Full-Time

Lead Product Security Engineer

Updated on 1/17/2025

Goodleap

Goodleap

1,001-5,000 employees

Sustainable home solutions marketplace with payment technology

Energy
Fintech
Social Impact
Consumer Goods

Compensation Overview

$164k - $220kAnnually

Senior, Expert

United States

Hybrid position requiring some in-office presence.

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Agile
Python
Git
Node.js
TypeScript
.NET
Microservices
AWS
Cryptography
Terraform
Development Operations (DevOps)
Google Cloud Platform
Requirements
  • Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
  • Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
  • Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
  • Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
  • Proven ability to establish credibility and build trust with engineers and operational staff; confident yet humble.
  • Hands-on experience with microservices and associated orchestration tools, such as ECS, EKS, Nomad, and Istio, with an understanding of the operational and security implications of these technologies.
  • Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
  • Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
  • Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
  • Prior experience developing security services for products or enterprise platforms, ideally using Python, Node.js, TypeScript, or .NET.
  • Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
  • Strong understanding of cryptography and key management use cases.
  • Experience overseeing vulnerability and threat management at the platform and application levels.
  • Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
  • Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
Responsibilities
  • Lead, participate in, and contribute to partnerships between security, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap products and services.
  • Define and refine processes such as threat modeling, embedment models, and the prioritization of features, defects, and vulnerabilities.
  • Assist the red team with ongoing activities, including bug bounty programs and continuous penetration testing platforms.
  • Contribute to investigations, threat hunting, and incident response activities in a supporting role. Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
  • Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
  • Select and operate product and application security solutions, from DAST/SAST, SCA, Threat Modeling, etc.

GoodLeap provides a marketplace for sustainable home solutions, connecting homeowners with professionals who specialize in eco-friendly home improvements. Their platform simplifies the purchasing process by offering a single point of sale technology that allows users to explore various upgrade options and choose flexible payment plans that suit their budgets. Unlike many competitors, GoodLeap focuses specifically on sustainability and partners with over 18,000 professionals nationwide, ensuring a wide range of services. The company's goal is to help homeowners make environmentally friendly upgrades while saving money, and they also contribute to sustainable energy projects through their partnership with GivePower, donating a portion of their revenue with each transaction.

Company Stage

Debt Financing

Total Funding

$778.2M

Headquarters

Roseville, California

Founded

2003

Growth & Insights
Headcount

6 month growth

0%

1 year growth

0%

2 year growth

-1%
Simplify Jobs

Simplify's Take

What believers are saying

  • GoodLeap closed a $470 million securitization backed by sustainable home improvement loans in 2023.
  • The company raised $800 million to expand in a $430-billion-per-year market.
  • Increased consumer interest in energy-efficient upgrades boosts demand for GoodLeap's financing options.

What critics are saying

  • Emerging fintech companies offering similar solutions could erode GoodLeap's market share.
  • Rising interest rates may reduce the affordability of GoodLeap's financing options.
  • Direct-to-consumer solar panel sales could threaten GoodLeap's traditional financing model.

What makes Goodleap unique

  • GoodLeap offers a seamless point-of-sale platform for sustainable home upgrades.
  • The company partners with over 18,000 professionals nationwide for home improvement solutions.
  • GoodLeap supports GivePower, donating to sustainable energy projects with every transaction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours