GoodLeap
Senior Product Security Engineer
9 days ago
About the Job
Essential Job Duties and Responsibilites
- Lead, participate in, and contribute to partnerships between security, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap products and services.
- Define and refine processes such as threat modeling, embedment models, and the prioritization of features, defects, and vulnerabilities.
- Assist the red team with ongoing activities, including bug bounty programs and continuous penetration testing platforms.
- Support or develop components of the security analytics platform.
- Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
- Contribute to investigations, threat hunting, and incident response activities in a supporting role. Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
- Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge and Abilities
- Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
- Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
- Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
- Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
- Proven ability to establish credibility and build trust with engineers and operational staff; confident yet humble.
- Hands-on experience with microservices and associated orchestration tools, such as ECS, EKS, Nomad, and Istio, with an understanding of the operational and security implications of these technologies.
- Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
- Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
- Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
- Prior experience developing security services for products or enterprise platforms, ideally using Python, Node.js, TypeScript, or .NET.
- Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
- Strong understanding of cryptography and key management use cases.
- Experience overseeing vulnerability and threat management at the platform and application levels.
- Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
- Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
About the Company

GoodLeap
<p>GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.</p>
Similar Jobs

Senior Security Engineer (Product Security)
Senior Security Engineer (Product Security)
- Iceye
- Espoo, Uusimaa, FI
- Hybrid
- Full time role
Revolutionizing climate resilience with real-time radar satellite data for disaster management and environmental monitoring.
About 2 months ago

Security Engineer
Security Engineer
- Base power company
- Austin, TX, US
- Remote
- Full time role
Revolutionizing home energy with distributed batteries for grid support and outage protection at low cost.
About 1 month ago

Senior Network Engineer
Senior Network Engineer
- Pioneer transformers
- United States
- Hybrid, Remote
- Full time role
Custom liquid-filled transformers designed for energy-efficient and sustainable electrical solutions.
11 days ago

Security Engineer (Mid and Senior)
Security Engineer (Mid and Senior)
- Octopus energy
- London, England, GB
- Hybrid, Remote
- Full time role
Redefining energy with transparency, AI, and renewables for a low CO2 future.
10 days ago

Security Operations Centre Analyst
Security Operations Centre Analyst
- Centrica energy
- In-person
- Full time role
Driving global green energy transition with sustainable, predictable energy trading.
10 days ago

Senior Systems Engineer
Senior Systems Engineer
- Re:build manufacturing
- Merrimack, NH, US
- Hybrid
- Full time role
Revitalizing U.S. manufacturing with cutting-edge tech for a sustainable future.
8 days ago

Senior Systems Engineer
Senior Systems Engineer
- Re:build manufacturing
- Wilmington, MA, US
- Hybrid
- Full time role
Revitalizing U.S. manufacturing with cutting-edge tech for a sustainable future.
7 days ago

Senior Systems Engineer
Senior Systems Engineer
- Re:build manufacturing
- Rochester, NY, US
- Hybrid
- Full time role
Revitalizing U.S. manufacturing with cutting-edge tech for a sustainable future.
7 days ago

Senior Systems Engineer
Senior Systems Engineer
- Re:build manufacturing
- Kalamazoo, MI, US
- In-person, Hybrid
- Full time role
Revitalizing U.S. manufacturing with cutting-edge tech for a sustainable future.
7 days ago

Senior Systems Engineer
Senior Systems Engineer
- Re:build manufacturing
- Rock Hill, SC, US
- Hybrid
- Full time role
Revitalizing U.S. manufacturing with cutting-edge tech for a sustainable future.
7 days ago