# Senior Security Engineer, Product Security at GoodLeap

- Company: GoodLeap
- What the company does: GoodLeap is a tech company delivering best-in-class financing and software products for sustainable solutions. Backed by NEA.
- Company website: https://goodleap.com/
- Type: Startups
- Level: Senior
- Location: Remote, US
- Work setup: Remote
- Pay: $146K to $170K base salary per year (USD)
- Posted: 2026-08-28
- Apply by: 2026-10-12
- Apply: https://jobs.lever.co/goodleap/0141a21f-3c8a-499b-98d7-0350ec407296
- Page: https://www.1752.vc/careers/jobs/goodleap-senior-security-engineer-product-security/

## About the role

GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance.

## What they're looking for

- You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on
- You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification
- Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest
- Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap
- Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code
- Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked

Tags: Security
