Product Security Engineer
About Rocketlane
Rocketlane is a B2B SaaS platform for client onboarding and project delivery, and we're building Nitro, our AI-native product layer. We're looking for a Product Security Engineer to own product and infrastructure security for the company.
What you'll own
This is a hands-on, individual-contributor security role covering the full range of product security work, not just one slice of it.
Offensive security and vulnerability discovery
Run internal penetration tests across our web app, APIs, mobile app, and cloud infrastructure, and triage findings from external pentest vendors
Actively hunt for vulnerabilities in new features, including in AI/LLM-powered surfaces (prompt injection paths, unsafe code execution in agent tooling, unauthenticated internal endpoints)
Have found and driven the fix for real vulnerabilities before. We need someone who thinks like an attacker, not just someone who runs a scanner and files a ticket
Cloud and infrastructure security
Review and harden our AWS setup: WAF rules, ALB/CloudFront TLS policies and cipher suites, container isolation, IAM and secrets hygiene
Investigate and close out Dependabot and other CI/CD security alerts across dozens of repos, and work with engineering teams to get fixes prioritized and shipped
Build and maintain internal security tooling
Compliance and customer trust
Help with our compliance audit cycles end to end: evidence collection, control testing, and coordinating with auditors. This typically takes up 5% of the work.
Respond to customer security questionnaires and InfoSec review requests, working with sales and customer success to turn these around quickly and accurately
Keep our security documentation and posture current as the product and infrastructure evolve
Cross-team coordination
Work directly with engineering, platform, and ops teams to get security fixes prioritized and shipped, not just logged
Report critical findings up to leadership with clear, actionable writeups (source, sink, impact, fix)
What we're looking for
3+ years in a hands-on security role covering penetration testing and vulnerability research, ideally across web, API, mobile, and cloud
Real, demonstrable experience finding and helping fix serious vulnerabilities (RCE, auth bypass, injection classes), not just running automated scans
Solid working knowledge of AWS security: WAF, ALB/CloudFront, IAM, container security on ECS or similar
Comfort integrating security tooling into CI/CD pipelines (SAST/DAST, dependency scanning) and driving remediation with engineering teams
Experience with, or strong interest in, securing LLM/AI-powered applications: unsafe code execution, prompt injection, agent tool-call boundaries
Strong written communication. You'll be writing up findings for engineers and explaining risk to non-technical stakeholders in the same week
Nice to have
Experience building or maintaining internal security scanning tools
Familiarity with Java/Spring Boot stacks (our backend) or Python (our AI/LLM stack)
A CTF background, bug bounty track record, or security certifications (OSCP, etc.)
Prior exposure to SOC 2 or similar compliance frameworks and customer-facing security questionnaires would be a plus
Why this role
You'd be the primary security engineer for a fast-moving product company actively shipping AI agent features, with direct access to leadership and real ownership over what gets fixed and when.