GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub. Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms. Join us, and let’s change the world, together.
Product Security Engineer III
Location
United States
Posted
14 days ago
Salary
$107.7K - $285.9K / year
Seniority
Mid Level
Job Description
Product Security Engineer III
GitHub, Inc.
Role Description GitHub is transforming how the world builds secure software, and we are looking for a Product Security Engineer III to join our Product Security Engineering team. This is a hands-on engineering role focused on building internal security platforms, tooling, and automation that protect GitHub's products at scale. - Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems. - Contribute to scalable solutions that reduce recurring vulnerability patterns, focusing on preventing classes of vulnerabilities rather than addressing individual instances. - Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings. - Develop security libraries, CI/CD integrations, and developer-facing tools that make the secure path the default path for engineering teams. - Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain. - Collaborate with teams across the organization to address security risks and define new requirements and feature sets. - Analyze key metrics and KPIs to identify trends in security issues, evaluate the effectiveness of security tooling and automation, and recommend improvements to address gaps in measurement. Qualifications - 5+ years experience in security analysis, security research, cyber security, security engineering, or relevant area OR Associate's Degree in a related field AND 4+ years experience in security analysis, security research, cyber security, security engineering, or relevant area OR Bachelor's Degree in a related field AND 3+ years experience in security analysis, security research, cyber security, security engineering, or relevant area OR Master's Degree in a related field AND 1+ year(s) experience in security analysis, security research, cyber security, security engineering, or relevant area OR equivalent experience. - 1+ year(s) of experience in building security tooling and implementing solutions in complex environments. - 3+ years experience programming in at least 2 of these 3 coding languages: Ruby, Go, Python. Requirements - Experience with static analysis tools (SAST/DAST), code scanning frameworks, or custom rule authoring. - Experience building agentic or AI-driven security tooling (e.g., automated triage, classification, or remediation). - Familiarity with software supply chain security concepts and tooling. - Experience working in large-scale monolith or distributed service codebases. - Familiarity with GitHub's products, platform, and developer ecosystem. - Strong expertise in security principles, including the Security Development Lifecycle (SDL), and experience in vulnerability management. Benefits - The base salary range for this job is USD $107,700.00 - USD $285,900.00 /Yr. - Eligible for benefits and additional rewards, including annual bonus and stock. - Rewards are allocated based on individual impact in role. - Opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Provides professional contributions to assist in achieving and maintaining security accreditation for CMRE systems and applications, data acquisition, processing and storage, and their interfacing with other CIS, across the life cycle (development, implementation, operation, enhancement, withdrawal from service). • Within a project structure, advises on cost-effective countermeasures to minimize the security risks anticipated during the development and operation phases of the CIS life cycle. • Within a framework of security accreditation, implements and operates the prescribed security controls under the supervision of the CIS Provider and the under the control of Security Staff. • Documents the architecture, configuration and security posture of CIS in use within CMRE to inform the risk management activities of the Security Organization. • Implements security best practices and security controls, under the supervision of the CIS Provider • Plans, implements and upgrades CIS • Analyses security breaches to determine their root cause • Contributes to define, implement and maintain corporate security policies • Supervises and manages Technical Teams as required. • Undertakes security testing, in accordance with an agreed Security Testing & Verification (ST&V) Plan. • Supports the CIS Provider in the formulation of Security Operating Procedures (SecOPs) for the CIS. • Contribute to the maintenance of configuration baselines through configuration management and change control. • Supports the CIS Provider in undertaking periodic vulnerability assessments, under the control of Security staff and in accordance with the requirements of the Security Accreditation Authority. • Provides regular training and awareness to other project staff • Supports periodic security audits performed by Security Staff and the Security Accreditation Authority.
• Conduct security architecture reviews across mobile (iOS/Android), backend (Java, Python, PHP), data pipelines, and third-party integrations. You're the security partner teams come to during design, not after. • Translate threat models and security requirements into pragmatic guidance engineers can act on. • Build trusted relationships with product and platform engineering teams • Further operationalize and tune ASPM tooling (Cycode) to unify SAST, SCA, secret scanning, and container security into actionable signal, not noise. • Build security-as-code patterns and pre-approved libraries that make the secure path the default path. • Automate vulnerability triage, deduplication, and routing so the team spends time on judgment, not toil. • Drive SLA-based remediation workflows with clear severity definitions, ownership, and escalation paths. • Build metrics that translate security posture into language engineering leadership and executives can use. • Partner on design reviews for AI-powered features: model access controls, data boundary enforcement, and retrieval system authorization. • Contribute to securing agent workflows, MCP integrations, and shared AI tooling as adoption scales across engineering. • Work with Privacy, Legal, and Data Platform on controls for sensitive data: real-time location, family relationships, and data involving minors.
Title: Security Technology Manager Location: San Jose, California, US Job Description: Remote United States Meet the Team At Cisco, Corporate Security plays a critical role in more than just protection—it’s a strategic partner in driving growth, innovation, and customer trust. Our team sits at the intersection of security, technology, and business enablement. We work across global business units, including Meraki Sales, Marketing, and Product Innovation to ensure security is not a barrier, but a catalyst for: Revenue growth through secure, scalable solutions, customer engagement via trusted, immersive experiences Innovation by integrating advanced technologies into real-world environments. We design and deliver secure, high-impact event environments that showcase Cisco innovation. From global conferences to executive briefings, we ensure every interaction is protected, seamless, and data-driven. Leveraging platforms like Splunk, we turn security data into actionable business intelligence—enhancing visibility, improving decision-making, and elevating the overall event and customer experience. Our mission is to protect what matters most while enabling the business to move faster, connect deeper with customers, and lead through innovation. Your Impact We are seeking an experienced Physical Security Technology Manager to lead the planning, implementation, and execution of physical security technology solutions across a diverse portfolio of projects—including global company events. This is an individual contributor role responsible for delivering secure, reliable, and scalable technology deployments. The ideal candidate brings deep expertise in event security operations, combined with strong technical knowledge of access control systems, video surveillance (CCTV), and network infrastructure. - You will work closely with cross-functional teams and global stakeholders to ensure consistent, high-quality security outcomes in both corporate and event environments. - Lead the design, deployment, and operation of physical security technology solutions across business units and global events - Configure and manage access control systems, CCTV platforms, and supporting network infrastructure, including system integrations - Partner with internal stakeholders, vendors, and event teams to define security requirements and execution strategies - Conduct site assessments and risk evaluations to determine appropriate security solutions - Ensure all systems are installed, tested, and fully operational before and during events - Troubleshoot and resolve technical issues in high-pressure, live-event environments - Develop and maintain documentation, standards, and best practices for deployments - Evaluate emerging technologies and industry trends to drive continuous improvement - Ensure compliance with organizational policies and regional regulations Minimum Qualifications - 8+ years of related experience in security technology management - Willingness and ability to travel up to 25% internationally and within the US on a frequent basis - Proven experience delivering physical security technology solutions, with a strong understanding of overall physical security operations - Experience with Next-generation access control systems (badging, credentialing, entry systems), including familiarity with emerging AI-driven solutions. Video surveillance systems, including CCTV and VMS platform Software and hardware development lifecycle fundamentals (SDLC/HDLC) - Demonstrated ability to lead and execute end-to-end technology deployments for large-scale environments or events - Experience collaborating across global teams and diverse stakeholders Preferred Qualifications - Experience in physical security technology or security engineering - Foundational understanding of Security Operations in Events-based environments/GSOC - Proven experience supporting large-scale events or global programs - Hands-on expertise with platforms such as LenelS2, Genetec, Milestone, or similar systems - Strong understanding of networking fundamentals (IP, VLANs, firewalls, VPNs) - Experience managing vendors and integrators - Relevant certifications (e.g., CPP, PSP, or technical certifications) are a plus Why Cisco? At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you. Message to applicants applying to work in the U.S. and/or Canada: The starting salary range posted for this position is $154,700.00 to $200,900.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process. U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time. U.S. employees are eligible for paid time away as described below, subject to Cisco’s policies: - 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees - 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco - Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees - Exempt employees participate in Cisco’s flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations) - 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next - Additional paid time away may be requested to deal with critical or emergency issues for family members - Optional 10 paid days per full calendar year to volunteer For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco’s policies. Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows: - .75% of incentive target for each 1% of revenue attainment up to 50% of quota; - 1.5% of incentive target for each 1% of attainment between 50% and 75%; - 1% of incentive target for each 1% of attainment between 75% and 100%; and - Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation. For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid. The applicable full salary ranges for this position, by specific state, are listed below: New York City Metro Area: $154,700.00 - $234,700.00 Non-Metro New York state & Washington state: $137,700.00 - $205,700.00 * For quota-based sales roles on Cisco’s sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined. ** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Líder de IT – Ciberseguridad
DevsuDevsu is a technology agency that provides software development services, IT augmentation and staffing.
• Supervisar a nuestro Equipo de Soporte de TI (Actualmente 2 personas) • Diseñar, desarrollar, implementar, operar, mantener y monitorear los controles de seguridad de TI. • Realizar evaluaciones de riesgos, mantener un registro de riesgos, coordinar el desarrollo de políticas y estándares de seguridad de la información. • Supervisar la implementación y cumplimiento de estándares y marcos de seguridad de la información y privacidad de datos adoptados por la empresa, incluidos SOC2 e ISO 27001 • Velar por el cumplimiento de los compromisos contractuales y la normativa de seguridad y privacidad de datos. (GRPD, CCPA) • Supervisar los registros de seguridad y realizar evaluaciones de vulnerabilidad • Trabajar en colaboración con ingenieros IT y DevOps para implementar nuevas políticas y procedimientos en procesos de desarrollo de software. • Garantizar la protección y disponibilidad de los datos y sistemas.




