Reddit is a community of communities, and they are seeking a Staff Product Security Engineer to enhance security frameworks for engineers and AI agents. The role involves designing secure workflows, conducting product security reviews, and eliminating systemic security debt across teams.
Responsibilities:
- Build and evolve secure frameworks, guardrails, and library-level controls that make common vulnerability classes harder to introduce
- Design security controls for AI-assisted development — including reusable rule packs and skills that shape how engineers and coding agents generate, review, and ship code
- Embed security into the workflows engineers already use
- Drive product security reviews for new launches and major architectural changes
- Identify and eliminate systemic security debt
- Shape strategy, influence architecture, and drive execution across teams
Requirements:
- 8+ years of experience in software engineering, product security, or application security, with at least 2 years operating at a staff level of scope and impact
- Proficiency in one or more languages (Go, Python, JS/TS)
- Experience designing, building, and operating production-quality systems and developer-facing platforms
- Experience building secure frameworks, libraries, or guardrails that improve security across many teams at once
- Demonstrated ability to integrate security into developer workflows: CI/CD, code review, release processes, and internal platforms
- Clear communicator who can explain technical detail and business impact to both engineers and leadership
- Comfortable in fast-moving environments where AI-assisted development is reshaping how software is built and reviewed
- Experience with vulnerability discovery and remediation pipelines, including bug bounty or researcher-reported findings
- Track record of mentoring engineers and raising the technical bar across a security or platform engineering org
- Experience securing AI/LLM systems, agentic workflows, or AI-assisted development tooling
- Familiarity with authentication/authorization systems, cloud-native platforms, and how to secure them