testing, offensive security, bug bounty programs, or external security researchers
  • Nice to have: experience securing AI-powered products, agentic systems, model integrations, or tools allowing AI systems to access data and take actions
  • Nice to have: security-community participation through research, open-source contributions, writing, or speaking

Benefits

  • Every employee receives stock options
  • Health and dental coverage, including prescription drugs and life insurance
  • 12 weeks of paid parental leave at 80% of salary
  • Three weeks of vacation
  • Paid sick leave
  • Paid company-wide break at the end of the year
  • Remote-first flexibility — Work remotely within Canada
  • Learning budgets
  • Lunch-and-learns
  • Freedom to own your work end to end
  • Optional office space in Ottawa, Montreal, and Toronto

Job type

Full Time

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

CloudKubernetesPython

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.