Full-Time

Senior Product Security Engineer

Posted on 9/5/2025

Mattermost

Mattermost

51-200 employees

Secure collaboration platform with customizable workflows

Compensation Overview

$135k - $175k/yr

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
JavaScript
Threat modeling
Vulnerability Analysis
Go
penetration testing
Requirements
  • BS in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent experience, with 5+ years of relevant experience in application security, secure software development, or penetration testing.
  • Deep understanding of web application security and secure development practices
  • Deep understanding with common security libraries, security controls, and common security flaws
  • Experience with Threat Modeling applications
  • Experience with static/dynamic analysis, and common exploit methods
  • Experience in one or more programming languages, ideally Go or Javascript
  • Excellent written and verbal communication skills
  • Demonstrable teamwork skills and resourcefulness
  • For candidates residing in the U.S.: This role may require the ability to obtain and maintain a U.S. government security clearance in the future. As such, U.S. applicants must be U.S. citizens and eligible under applicable clearance requirements.
  • Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR.
Responsibilities
  • Support the application vulnerability management and mitigation approaches
  • Conduct application security reviews through manual code review or static/dynamic code analysis
  • Engage in threat modeling and design reviews of in-house developed software components
  • Provide security guidance and training to internal development teams
  • Triage SCA findings and support internal development teams in SCA findings remediation
  • Improve and/or automate existing processes to increase efficiency.
Desired Qualifications
  • Experience working in open source communities
  • Experience running a bug bounty program
  • Certifications in the domain of penetration testing or application security (e.g. OSCP, OSWE, GWAPT, …)
  • Experience with Electron, React or React Native
  • Participation in Bug Bounties, CTFs or similar activities

Mattermost provides a secure, customizable collaboration platform designed for technical teams. It offers real-time messaging, file and code snippet sharing with inline syntax highlighting, and workflow automation, all within a platform that can be fully customized and deployed anywhere to meet strict security and data-control needs. The product integrates with essential developer and IT tools like GitHub, GitLab, and ServiceNow, enabling users to run and automate workflows from a single interface. In addition to an open-source version, Mattermost offers premium features such as built-in identity and access controls, granular admin controls, advanced compliance auditing and reporting, and flexible deployment options. Its goal is to help technical teams collaborate more effectively while maintaining strong security and data governance.

Company Size

51-200

Company Stage

Series B

Total Funding

$70.1M

Headquarters

Palo Alto, California

Founded

2016

Simplify Jobs

Simplify's Take

What believers are saying

  • Expands into cyber defense and DevSecOps with secure out-of-band SOC/CERT workflows.
  • 800,000 workspaces and 800+ customers including NASA, Nasdaq, Samsung, SAP, USAF.
  • Monthly MIT-licensed releases with Go/React single Linux binary and voice/screen sharing.

What critics are saying

  • Slack's enterprise dominance and AI features lock in customers, eroding market share.
  • Microsoft Teams free tier with government compliance undercuts premium public sector pricing.
  • DoD CMMC 3.0 certification delays exclude Mattermost from $10B+ defense contracts.

What makes Mattermost unique

  • Open-source platform with sovereign cloud deployments across Azure, Oracle, Google, AWS.
  • AI-powered Intelligent Mission Environment for classified networks and tactical edge operations.
  • In-region presence in Australia, Canada, Japan, and US Federal with cleared personnel.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Fully remote work

Office setup fund

Coworking space stipend

Internet and mobile phone reimbursement

401k

Unlimited vacation

Family & friends days

Async weeks

Health benefits

Global and regional team meetups

Open source Fridays

Community hackathons and events

Growth & Insights

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
INACTIVE