Senior Product Security Engineer I

Oscar Health

Confirmed live yesterday Trusted
Hybrid

Quick summary

Work type
Hybrid
Location
New York, NY
Posted
58 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $181k
$128k most similar roles pay here $229k

This listing doesn't post a salary. Most similar roles pay $152,591–$209,500.

Based on 240 similar postings.

Employer

About Oscar Health

Oscar Health is a technology-driven health insurance company offering individual, family, and small business health plans.

Oscar Health currently has 70 open roles on FindRole.

Listed pay typically runs $149,040–$195,615 across 65 roles with salary data.

Most-posted roles

View all roles at Oscar Health

At a glance

TL;DR · Senior Product Security Engineer I

The Senior Product Security Engineer I joins the Security Team to serve as a key technical resource leading the security of the software development life cycle from design to completion. This role focuses on securing architecture, managing the vulnerability lifecycle through SAST and DAST tools, and performing manual analysis. The engineer will build risk assessment frameworks, conduct source code reviews for internal and third-party software, and write production-quality code and libraries. A primary focus involves AI integration and security, specifically designing measures for AI-driven workflows and integrating security reviews into AI agent processes. Required skills include experience in the secure SDLC, building complex standalone systems, and using AI models integrated via protocols like the Model Context Protocol. The role addresses the intersection of traditional application security and modern AI-driven engineering.

What you'll do

  • Lead the security of the software development life cycle from design to completion.
  • Design security measures for AI-driven workflows and integrate reviews into AI agent processes.
  • Manage the vulnerability lifecycle including automated identification, manual analysis, and remediation tracking.
  • Conduct source code reviews for internal and third-party software.
  • Write production-quality code and libraries for use by engineering teams.
  • Build risk assessment frameworks and develop action plans to manage identified risks.
  • Provide technical guidance and presentations to engineering teams regarding vulnerability remediation.

What we're looking for

  • 4+ years of combined career experience in software development and information security.
  • Proven experience across all areas of the Secure Software Development Life Cycle (SDLC).
  • Strong background in building moderate to complex standalone systems or major new features.
  • Hands-on experience using AI models and integrating them with internal systems via protocols like Model Context Protocol (MCP).
  • Ability to conduct source code reviews and write production-quality code and libraries.
  • Experience managing the vulnerability management lifecycle, including SAST, DAST, and manual analysis.
  • Ability to build risk assessment frameworks and deliver actionable remediation plans.
  • A Bachelor's degree or four years of equivalent experience is preferred.

More like this

Similar roles

Senior Security Engineer I, Product Security

Oscar Health

Los Angeles, CA 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Source Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Tempe, AZ 8 days ago
SAST DAST SDLC Vulnerability Management Code Review AI Integration Model Context Protocol (MCP) Software Development Risk Assessment Source Code Review
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Senior Product Security Engineer

Adobe

San Jose, CA 7 days ago $180,600$261,450
OWASP Top 10 CVSS v3.1 Burp Suite Python PowerBI JIRA REST API OAuth2 AWS Lambda API Gateway SQL Injection XSS SSRF IDOR SOAR Webhooks curl DevTools
5+ yrs exp

Senior Security Engineer I, AI

Oscar Health

New York, NY 56 days ago $163,944$215,176
LLM RAG AI Security Prompt Injection Model Poisoning MITRE ATLAS OWASP Top 10 AWS GCP IAM Cloud Security Application Security Data Security HIPAA red-teaming
4+ yrs exp Hybrid

Senior Security Engineer

Apple Inc

Seattle, WA 149 days ago $175,000$263,300
AI/ML LLM Vector Databases Prompt Injection Threat Modeling Security Assessment Cloud-Native Automation MCP A2A Data Leakage
5+ yrs exp