Senior Product Security Engineer

Navan

Quick summary

Work type
On-site
Location
Redwood City, CA
Salary
$113,400–$252,000 / yr
Posted
57 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $182k
This role $183k
$97k most similar roles pay here $269k

This role pays more than 52% of similar roles. Most pay $151,475–$213,375 — the shaded band above. At the midpoint, this role pays about $183k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About Navan

Navan (formerly TripActions) is a travel and expense management platform that provides corporate travel booking, expense management, and card solutions to simplify business travel for enterprises. Industry: Travel Management & Financial Technology

Navan currently has 17 open roles on FindRole.

Listed pay typically runs $113,400–$252,000 across 6 roles with salary data.

Most-posted roles

View all roles at Navan

At a glance

TL;DR · Senior Product Security Engineer

As a Senior Product Security Engineer at Navan, you will join the Director of Product Security and Trust’s team to build and scale an application security program. Your role involves identifying risks early in the SDLC, developing custom automated security solutions, and providing security analysis and training to engineering teams. You will act as a tech lead for high-priority initiatives, participate in expanding the S-SDLC program, review product designs for security defects, and work closely with engineers to automate pipeline activities. The ideal candidate has 6-8 years of experience in SSDLC tooling, automation, and threat modeling, along with expertise in cloud environments like AWS, application security testing tools, infrastructure as code, Java Spring Framework, JavaScript/CSS/Angular, Docker/Kubernetes, continuous integration, defect tracking, and source code management. Additionally, you should have a deep understanding of common application & network protocols, cryptographic primitives, and secure SaaS architecture in containerized microservices environments.

What you'll do

  • Lead high-priority product security initiatives and ensure timely delivery.
  • Expand and mature the Secure Software Development Lifecycle (S-SDLC) program.
  • Review product designs for security defects, perform threat modeling, and recommend remediations.
  • Develop custom automated security solutions to enhance application security.
  • Provide training and guidance to development teams on integrating security early in the SDLC.
  • Cultivate security ownership within product teams to promote a 'shift left' culture.

What we're looking for

  • 6-8 years of experience in technical product security related to SSDLC tooling and automation.
  • Proven ability to perform threat modeling, architecture reviews, and penetration testing for complex applications.
  • Strong expertise in cloud environments (AWS), application security testing tools, and infrastructure as code technologies.
  • Deep knowledge of common application & network protocols, cryptographic primitives, and secure SaaS architecture.
  • Experience working in Agile development with continuous integration pipelines and defect tracking systems.
  • Ability to provide pragmatic security advice for web applications, mobile apps, and cloud software.
  • In-depth understanding of browser security and modern JavaScript frameworks (Angular).

More like this

Similar roles

Senior Product Security Engineer

Navan

Redwood City, CA 57 days ago $113,400$252,000
AWS Terraform Java Spring Framework Hibernate JavaScript Angular Docker Kubernetes Jenkins GitHub SAST DAST IAST SCA Jira CI/CD PostgreSQL Agile PCI DSS SOC2 HIPAA FedRAMP

Senior Product Security Engineer

Navan

Redwood City, CA 57 days ago
AWS Terraform Java Spring Framework Hibernate JavaScript Angular Docker Kubernetes Jenkins GitHub SAST DAST IAST SCA Jira CI/CD Cloud Security Microservices Containerization Agile Development PCI DSS SOC2 HIPAA FedRAMP

Senior Product Security Engineer

Adobe

San Francisco +4 42 days ago $180,600$261,450
GitHub Actions Jenkins Kubernetes Terraform CI/CD Python Go Bash GitOps Secure SDLC Supply Chain Security Threat Modeling Cloud Native Systems Containerized Workloads Artifact Signing Open Source Risk Management

Senior Product Security Engineer - Software

Rockwell Automation

Remote (United States Of America Milwaukee (South 2Nd Street), US) 93 days ago
C# Java PHP .NET Core React Docker Kubernetes Go SQL HTML CSS JavaScript CI/CD SAST DAST SCA SonarQube Blackduck JFrog XRay PrismaCloud TCP/IP UDP HTTP HTTPS GitHub Mercurial Subversion AWS Azure GCP
Remote

Senior Product Security Engineer

Plaid

New York City 70 days ago $204,156$281,196
Python Django React PostgreSQL AWS RDS S3 Lambda CI/CD GitHub Kubernetes Terraform Docker GitLab Jenkins