Full-Time

Lead Product Security Engineer

Confirmed live in the last 24 hours

Goodleap

Goodleap

501-1,000 employees

Sustainable home solutions marketplace with payment technology

Energy
Consumer Software
Consumer Goods

Compensation Overview

$164k - $187kAnnually

Senior

San Mateo, CA, USA

Hybrid position based in San Mateo, CA.

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Agile
Python
Git
Node.js
TypeScript
.NET
AWS
Cryptography
Terraform
Development Operations (DevOps)
Google Cloud Platform
Requirements
  • Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
  • Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
  • Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
  • Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
  • Proven ability to establish credibility and build trust with engineers and operational staff; confident yet humble.
  • Hands-on experience with microservices and associated orchestration tools, such as ECS, EKS, Nomad, and Istio, with an understanding of the operational and security implications of these technologies.
  • Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
  • Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
  • Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
  • Prior experience developing security services for products or enterprise platforms, ideally using Python, Node.js, TypeScript, or .NET.
  • Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
  • Strong understanding of cryptography and key management use cases.
  • Experience overseeing vulnerability and threat management at the platform and application levels.
  • Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
  • Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
Responsibilities
  • Lead, participate in, and contribute to partnerships between security, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap products and services.
  • Define and refine processes such as threat modeling, embedment models, and the prioritization of features, defects, and vulnerabilities.
  • Assist the red team with ongoing activities, including bug bounty programs and continuous penetration testing platforms.
  • Contribute to investigations, threat hunting, and incident response activities in a supporting role. Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
  • Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
  • Select and operate product and application security solutions, from DAST/SAST, SCA, Threat Modeling, etc.

GoodLeap provides a marketplace for sustainable home solutions, connecting homeowners with professionals who specialize in eco-friendly home improvements. Their platform simplifies the purchasing process by offering a single point of sale technology that allows users to explore various upgrade options and choose flexible payment plans that suit their budgets. Unlike many competitors, GoodLeap focuses specifically on sustainability and partners with over 18,000 professionals nationwide, ensuring a wide range of services. The company aims to help homeowners save money while making environmentally conscious choices, and it also contributes to sustainable energy projects through its partnership with GivePower, donating a portion of its revenue from each transaction.

Company Stage

Debt Financing

Total Funding

$778.2M

Headquarters

Roseville, California

Founded

2003

Growth & Insights
Headcount

6 month growth

4%

1 year growth

14%

2 year growth

30%
Simplify Jobs

Simplify's Take

What believers are saying

  • GoodLeap's recent $800 million investment round, led by prominent firms like MSD Partners and BDT Capital Partners, indicates strong investor confidence and provides substantial capital for expansion.
  • The company's ability to close multiple high-value securitizations in 2023 highlights its financial stability and operational efficiency.
  • As the top residential solar lender, GoodLeap is well-positioned to capitalize on the growing demand for sustainable home solutions.

What critics are saying

  • The competitive landscape for sustainable home solutions is intensifying, requiring GoodLeap to continuously innovate to maintain its market leadership.
  • The reliance on securitizations for funding could expose the company to market volatility and interest rate risks.

What makes Goodleap unique

  • GoodLeap stands out as America's leading digital marketplace for sustainable solutions, focusing specifically on residential solar and sustainable home improvement loans.
  • The company has successfully executed multiple securitizations, totaling over $1.39 billion in 2023 alone, showcasing its financial robustness and market trust.
  • GoodLeap's rebranding from Loanpal signifies a strategic pivot to capture a larger share of the $430-billion-per-year market for energy efficiency and home sustainability investments.

Help us improve and share your feedback! Did you find this helpful?