GitHub logo

Product Security Engineer III

GitHub
Remote, USARemoteSoftware EngineeringMid-Level$107,700 - $285,900Posted: 3 days ago
Apply NowOpens GitHub's site

About the role

Product Security Engineer III

United States

Security

Experienced Professional

Individual Contributor

Yes

5776

Full Time

Get future jobs matching this search

or

Job Description

About GitHub

GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.

Locations

In this role you can work from Remote, United States

Overview

GitHub is transforming how the world builds secure software, and we are looking for a Product Security Engineer III to join our Product Security Engineering team. This is a hands-on engineering role focused on building internal security platforms, tooling, and automation that protect GitHub's products at scale.

You will design, build, and maintain the systems that make GitHub's security program run: static analysis pipelines, agentic security tooling, supply chain defenses, and developer-integrated security controls. The ideal candidate is a strong software engineer who is passionate about application security and wants to solve security problems through code. You will partner closely with product and engineering teams to ship security improvements that scale with the organization.

Responsibilities

Design, build, and maintain security tooling and automation, including static analysis pipelines, secret scanning workflows, and dependency analysis systems.

Contribute to scalable solutions that reduce recurring vulnerability patterns, focusing on preventing classes of vulnerabilities rather than addressing individual instances.

Build and improve agentic security tooling for automated triage, assessment, and remediation of security findings.

Develop security libraries, CI/CD integrations, and developer-facing tools that make the secure path the default path for engineering teams.

Contribute to supply chain security defenses, building detection and prevention systems that protect GitHub's software supply chain.

Collaborate with teams across the organization to address security risks and define new requirements and feature sets.

Analyze key metrics and KPIs to identify trends in security issues, evaluate the effectiveness of security tooling and automation, and recommend improvements to address gaps in measurement.

Qualifications

Required Qualifications:

5+ years experience in security analysis, security research, cyber security, security engineering, or relevant area

OR Associate's Degree in a related field AND 4+ years experience in security analysis, security research, cyber security, security engineering, or relevant area

OR Bachelor's Degree in a related field AND 3+ years experience in security analysis, security research, cyber security, security engineering, or relevant area

OR Master's Degree in a related field AND 1+ year(s) experience in security analysis, security research, cyber security, security engineering, or relevant area

OR equivalent experience.

1+ year(s) of experience in building security tooling and implementing solutions in complex environments.

3+ years experience programming in at least 2 of these 3 coding languages: Ruby, Go, Python.

Preferred Qualifications:

Experience with static analysis tools (SAST/DAST), code scanning frameworks, or custom rule authoring.

Experience building agentic or AI-driven security tooling (e.g., automated triage, classification, or remediation).

Familiarity with software supply chain security concepts and tooling.

Experience working in large-scale monolith or distributed service codebases.

Familiarity with GitHub's products, platform, and developer ecosystem.

Strong expertise in security principles, including the Security Development Lifecycle (SDL), and experience in vulnerability management.

Compensation Range

The base salary range for this job is USD $107,700.00 - USD $285,900.00 /Yr.

Minimum requirements

  • 3+ years programming in at least two of Ruby, Go, or Python
  • 1+ year experience building security tooling in complex environments
  • 3+ years experience in security analysis, research, engineering, or equivalent with relevant degree or experience combinations

This listing was parsed by AI and may not be complete. Check the official posting on GitHub's site for the most accurate information.

Ready to apply?
Applications are handled on GitHub's own careers site.
Apply Now

More roles at GitHub

Senior Software Engineer, Copilot Code Review
Remote, USA · Remote
View →
Staff Product Designer
Remote, USA · Remote
View →
Senior Software Engineer
Remote, USA · Remote
View →
Staff Software Engineer, Elasticsearch
Remote, USA · Remote
View →
Software Engineer III, Copilot Models Inference
Remote, USA · Remote
View →