Join Close, a profitable remote CRM company, as its first dedicated Senior Product Security Engineer: protect customer-facing software from anywhere in the United States, with a goal-based bonus and scope to shape the security program.
Looking for product security engineer jobs USA 2026? Close is recruiting a senior engineer who can investigate vulnerabilities, write fixes and make security testing useful for product teams.
Verified: 11 October 2026. Employer posting date: 6 October 2026. Aptub independently summarizes the official vacancy; the header icon is a generic cybersecurity illustration, not Close’s corporate logo.
| Organization | Close |
|---|---|
| Position title | Senior Product Security Engineer |
| Work location / mode | 100% remote; United States only |
| Employment type | Full time |
| Compensation | Numeric range not disclosed; company goal-based bonus advertised |
| Experience | Senior application security and coding capability; minimum years not specified |
| Education | No mandatory degree or certification stated |
| Deadline / schedule | No closing date published; standard five-day week or manager-agreed four-day week at 80% pay |
Close develops sales CRM software covering email, calls, SMS, reporting, workflows and AI. The employer describes a profitable, bootstrapped business with a fully remote team. This new position reports to the Backend Platform team manager within Engineering, Product and Design and partners with Infrastructure and Security & Trust.
Technical capability: Be able to read unfamiliar code, reproduce an exploit safely and propose or deliver a production-ready correction. Python or TypeScript experience is especially relevant. The role covers authentication, authorization, tenant isolation, injection, SSRF, data flows and business-logic weaknesses.
Engineering environment: Python, Flask, FastAPI, TaskTiger, Temporal, TypeScript, React, React Native, REST and GraphQL; Docker, Kubernetes, AWS EKS, MSK, EC2 and ElastiCache; Terraform, Ansible, Vault and GitHub Actions; MongoDB, PostgreSQL, Redis, Kafka and Elasticsearch. Frontend tooling includes Vite, Vitest, React Testing Library, Playwright and Chromatic, with WebSockets and WebRTC. These describe the environment, not a requirement to master every tool.
Judgment and collaboration: Assess exploitability and business impact, distinguish severity from remediation priority, communicate with engineers and business owners, and follow findings through closure. Close expects responsible use of coding agents and LLMs, with human verification and careful handling of untrusted dependencies and credentials.
Academic and experience criteria: The advertisement gives no required degree, named certification or numerical experience threshold. It does expect independent senior-level security investigation, automation and coding skills.
The employer advertises approximately five weeks of starting PTO, a one-week company winter break, paid U.S. holidays and two additional PTO days per year of service. Other benefits include paid parental leave and a one-month paid sabbatical after each five years.
For U.S. residents, benefits include medical coverage with most premiums paid by Close, dental and vision coverage, HSA/FSA options, company-paid long-term disability and a 401(k) match of up to 6% with immediate vesting. A manager-agreed four-day schedule pays 80% of standard pay. Confirm eligibility and current plan terms during recruitment.
Aptub’s analysis and preparation advice follows; it is not a promise from the employer or a confirmed interview syllabus.
Being the first dedicated product security hire offers influence over priorities and tooling, but also creates a broad workload. This is a strong fit for an engineer who wants to own outcomes across code review, remediation and infrastructure partnerships. Ask what resources, authority and incident-response expectations accompany that ownership.
Prepare evidence, not a tool inventory. Bring a sanitized example showing the weakness you discovered, how you reproduced it safely, the change you made and how you verified the correction. Explain how your work improved an outcome using only figures you can substantiate. Never share employer secrets or private customer data.
Practice the decisions behind a fix. Be ready to discuss API authorization, multi-tenant isolation, dependency risk and safe credential rotation. Describe how you would prioritize a reachable vulnerability over a higher-scored issue protected by effective controls. These are preparation suggestions based on the work, not leaked assessment questions.
Clarify pay before comparing offers. There is no published salary band to benchmark this vacancy reliably. Request the base range, bonus formula, benefits and on-call arrangements. Calculate the effect of 80% pay before choosing the four-day option. Remote status here does not mean worldwide eligibility.
Application safety: Aptub does not collect applications or charge a fee for this listing. Use the employer’s official application link and verify any unexpected payment or sensitive-document request directly with Close.
Explore more remote cybersecurity jobs. Check each vacancy’s country restrictions separately.
No. Close lists this position as USA only. Applicants outside the United States should not assume eligibility because the company has an international remote team.
The employer does not publish a numeric salary range. It lists competitive compensation and a company goal-based bonus. Ask the recruiter for the base-pay range and bonus terms.
No closing date is stated on the employer page. The vacancy was checked on 11 October 2026; confirm it remains open before applying.
The listing does not specify a mandatory degree, named certification or minimum number of years. It seeks senior hands-on application security and software engineering capability.
The advertised 80% work option allows a four-day week at 80% pay, arranged with your manager. It is not a four-day week on full-time pay.
Source: Close’s official employer listing. Its current terms take precedence if the vacancy changes.
