ClassPass Logo

ClassPass

Senior Product Security Engineer

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Lead product security architecture and offensive testing, including threat modeling, architecture reviews, penetration testing across web applications, APIs, mobile clients, and cloud infrastructure, secure design definition, code reviews, and remediation validation. Partner with engineering teams on authentication, authorization, data protection, trust boundaries, and cloud-native security while communicating risks and leading cross-functional security initiatives.
The summary above was generated by AI

At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections.

ClassPass offers thousands of fitness and wellness experiences worldwide, helping people lead active, balanced lifestyles. Our platform makes discovering and enjoying activities simple, personalized, and joyful—whether it's fitness classes, self-care sessions, a healthy lunch, or a new adventure. Join us in shaping healthier, more vibrant communities around the globe.

Who We Are

We are a dedicated team of product security engineers committed to developing and supporting ground-breaking software products. Together we will work to safeguard the future, enabling wellness businesses worldwide to empower their customers to lead healthy lives. Driven by a higher purpose, we continuously challenge ourselves and our organization to excel, recognizing the strength that comes from collaborative efforts toward a common objective. We are strong advocates for a diverse workplace, fostering an environment where individuals can bring their authentic selves to contribute to our shared success. At the core of our achievements is a deep belief in the value of our people. If you share our passion and vision, we invite you to consider joining our team. Together, we can explore remarkable feats and make a lasting impact!

Your Role

As a Senior Security Engineer, you will drive the security architecture and support the offensive testing practice of the Product Security team. You'll partner with engineering to design secure-by-default systems, review architectures and designs for exploitable weaknesses, and personally test our products the way an attacker would. You will lead threat modeling for new features and platforms, define secure design patterns and reference architectures, and conduct hands-on penetration testing across web applications, APIs, and cloud .

You'll ensure security is designed in from the start rather than bolted on afterward — reviewing designs before code is written, validating that architectural controls hold up under adversarial testing, and translating findings into concrete remediation guidance engineering teams can act on. You'll pursue continuous improvement to help Playlist achieve its mission: powering the world's fitness and wellness businesses and connecting them with more consumers, more effectively, than anyone else.

The Role You'll Play
  • Lead threat modeling and architecture security reviews for new products, features, and major system changes, identifying design-level risks before they reach production.
  • Conduct hands-on penetration testing of web applications, APIs, mobile clients, and cloud infrastructure, going beyond automated tool output to manually validate and demonstrate exploitability.
  • Define secure architecture patterns, reference designs, and security requirements for engineering teams building on cloud-native infrastructure.
  • Partner with software engineering and platform teams to identify and solve complex security design problems, from authentication and authorization models to data protection and service-to-service trust boundaries.
  • Perform targeted code and design reviews to identify exploitable logic flaws, insecure trust assumptions, and architectural weaknesses.
  • Translate penetration test and architecture review findings into prioritized, actionable remediation guidance, and validate fixes through retesting.
  • Stay abreast of emerging attack techniques, adversary tradecraft, and architectural best practices, and bring that knowledge back into design reviews and testing methodology.
  • Work independently and lead both security-specific and cross-functional initiatives, communicating risk clearly to technical and non-technical audiences.
 The Experience You’ll Bring

You are an intellectually curious senior security engineer who thinks like an attacker and designs like an architect. You bring deep expertise in application security architecture and offensive testing methodology, and you can move between designing a secure system and trying to break one. You communicate findings and design recommendations clearly to both engineers and leadership. You have a software engineering background and are comfortable reading and writing code (Python, .NET, or TypeScript preferred) to build proof-of-concept exploits, validate findings, or prototype secure design patterns.

You will thrive in this role with experience

  • 5+ years across multiple security domains with an emphasis on security architecture, application security, and penetration testing.
  • Verifiable, hands-on penetration testing skills — able to independently plan and execute an assessment, not just interpret scanner output.
  • 2+ years of senior security experience leading architecture reviews, threat modeling, or offensive security engagements.
  • Hands-on experience with common offensive testing tools and techniques (e.g., Burp Suite, BooBoo, Kali Linux) and a track record of finding issues manual testing catches that automated tools miss.
  • Practical experience with SAST, DAST, SCA, WAF, and CNAPP solutions (e.g., Semgrep, Yogi, Snyk, Wiz, or equivalents) within CI/CD pipelines.
  • Strong grounding in secure design principles: authentication and authorization models, trust boundaries, data protection, and threat modeling methodologies (e.g., STRIDE, attack trees).
  • Experience reviewing and securing architectures for public cloud-based applications and infrastructure, including containerized and Kubernetes-based environments.
  • Proficiency in a modern language (Python, .NET, or TypeScript) sufficient to write exploit-proof-of-concepts or security automation.
  • Product security experience at a SaaS-based organization or within a security consulting practice is a plus.
  • Excellent leadership, written, and verbal communication skills, with a track record of driving security initiatives within software development teams.
  • Self-motivated, self-directed, and self-organized.

It is the Company's intent to pay all Team Members competitive wages and salaries that are motivational, fair and equitable. The goal of Company's compensation program is to be transparent, attract potential employees, meet the needs of all current employees, and encourage Team Members to stay with our organization. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location.

The base salary range for this position in the United States is $150,000 to $175,000. The total compensation package for this position may also include a performance bonus, benefits and/or other applicable incentive compensation plans

Have we piqued your curiosity?

Sound like the role for you? We’d love to hear from you! Even if you’re not 100% sure about potential fit, we still encourage you to apply. We’re looking for the right person, not the perfect series of checkboxes.

The Company is an Equal Opportunity Employer. We highly value diversity at our company and encourage people of all different backgrounds, experiences, abilities and perspectives to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.

By entering your email and phone number and submitting your application, you consent to receive emails, calls and SMS about your application and other roles at The Company, including by auto-dialer. Message and data rates may apply. Opt-out or text STOP to cancel at any time. If you are a California resident or reside outside the United States then by submitting your application you confirm that you have read, understood, agree and - where applicable - grant your prior, free, informed and express consent for the processing of your personal information, including sensitive personal information, as described in our California Applicant Privacy Notice or International Applicant Privacy Notice (as applicable).

ClassPass San Francisco, California, USA Office

33 New Montgomery St, San Francisco, CA, United States, 94105

Similar Jobs

2 Days Ago
In-Office or Remote
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead secure design reviews, threat modeling, and security risk assessments for products and features. Partner with engineers, product managers, and designers to develop secure architectures, provide remediation guidance, promote security culture through training and mentoring, oversee vulnerability management, and explain security events. Build security tooling, automate secure development practices, and establish architectural patterns and processes that reduce security risk across DigitalOcean’s engineering organization.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwasp Top TenRustVirtualization
2 Days Ago
Remote
United States
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Assess product and application architectures, develop threat models, identify security risks, and guide engineering teams on remediation. Promote security culture through training, mentoring, vulnerability management, and internal security initiatives. Build security tooling, automation, patterns, and workflows that embed secure-by-design practices across engineering. Partner with product managers, designers, and engineers to secure complex, large-scale cloud systems.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwaspRustVirtualization
26 Days Ago
Remote or Hybrid
San Francisco, CA, USA
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account